
Author
Jason Miller

12 min read
One Schema Name, Every Stored Credential: CVE-2026-33696 and the n8n Blast Radius
The reader gains concrete detection queries, patching verification steps, and an understanding of the full attack chain (including the overlooked XML node).…


10 min read
Memory Made Chatbots Useful. It Also Made Them Gossips.
Understands contextual integrity as a new, undetectable-by-access-controls privacy failure mode, gets the CIMemories benchmark evidence (up to 69% violation.…


12 min read
One ../ From Copilot: The CVE-2026-32193 Chain, Rebuilt for AKS Defenders
Readers get the full path-traversal-to-Copilot-hijack attack chain that public CVE coverage missed, plus concrete node-pool patching commands and detection.…


11 min read
The Signature Was Valid and the Boot Was Still Compromised
Readers gain a five-class taxonomy of non-cryptographic Secure Boot failure modes, concrete mitigation and detection steps for two 2026 CVEs, and a prioritized.…


10 min read
Your Dashboard Might Be Someone's Proxy Exit: a Field Check for the DoFun Head Unit Botnet
The reader understands how the DoFun head unit botnet operates and gets a practical ten-minute workflow to check for infection, remove the payload, and contain.…


12 min read
"No Watermark Detected" Tells You Nothing. The SynthID Removal Toolchain Is Why
Readers learn why a negative watermark result carries zero evidentiary weight, how mature the SynthID removal toolchain has become, and how to structure.…


10 min read
Your Sent Items Folder Is a Phishing Kit Now
Understand how attackers turn compromised mailboxes and public writing samples into flawless impersonations, and learn which controls (phishing-resistant MFA.…


11 min read
Grok Decrypted Its Own Attack Instructions. Your Agent Would Too
Understand how encrypted context injection launders untrusted content into trusted tool output, and learn the concrete harness-level defenses that break the.…


11 min read
The Hugging Face Sandbox Escape: Everyone Watched the Proxy, Nobody Watched Port 53
The reader learns three DNS-based exfiltration and tunneling techniques that bypass proxy-only egress controls, plus concrete detection logic (query entropy.…


13 min read
Five of the Top Seven Skills Were Malware: A Working Guide to OWASP's Agentic Skills Top 10
The reader gains a plain-language breakdown of OWASP's Agentic Skills Top 10 risks plus concrete controls, like permission manifests, pinning, sandboxing, and.…


9 min read
CircleCI's MCP Server RCE: A Defender's Playbook for All Three Advisories
A same-day playbook to assess exposure across all three CircleCI MCP advisories, hunt for signs of exploitation, remediate or migrate, and harden any.…


10 min read
9,300 Leaked AWS Keys Are Still Live. One of Them Might Be Yours.
A same-day runbook with copy-paste commands to find live leaked keys in your accounts and code, rotate them without downtime, and replace long-lived.…
