Blog· 209 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

"No Watermark Detected" Tells You Nothing. The SynthID Removal Toolchain Is Why
By Jason Miller

Your Sent Items Folder Is a Phishing Kit Now
By Jason Miller

Grok Decrypted Its Own Attack Instructions. Your Agent Would Too
By Jason Miller

The Hugging Face Sandbox Escape: Everyone Watched the Proxy, Nobody Watched Port 53
By Jason Miller

Five of the Top Seven Skills Were Malware: A Working Guide to OWASP's Agentic Skills Top 10
By Jason Miller

CircleCI's MCP Server RCE: A Defender's Playbook for All Three Advisories
By Jason Miller

9,300 Leaked AWS Keys Are Still Live. One of Them Might Be Yours.
A same-day runbook with copy-paste commands to find live leaked keys in your accounts and code, rotate them without downtime, and replace long-lived credentials with roles.…
By Jason Miller

RedC2 4.0 on npm: Detecting the Import-Time Linux Backdoor Behind 14 Trojanized Packages
Get a concrete IoC set, ready-to-adapt Sigma and YARA rules, and a same-day audit and remediation workflow for the RedC2 4.0 npm campaign, plus a clear-eyed read on what its AI-driven C2 actually changes for detection.…
By Jason Miller

Self-Correction Loops Can Make LLM Pipelines Worse: An 85% to 62% Case Study and a Pre-Ship Measurement Playbook
A concrete failure taxonomy and a pre-ship measurement playbook (flip-rate tracking, shadow mode, paired holdout A/B, written ship gates) to decide whether a judge loop helps or quietly degrades their pipeline.…
By Jason Miller
