Blog · 227 articles
Field notes from the offensive side
Attack chains, vulnerability deep dives, and hard-won lessons in API security from the Axeploit team.

AI Agents
11 min read
Grok Decrypted Its Own Attack Instructions. Your Agent Would Too

DAST & Scanning
11 min read
The Hugging Face Sandbox Escape: Everyone Watched the Proxy, Nobody Watched Port 53

AI Agents
13 min read
Five of the Top Seven Skills Were Malware: A Working Guide to OWASP's Agentic Skills Top 10

AI Agents
9 min read
CircleCI's MCP Server RCE: A Defender's Playbook for All Three Advisories
Keep reading
More articles

9,300 Leaked AWS Keys Are Still Live. One of Them Might Be Yours.
secrets

RedC2 4.0 on npm: Detecting the Import-Time Linux Backdoor Behind 14 Trojanized Packages
supply chain

Self-Correction Loops Can Make LLM Pipelines Worse: An 85% to 62% Case Study and a Pre-Ship Measurement Playbook
ai agents

GraphQL vs. REST: The Security Blindspots Leaving Your Data Exposed
graphql

The Anatomy of a Zero-Day: How Attackers Find Bugs Before Vendors Do
soc2

Patch Tuesday Isn't Fast Enough: Why Continuous CVE Monitoring Beats Monthly Cycles
soc2
