» Tag
pentesting
5 postsBuilding an AI that pentests your AI, with proof required
An engineer built an adversarial LLM harness that only reports proven exploits against a live agent, replacing vague 'might be vulnerable' pentest reports with deterministic, oracle-verified findings.
LWR: A Pentester's Guide to Salesforce's WebRuntime API
Salesforce's new WebRuntime API and LWR have become significant targets for pentesters. This entry provides crucial insights for security professionals.
Hunt NGINX Proxies with Damn Vulnerable NGINX Proxy
Damn Vulnerable NGINX Proxy provides a resource for discovering vulnerabilities in NGINX servers.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comWindows Privilege Abuse: The Shortcut to SYSTEM Access
Exploring how Windows privileges like SeImpersonatePrivilege are weaponized into SYSTEM access via Potato attacks, and why architectural defenses matter.
Booking.com Breach: When the Vendor Chain Becomes the Attack Surface
The Booking.com breach highlights the critical importance of vendor chain security. Key lessons for engineers are discussed.