» Tag
pentesting
4 postsBuilding an AI that pentests your AI, with proof required
An engineer built an adversarial LLM harness that only reports proven exploits against a live agent, replacing vague 'might be vulnerable' pentest reports with deterministic, oracle-verified findings.
Hunt NGINX Proxies with Damn Vulnerable NGINX Proxy
Damn Vulnerable NGINX Proxy provides a resource for discovering vulnerabilities in NGINX servers.
Windows Privilege Abuse: The Shortcut to SYSTEM Access
Exploring how Windows privileges like SeImpersonatePrivilege are weaponized into SYSTEM access via Potato attacks, and why architectural defenses matter.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comBooking.com Breach: When the Vendor Chain Becomes the Attack Surface
The Booking.com breach highlights the critical importance of vendor chain security. Key lessons for engineers are discussed.