Category: Mix

When your AI Assistant Becomes the Attacker’s Command-and-Control — API Security
26
Nov
2025

When your AI Assistant Becomes the Attacker’s Command-and-Control — API Security

Earlier this month, Microsoft uncovered SesameOp, a new backdoor malware that abuses the OpenAI Assistants API as a covert command-and-control…

Keep the Robots Out of the Gym
26
Nov
2025

Keep the Robots Out of the Gym

AI is getting so good now (at the end of 2025) that I now have a new, primary recommendation going…

Is Prompt Injection a Vulnerability?
26
Nov
2025

Is Prompt Injection a Vulnerability?

I want to respond to my buddy Joseph Thacker’s blog post about Prompt Injection and whether or not it’s a…

Exploiting JWT vulnerabilities to achieve RCE
25
Nov
2025

Exploiting JWT vulnerabilities to achieve RCE

At Intigriti, we host monthly web-based Capture The Flag (CTF) challenges as a way to engage with the security research…

The AI Quality Paradox | Daniel Miessler
25
Nov
2025

The AI Quality Paradox | Daniel Miessler

When excellence itself becomes the marker of AI, not human talent November 24, 2025 Nano Banana Pro has shown me…

Keep the Robots Out of the Gym
25
Nov
2025

Keep the Robots Out of the Gym

AI is getting so good now (at the end of 2025) that I now have a new, primary recommendation going…

Thoughts on Prompt Injection OPSEC
25
Nov
2025

Thoughts on Prompt Injection OPSEC

I want to respond to this blog post that’s arguing that prompt injection strings are essentially zero-days that we should…

Prompt Injection Isn't a Vulnerability · Joseph Thacker
24
Nov
2025

Prompt Injection Isn’t a Vulnerability · Joseph Thacker

OKAY. OKAY. OKAY. It can be a vulnerability. But it’s almost never the root cause. I think we need to…

Judge AI by Outputs, not Mechanism
22
Nov
2025

Judge AI by Outputs, not Mechanism

This song captures extraordinarily well why arguments about AI understanding are completely misguided and empty. This is a blues version…

Prompt Injection Isn't a Vulnerability · Joseph Thacker
21
Nov
2025

Prompt Injection Isn’t a Vulnerability · Joseph Thacker

Stop calling Prompt Injection a vulnerability. It’s not one. And it’s actually causing a lot of confusion in the handling…

How to Secure Them This Black Friday — API Security
21
Nov
2025

How to Secure Them This Black Friday — API Security

Can you ever imagine the impact on your business if it went offline on Black Friday or Cyber Monday due…

Leave the em dash Alone
21
Nov
2025

Leave the em dash Alone

I’m annoyed by all the hate against the em dash. As Matthew Butterick captures brilliantly, it adds pauses to sentences….