Category: Mix

26
Aug
2025

MCPs are just other people’s prompts and other people’s APIs

I’ve been thinking about Model Context Protocols (MCPs) for months, and here’s the simplest way to explain what they actually…

26
Aug
2025

MCPs are just other people’s prompts and other people’s APIs

The Simple Truth About MCPs I’ve been thinking about Model Context Protocols (MCPs) for months, and here’s the simplest way…

22
Aug
2025

Exploiting API4 — 8 Real-World Unrestricted Resource Consumption Attack Scenarios (and How to Stop Them) — API Security

Unrestricted Resource Consumption (API4:2023) is the only threat category in the OWASP API Security Top 10 explicitly dedicated to Denial…

[tl;dr sec] #293 - MCP Security, AWS Enumeration, North Korean Hacker's Files Leaked
21
Aug
2025

[tl;dr sec] #293 – MCP Security, AWS Enumeration, North Korean Hacker’s Files Leaked

Rage-fueled Rewrite Monday morning I discovered that some tl;dr sec automation I’d built in Zapier randomly stopped working, despite me…

21
Aug
2025

Protecting Your AI-Powered Infrastructure — API Security

With innovation comes risk. As organizations race to build AI-first infrastructure, security is struggling to keep pace. Multi-Agentic Systems –…

AI Models Are Not Safety-Tuned for Kids · Joseph Thacker
20
Aug
2025

AI Models Are Not Safety-Tuned for Kids · Joseph Thacker

It hit me like a lightning bolt during a casual conversation about AI safety: we’re tuning these models for adults,…

The Quest for the Shortest Domain · Joseph Thacker
20
Aug
2025

The Quest for the Shortest Domain · Joseph Thacker

In the world of bug bounty hunting, having a short domain for XSS payloads can be the difference in exploiting…

18
Aug
2025

The Third Limitation to Creativity

The moment when you realize what was previously impossible is now trivial I just wrote a new piece about the…

strategic guidance for CISOs and cybersecurity leaders
18
Aug
2025

strategic guidance for CISOs and cybersecurity leaders

If you are a CISO or cybersecurity leader looking to scale your bug bounty program but are not sure when the right time to do…

17
Aug
2025

Who’s Not Getting Laid Off?

Who is not being laid off? That’s the question. I’m thinking about all these layoffs. I’m trying to figure out…

17
Aug
2025

Two Creativity Barriers | Daniel Miessler

I think there are two primary ways we limit our own creativity. What I’ll call Type 1 is the inability…

16
Aug
2025

Our 20,000 Eyes and Hands

Here’s a different way to think about the change coming to the workforce and economy from AI. Imagine everyone in…