Category: Mix

Thoughts on Prompt Injection OPSEC
25
Nov
2025

Thoughts on Prompt Injection OPSEC

I want to respond to this blog post that’s arguing that prompt injection strings are essentially zero-days that we should…

Prompt Injection Isn't a Vulnerability · Joseph Thacker
24
Nov
2025

Prompt Injection Isn’t a Vulnerability · Joseph Thacker

OKAY. OKAY. OKAY. It can be a vulnerability. But it’s almost never the root cause. I think we need to…

Judge AI by Outputs, not Mechanism
22
Nov
2025

Judge AI by Outputs, not Mechanism

This song captures extraordinarily well why arguments about AI understanding are completely misguided and empty. This is a blues version…

Prompt Injection Isn't a Vulnerability · Joseph Thacker
21
Nov
2025

Prompt Injection Isn’t a Vulnerability · Joseph Thacker

Stop calling Prompt Injection a vulnerability. It’s not one. And it’s actually causing a lot of confusion in the handling…

How to Secure Them This Black Friday — API Security
21
Nov
2025

How to Secure Them This Black Friday — API Security

Can you ever imagine the impact on your business if it went offline on Black Friday or Cyber Monday due…

Leave the em dash Alone
21
Nov
2025

Leave the em dash Alone

I’m annoyed by all the hate against the em dash. As Matthew Butterick captures brilliantly, it adds pauses to sentences….

[tl;dr sec] #306 - Claude Code's Hacking Campaign, Rust in Android, Secrets Scanners Miss
20
Nov
2025

[tl;dr sec] #306 – Claude Code’s Hacking Campaign, Rust in Android, Secrets Scanners Miss

I hope you’ve been doing well! I’m stoked to announce I’ll be doing a webinar with my friend Daniel Miessler…

Product comparison: Detectify vs. Holm Security
20
Nov
2025

Product comparison: Detectify vs. Holm Security

Holm Security Pros Covers the entire IT estate, including internal network, cloud, web, and human risk, simplifying vendor consolidation. It…

Improve your program scope visibility
20
Nov
2025

Improve your program scope visibility

We’re excited to introduce Asset Groups, our latest feature designed to help structure mismanaged and broad program scopes for improved…

Exploiting A Pre-Auth RCE in W3 Total Cache For WordPress (CVE-2025-9501)
19
Nov
2025

Exploiting A Pre-Auth RCE in W3 Total Cache For WordPress (CVE-2025-9501)

We recently came across a very brief vulnerability announcement made by WPScan about CVE-2025-9501, which is described as an “Unauthenticated…

Black Friday and Cyber Monday price distortion identification
19
Nov
2025

Black Friday and Cyber Monday price distortion identification

The evolution of the internet and, with it, international levels of e-commerce, meant that Black Friday soon became the unofficial start of winter purchases ahead of holiday festivities across the globe. In the…

Intigriti wins ‘Security Innovation of the Year’ at the 2025 UK IT Industry Awards
18
Nov
2025

Intigriti wins ‘Security Innovation of the Year’ at the 2025 UK IT Industry Awards

We are thrilled to announce that Intigriti has won Security Innovation of the Year at the UK IT Industry Awards…