Category: Mix

Metanarrative Prompt Injection · Joseph Thacker
20
Oct
2025

Metanarrative Prompt Injection · Joseph Thacker

When exploiting AI applications, I find myself using this technique really often so I figured I’d write a quick blog…

Reflected XSS: Advanced Exploitation Guide
20
Oct
2025

Reflected XSS: Advanced Exploitation Guide

Cross-site scripting vulnerabilities are, by no doubt, one of the vulnerability types that’ll keep haunting applications for a long time….

20
Oct
2025

Reflected XSS: Advanced Exploitation Guide

Cross-site scripting vulnerabilities are, by no doubt, one of the vulnerability types that’ll keep haunting applications for a long time….

20
Oct
2025

Reflected XSS: Advanced Exploitation Guide

Cross-site scripting vulnerabilities are, by no doubt, one of the vulnerability types that’ll keep haunting applications for a long time….

Safeguarding digital playgrounds. Gaming and eSports insights.
20
Oct
2025

Safeguarding digital playgrounds. Gaming and eSports insights.

According to Statista, revenue for the gaming and esports industry is expected to demonstrate an annual growth rate (CAGR 2025-2029)…

Why I Think Karpathy is Wrong on the AGI Timeline
20
Oct
2025

Why I Think Karpathy is Wrong on the AGI Timeline

Andrej Karpathy came on Dwarkesh’s podcast recently, and I have a number of thoughts. Many are saying that Karpathy thinks…

Product comparison: Detectify vs. Escape
20
Oct
2025

Product comparison: Detectify vs. Escape

Escape Pros Escape provides deep, contextual visibility by integrating with internal developer and cloud tools. Its AI-powered assessment finds complex…

Why I Think Karpathy is Wrong on the AGI Timeline
19
Oct
2025

Why I Think Karpathy is Wrong on the AGI Timeline

Andrej Karpathy came on Dwarkesh’s podcast recently, and I have a number of thoughts. Many are saying that Karpathy thinks…

[tl;dr sec] #301 - Security Leadership Master Class, DEF CON Cloud Village Talks, AI-Powered Honeypot
16
Oct
2025

[tl;dr sec] #301 – Security Leadership Master Class, DEF CON Cloud Village Talks, AI-Powered Honeypot

I hope you’ve been doing well! Reflections and Cooking First off, thanks so much to everyone who reached out with…

When Authentication Fails — Exposing APIs to Risk — API Security
16
Oct
2025

When Authentication Fails — Exposing APIs to Risk — API Security

Authentication issues seem like low-level attacks. But authentication today – especially API authentication – can be more difficult than people…

Extending your lifespan through attention
14
Oct
2025

Extending your lifespan through attention

One of the most surprising things I’ve ever learned is that novelty and attention extend your lifespan. Or, more precisely,…

Why API security is different (and why it matters)
14
Oct
2025

Why API security is different (and why it matters)

Two months in at Detectify and I’ve realized something: API security is a completely different game from web application security….