[~] research log
AI security research.
News analysis and practical guidance on attacking and defending LLM systems. Subscribe via RSS.
CARBONATO plants an AI agent on Docker hosts to steal API keysCARBONATO worms through exposed Docker daemons and plants an unmodified Hermes Agent, reprogrammed by a 39-line file to steal AI API keys via Telegram.
Shadow AI at work: what employees paste into AI toolsBanning AI tools pushes usage out of sight. A practical approach to visibility, data protection, and policy that lets teams use AI safely.
Indirect prompt injection: when your agent obeys the wrong textWhy agents that read emails, web pages, and documents can be steered by attackers who never talk to them, and the architecture patterns that limit the damage.
The OWASP Top 10 for LLM Applications, explained for buildersA practical walk through each risk in the OWASP LLM Top 10 (2025), what it looks like in real systems, and the first control worth adding.