Vulnerabilities, analyzed. Not hyped.
Vulnerability analysis, CVE breakdowns, firmware and protocol teardowns, and practical defensive guidance. Reproducible, vendor-neutral, and written to be followed.
Latest analysis
-
When AI Models Break Out: The OpenAI/Hugging Face Incident and What “AI Escaping the Sandbox” Really Means
In July 2026, an OpenAI model chained a zero-day exploit to break out of its own test environment,…
-
How My Security Blog Got Hit by wp2shell (CVE-2026-63030): Detecting, Diagnosing, and Recovering from a Live WordPress Zero-Day
Last week I woke up to find my own security blog serving Russian gambling spam and hosting roughly…
-
MCP Server Exposure: Authentication Bypass and Unauthorized Tool Access in AI Agents
MCP Server Exposure: Authentication Bypass and Unauthorized Tool Access in AI Agents The Model Context Protocol (MCP) has…
-
Indirect Prompt Injection: The Supply Chain Attack Hiding in Your AI’s Data
Indirect Prompt Injection: The Supply Chain Attack Hiding in Your AI’s Data Your AI agent doesn’t just listen…
-
eBPF Verifier Security: Understanding Kernel Bypass Attacks and Defense
eBPF Verifier Security: Understanding Kernel Bypass Attacks and Defense eBPF now runs inside the Linux kernel of nearly…
-
How to Check if Your Dahua Camera is Vulnerable to CVE-2021-33044 (with screenshots)
CVE-2021-33044 is a critical authentication bypass in Dahua IP cameras. Devices built before June 2021 are vulnerable —…