The AI Systems Security Specialist — Series Overview
A nine-part weekly series on securing AI systems — from tokens and context windows to trust boundaries, agent tool abuse, red teaming, governance, and the AI-assisted SOC.
A nine-part weekly series on securing AI systems — from tokens and context windows to trust boundaries, agent tool abuse, red teaming, governance, and the AI-assisted SOC.
Part 4 of the AI Systems Security Specialist series: agent autonomy as a risk multiplier — the confused deputy at machine speed, MCP as an attack surface, tool poisoning and rug pulls, memory poisoning, multi-agent trust, and the real 2026 agent incidents.
Part 3 of the AI Systems Security Specialist series: the 2026 state of the art in defending AI systems — information-flow control, dual-LLM patterns, spotlighting, deterministic egress control, capability scoping, and the honest answer to whether prompt injection can be solved.
Part 2 of the AI Systems Security Specialist series: direct and indirect prompt injection, tokenizer-level filter evasion, multi-modal payloads, system prompt extraction, and the exfiltration channels that turn a text bug into a data breach — built around real 2025–2026 incidents including EchoLeak.
Part 1 of the AI Systems Security Specialist series: the complete architecture of an LLM application — tokens, context windows, inference, the five-layer stack, orchestrators, RAG, embeddings, trust boundaries and sensitive data flows — plus a full worked security review of a vulnerable RAG chatbot.

TLP:AMBER — This analysis is prepared for the defensive benefit of the security community. All data is sourced from open-source intelligence: dark-web monitoring, public threat-intelligence tracker...
Comprehensive Cyber Threat Intelligence report on Cicada3301 (Repellent Scorpius) — a Rust-based RaaS with ALPHV/BlackCat code overlap targeting Windows, Linux/ESXi, NAS, and PowerPC. Full MITRE ATT&CK TTP mapping, CVE arsenal, confirmed IOCs, YARA & Sigma rules, and a complete defensive playbook.
A deep technical and strategic guide to Cyber Threat Intelligence — from the lifecycle and MITRE ATT&CK heatmap coverage to IoC enrichment pipelines, cognitive bias in triage, and structured case study analysis of SolarWinds and NotPetya.
The full technical writeup of my Black Hat MEA 2025 session in Riyadh: how LLMs and RAG architecture are transforming threat intelligence, a deep dive into ThreatLens (open-source), and the skills that define the next generation of security engineers.
A deep dive into advanced attack surfaces in modern AI systems: AI agents, RAG pipelines, embeddings, MCP tool surfaces, supply chain attacks, and AI infrastructure exploits.