<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://sahnoun11.github.io/</id><title>Oussama Sahnoun</title><subtitle>Cybersecurity blog by Oussama Sahnoun. Focused on penetration testing, red teaming, and threat research, sharing insights, tutorials, and security guides for professionals and enthusiasts.</subtitle> <updated>2026-09-18T15:50:41+01:00</updated> <author> <name>Sahnoun_Oussama</name> <uri>https://sahnoun11.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://sahnoun11.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://sahnoun11.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Sahnoun_Oussama </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>AI Agents &amp; Tool Abuse — When the Blast Radius Moves at Machine Speed</title><link href="https://sahnoun11.github.io/posts/ai-agents-and-tool-abuse/" rel="alternate" type="text/html" title="AI Agents &amp;amp; Tool Abuse — When the Blast Radius Moves at Machine Speed" /><published>2026-09-17T09:00:00+01:00</published> <updated>2026-09-18T15:50:04+01:00</updated> <id>https://sahnoun11.github.io/posts/ai-agents-and-tool-abuse/</id> <content type="text/html" src="https://sahnoun11.github.io/posts/ai-agents-and-tool-abuse/" /> <author> <name>Sahnoun_Oussama</name> </author> <category term="AI Security" /> <category term="AI Systems Security Specialist" /> <summary>Part 4 of the AI Systems Security Specialist series: agent autonomy as a risk multiplier — the confused deputy at machine speed, MCP as an attack surface, tool poisoning and rug pulls, memory poisoning, multi-agent trust, and the real 2026 agent incidents.</summary> </entry> <entry><title>Secure AI Systems Engineering — Building So That Being Fooled Doesn't Matter</title><link href="https://sahnoun11.github.io/posts/secure-ai-systems-engineering/" rel="alternate" type="text/html" title="Secure AI Systems Engineering — Building So That Being Fooled Doesn&amp;apos;t Matter" /><published>2026-09-10T09:00:00+01:00</published> <updated>2026-09-13T07:48:26+01:00</updated> <id>https://sahnoun11.github.io/posts/secure-ai-systems-engineering/</id> <content type="text/html" src="https://sahnoun11.github.io/posts/secure-ai-systems-engineering/" /> <author> <name>Sahnoun_Oussama</name> </author> <category term="AI Security" /> <category term="AI Systems Security Specialist" /> <summary>Part 3 of the AI Systems Security Specialist series: the 2026 state of the art in defending AI systems — information-flow control, dual-LLM patterns, spotlighting, deterministic egress control, capability scoping, and the honest answer to whether prompt injection can be solved.</summary> </entry> <entry><title>Prompt Injection &amp; Abuse Techniques — Attacking the Architecture</title><link href="https://sahnoun11.github.io/posts/prompt-injection-and-abuse-techniques/" rel="alternate" type="text/html" title="Prompt Injection &amp;amp; Abuse Techniques — Attacking the Architecture" /><published>2026-09-03T09:00:00+01:00</published> <updated>2026-09-03T16:15:59+01:00</updated> <id>https://sahnoun11.github.io/posts/prompt-injection-and-abuse-techniques/</id> <content type="text/html" src="https://sahnoun11.github.io/posts/prompt-injection-and-abuse-techniques/" /> <author> <name>Sahnoun_Oussama</name> </author> <category term="AI Security" /> <category term="AI Systems Security Specialist" /> <summary>Part 2 of the AI Systems Security Specialist series: direct and indirect prompt injection, tokenizer-level filter evasion, multi-modal payloads, system prompt extraction, and the exfiltration channels that turn a text bug into a data breach — built around real 2025–2026 incidents including EchoLeak.</summary> </entry> <entry><title>AI/LLM Systems &amp; Security Architecture — The Foundation Every AI Security Assessment Starts From</title><link href="https://sahnoun11.github.io/posts/ai-llm-systems-and-security-architecture/" rel="alternate" type="text/html" title="AI/LLM Systems &amp;amp; Security Architecture — The Foundation Every AI Security Assessment Starts From" /><published>2026-08-27T09:00:00+01:00</published> <updated>2026-08-27T21:17:09+01:00</updated> <id>https://sahnoun11.github.io/posts/ai-llm-systems-and-security-architecture/</id> <content type="text/html" src="https://sahnoun11.github.io/posts/ai-llm-systems-and-security-architecture/" /> <author> <name>Sahnoun_Oussama</name> </author> <category term="AI Security" /> <category term="AI Systems Security Specialist" /> <summary>Part 1 of the AI Systems Security Specialist series: the complete architecture of an LLM application — tokens, context windows, inference, the five-layer stack, orchestrators, RAG, embeddings, trust boundaries and sensitive data flows — plus a full worked security review of a vulnerable RAG chatbot.</summary> </entry> <entry><title>The AI Systems Security Specialist — Series Overview</title><link href="https://sahnoun11.github.io/posts/ai-systems-security-specialist-series-overview/" rel="alternate" type="text/html" title="The AI Systems Security Specialist — Series Overview" /><published>2026-08-20T09:00:00+01:00</published> <updated>2026-08-20T09:00:00+01:00</updated> <id>https://sahnoun11.github.io/posts/ai-systems-security-specialist-series-overview/</id> <content type="text/html" src="https://sahnoun11.github.io/posts/ai-systems-security-specialist-series-overview/" /> <author> <name>Sahnoun_Oussama</name> </author> <category term="AI Security" /> <category term="AI Systems Security Specialist" /> <summary>A nine-part weekly series on securing AI systems — from tokens and context windows to trust boundaries, agent tool abuse, red teaming, governance, and the AI-assisted SOC.</summary> </entry> </feed>
