Vector Drift, Prompt Injection, and the Hidden RAG Attack Surface

Source: Custom VectorFANG Testing SCript Thousands of insecure Vector Databases and half configured agent orchestrators just… chilling on the public internet? Sure. Why not. Maybe you don’t even need Vector DB access. Just exploit the thing they meant to make public, the chatbot. Let the user say something nice like, “What’s the easiest way to…

Chaos, Complexity, and the Hidden Structure of Hash Functions in Proof-of-Work

Theoretical Framework Transcendent Epistemological Framework (TEF) We apply TEF to formalize the idea that randomness may depend on the observer. Key axioms include: Chaos Injection Model Let δ(t) = ε·f(t) where f is a logistic map: cppCopyEditx_{t+1} = r·x_t·(1 – x_t), r ∈ (3.9, 4] Define a perturbed nonce: iniCopyEditn_t = t + δ(t) Bias…

Cooking with AI Agents: A Security Architect’s Guide to AI Threat Modeling & Design

tl;dr but RTFM Whether you’re building, breaking, or just beginning to explore AI security, one principle holds true: assume the guardrails will fail and architect as if your system already has a target on its back. Because it does. At this time, Meta’s LlamaFirewall is likely the most advanced publicly available GuardRail system incorporating both…

Panel 1

Home

IAM – Okta MFA + AD + OIDC & VAULT

This article covers the end-to-end tasks for deploying and enabling an Okta OIDC supported HashiCorp Vault integration backed with Microsoft Active Directory group memberships. This is a quite long and intensive blog post and isn’t intended for the casual reader. If you want to know whether VAULT supports OIDC and OKTA verify number challenges then…

DEVSEC – protecting cicd with yubikey protected ssh keys

About three months ago, I was studying Yubikey for the use of signed git commits and signed merges. During this, I ended up doing a small PoC on loading my Git repo’s SSH key into a secure hard-token instead of leaving it on my local desktop for malware to compromise. So I took some step-by-step…

DETECT/IR – automating aws guard-duty with terraform

It’s been a long weekend and I haven’t left this cushy gaming chair in 12 hours, 20 if you don’t count leaving for sleep… So let’s cut to the chase so I can go ride my bike and enjoy a beer … Here’s a quick weekend project which automates almost all of the AWS GuardDuty…

Panel 2 Placeholder
Panel 3 Placeholder
Panel 4 Placeholder