Is Claude Code Secure? Let’s Find Out!

Vulnerable Plugin + MCP Enumeration TL&DR Claude Code didn’t invent most of the security problems discussed in this article but it will make them faster, louder and easier to repeat. As I rush to use AI myself, I realize the attack surface is widening in ways that follow classic software supply chain weaknesses: With a…

Anthropic’s Security Layers Explained: The Good, Bad & Ugly

Can you secure the Anthropic SaaS cloud platform? The answer, sorta, kinda, maybe. This article is intended for architects and managers. Low level embedded security analysis is in the works for next week in another article. Let me say ahead of time, huge shout out to Anthropic, I personally respect the company a ton and…

AI RED TEAMING – man-in-the-vector Attack & custom Tooling

Want deeper dives into AI vector embedding attack vectors? See more at Security Sandman. This article provides practical examples to assist red teams and security researches to find and exploit vulnerable AI systems using Vector Databases and even flow chaining tools. I’ve prototyped some simple tools to demonstrate the attack chain and later I’ll finish…

Panel 1

Home

training ai to Predict your competitor’s next …

Imagine a world where your every sentiment, every email, every social media post, every meeting minute and every line of code you write was then condensed down to create a pseudo “clone” of yourself. It sounds both horrifying and amazingly beautiful too. Now imagine your ideas, comments and thoughts being used against you or your…

Abusing AI for Password Guessing and social engineering

While taking some time off, I wanted to dig into the world of AI as it relates to password based attacks and password guessing. Breached password lists are gold standard and password hash cracking has been awhile for decades but I was more intrigued into whether a personal or free account user can prompt large…

CHANGE HEALTHCARE: ITS LITERALLY IN THE NAME

For cyber security folks, we’re both horrified and laughing that a company named “Change Healthcare” who has stockpiles of marketing jargon for “Improving IT Security” also made the news for a cyber incident. As a cyber security professional by day and a partial owner and investor of a new medical business, this breach hits home…

Panel 2 Placeholder
Panel 3 Placeholder
Panel 4 Placeholder