/blog

Notes from the AI red team

Analysis of AI agent vulnerabilities, attack techniques, and defensive patterns — plus findings from scans I run against public targets.

April 25, 2026·6 min read

The OWASP LLM Top 10 Is Missing Three Categories

The OWASP Top 10 for LLM Applications is the best framework we have. It also has three blind spots that account for a disproportionate share of what I'm finding in the field — multi-tenant context bleed, agent-to-agent handoff attacks, and temporal/memory attacks.

Read post →
April 16, 2026·2 min read

Why I Built Wraith

Most security tools don't know how to test AI agents. That's a gap worth building a product around.

Read post →