active defense and adversarial agents: token burn
sticking with the theme of applied active defense (previous post), I wanted to explore token burn (lots of names here; unbounded consumption
Security research, field notes, and practical experiments
Independent technical notes by Willis Vandevanter, published in reverse chronological order.
sticking with the theme of applied active defense (previous post), I wanted to explore token burn (lots of names here; unbounded consumption
the previous post briefly touched on active defense in the scope of AI agents and LLMs. active defense is the practice of placing traps and tripwires that force an attacker (or an automated agent) to reveal itself or interrupt its own workflow rather than …
another by-product of anatomy of a frontier lab agent intrusion: a technical timeline of the july 2026 incident is that the adversary …
After reading the most recent hugging face incident report (Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July …
The 2026-07-28 Model Context Protocol specification is out. One interesting addition for application security:
List results are …
Misconfigured GraphQL implementations can allow for attackers to bypass authorization and access internal APIs. These “secondary context attacks” exploit the gap between GraphQL’s frontend interface and backend REST services, often turning …
The @trickest Inventory project is an interesting resource. It has a …
In this two part series we are going to take Burp Suite Project files as input from the command line, parse them, and then feed them into a testing pipeline.
The series is broken down into two parts:
In this two part series we are going to take Burp Suite Project files as input from the command line, parse them, and then feed them into a testing pipeline.
The series is broken down into two parts: