active defense and adversarial agents: context bombs
From Tracebit’s
active defense and adversarial agents: exploding search space (academic)
in previous posts we have been looking at different active defense approaches: guardrail triggers, token burn, hostname beacon, malicious skills, context bombs, service sandbagging, GCG attacks, and making a working attack expensive to maintain. I want to …
active defense and adversarial agents: malicious skills
in the previous post we looked at hostname beacons. this time: malicious skills.
active defense is the practice of planting traps that force an agent to reveal itself or change the economics of its operation.
skills are a high-signal trap because they are …
active defense and adversarial agents: hostname beacon
in the previous post we opined on token burns in active defense, this time we will consider hostname beacons.
first, active defense is the practice of placing traps that force an attacker or automated agent to reveal itself or interrupt its own workflow rather …
active defense and adversarial agents: token burn
sticking with the theme of applied active defense (previous post), I wanted to explore token burn (lots of names here; unbounded consumption
active defense and adversarial agents: guardrail triggers
the previous post briefly touched on active defense in the scope of AI agents and LLMs. active defense is the practice of placing traps and tripwires that force an attacker (or an automated agent) to reveal itself or interrupt its own workflow rather than …
rethinking threat models when the cost is tokens not time
another by-product of anatomy of a frontier lab agent intrusion: a technical timeline of the july 2026 incident is that the adversary …
Bespoke C2 - LLM era
After reading the most recent hugging face incident report (Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July …
MCP list caching and tool poisoning
The 2026-07-28 Model Context Protocol specification is out. One interesting addition for application security:
List results are …
Exploiting GraphQL Secondary Context Attacks
Misconfigured GraphQL implementations can allow for attackers to bypass authorization and access internal APIs. These “secondary context attacks” exploit the gap between GraphQL’s frontend interface and backend REST services, often turning …