Blog
Short, technical write-ups on vulnerabilities, attack paths, and what we're seeing in the field.
RESEARCH · THREAT INTELLIGENCE
The place practitioners come for real vulnerability research — how attacks actually work, what we're seeing across AI and agent systems, and what it means for the standards you report on. Written by the operators who run the engagements.
LATEST RESEARCH
Vulnerability write-ups, threat intel, and analysis from live engagements.
An agent tool-abuse walk-through: how low-privilege input becomes privileged execution — without touching the admin UI.
ReadRed team exercises as an organizational control under NIST 800-53 Rev. 5 — what to expect, and how to prepare now.
ReadVector-DB poisoning and embedding inversion in practice — and why retrieval security belongs in your threat model.
ReadAn anonymized engagement teardown — recon to reproduction — showing business impact, not just CVSS.
ReadHow our operators think about pre-emption — running the attack before there's an attacker on it.
ListenA recorded demonstration of incremental prompt escalation, and the guardrail design that stops it.
WatchWHERE TO FIND IT
Whichever way you learn best, the research is the same — written and recorded by the operators who run the engagements.
Short, technical write-ups on vulnerabilities, attack paths, and what we're seeing in the field.
Deeper analysis and methodology — the reference material your team can cite internally.
Recorded demonstrations of real techniques, from prompt injection to lateral movement.
Conversations with operators on how modern attacks — and modern defenses — actually work.
New vulnerability write-ups, threat intel, and engagement teardowns — straight to your inbox.
Subscribe to Override research