All posts

New posts as engagements turn up something worth sharing — check back regularly.

Supply Chain Security
August 23, 20265 min read

LiteLLM Supply Chain Attack: How a 36-Byte .pth File Became a Credential Theft Path

A serious LiteLLM supply-chain compromise exposed how a tiny 36-byte Python .pth file could trigger code execution automatically at interpreter startup. This article breaks down the attack chain, credential theft risk, safe PoC demonstration, indicators of compromise, and key defensive lessons for security teams.

Read post
AI Security
August 18, 20266 min read

AI Agent Hacks Gym Website: What This Australian Incident Means for Cybersecurity

An AI agent reportedly discovered and exploited weaknesses in an Australian gym booking system while trying to complete a routine task. Here's what the incident teaches us about AI agents, API security, authorization and the emerging risks of autonomous systems.

Read post
Engagement Process
July 9, 20264 min read

Why Retesting Should Never Be Optional

A finding marked 'fixed' by the engineering team and a finding confirmed fixed by the people who broke it in the first place are not the same thing.

Read post
VAPT
July 22, 20265 min read

Grey Box vs Black Box: Picking the Right Pentest

The scoping decision most clients skip past — and why it changes what your report is actually worth.

Read post
Application Security
August 3, 20266 min read

OWASP Top 10 in 2026: What Actually Changed

The list looks familiar at a glance, but the underlying attack patterns behind each category have shifted more than most teams realize.

Read post