The reading room
Research on AI attack techniques and offensive security
How we think about what we test, written up with the framework ids attached. Every piece answers its question in the first paragraph, cites its sources in the margin, and ends with what to do about it.
- Published
- 8
- Method
- V1.0
- Advisories
- 0
Published research
What is prompt injection?
Why a model obeys text it was only meant to read, direct and indirect, and the defences that hold.
LLM01:2026
Penetration testing versus vulnerability scanning
What each finds, what each misses, and when an automated scan is enough.
WSTG-BUSL
The OWASP Top 10 for LLM Applications 2026, explained
All ten risks of the 2026 edition, what moved since 2025, and how each one is tested.
LLM01 to LLM10:2026
Black box, grey box, white box pentests compared
What the tester knows in each, and how coverage per day changes.
WSTG-ATHZ
MCP security: risks and best practices
Model Context Protocol servers, from tool poisoning to over-broad tokens.
LLM01:2026
Denial of wallet: when the AI bill is the outage
How token, tool and API costs become an attack surface, how to test the caps, and which limits hold.
LLM06:2026
MITRE ATLAS explained: tactics, techniques and tests
How the knowledge base of attacks on AI systems is built, and how its ids become a test plan.
ATLAS 2026.09
How to prepare for a penetration test
Scope, accounts, environments, permissions and windows, so testing days go to testing.
No technique pieces are published yet.
No framework pieces are published yet.
No guides are published yet. The first ones cover pentest types, scanning and how to prepare for a test.
No advisories yet. An advisory is published here only after the vendor has had the chance to fix the issue.
No lab reports yet. A report lands here with its method and its data, or not at all.
How we write
Own lab, or already fixed
We write about systems we built to be broken, or about public issues their vendors have already fixed. Never about a client.
Ids checked at the source
Every OWASP and MITRE ATLAS id is checked against the publisher’s own document before it is printed, with the edition attached.
A source for every fact
Every factual sentence carries a numbered note in the margin, and every note names a document you can open and check.
Defensive by design
We explain how a risk works, what it costs and how to test for it at the level of structure. No payloads, no recipes.
Ends with the fix
Every piece closes on the controls that would have stopped the attack, and on what they do not stop.
Reviewed before launch
A named security lead reviews each piece before it is published. Until then its byline says the review is pending.
Found a vulnerability in something we wrote about, or in this site? Our disclosure policy says how to reach us, and advisories explains how we publish our own.