Blog
Practical material on offensive security and compliance - no marketing fluff.
The MyDr attack: what we actually know about the medical data breach
Attackers claim they stole 2.5 TB of data and 18.8 million PESEL numbers from the MyDr platform. We break down the incident: the claimed vector (XXE in PKCS#12 → GitHub key → AWS), what was verified, the attribution and false-flag question, and how to defend - claims kept separate from facts.
Read more 10 August 2026Attack analysis / AIBioShocking: the prompt injection that turns an AI browser into a password thief
LayerX showed how a fake web-page game convinces an AI browser in agent mode that the normal rules no longer apply - and gets it to steal credentials. We explain the indirect prompt injection mechanism, show the payload anatomy, and how to defend.
Read more 10 August 2026Attack analysis / AIGTG-1002: the first cyber-espionage campaign run by an AI agent
Anthropic documented the first cyber-espionage campaign in which an AI agent ran 80-90% of the work - reconnaissance, writing exploits, harvesting credentials and exfiltration. Humans approved only 4-6 decisions. We break down the mechanism, the social-engineering jailbreak, and the defence.
Read more 24 July 2026Attack analysis / AIJadePuffer: the ransomware attack an AI agent ran itself (from breach to ransom note)
Sysdig documented the first ransomware attack in which an LLM agent ran the whole technical job - recon, credential theft, lateral movement, encryption and the ransom note. We break down the chain step by step, show the bug it fixed in 31 seconds, and explain why this is genuinely new.
Read more 13 July 2026Vulnerability analysis / AIAttacking an AI platform: the Langflow chain (CVE-2026-33017 + CVE-2026-55255)
The first AI agent platform in the CISA KEV catalog. Unauthenticated RCE on the host, an IDOR takes other tenants' flows. Both lead to OpenAI, AWS and database keys. We break down the real-world attack chain and how to defend.
Read more 12 July 2026Privacy / OSINTGDID: the Windows identifier a VPN won't hide
Windows 11 assigns every installation a persistent Global Device Identifier. In July 2026 an FBI filing showed how a GDID located a user despite a VPN. We explain what it is, how it tracks, and why a network tunnel isn't enough.
Read more 12 July 2026Vulnerability analysisAnatomy of an RCE: how Log4Shell worked (CVE-2021-44228)
A single string in an HTTP header, full server takeover. We break down the Log4Shell attack chain step by step - with diagrams, a sample request and layered defence.
Read more 10 July 2026ComplianceNIS2 in practice: where to start before the auditor arrives
Registration by October 2026, measures in place by April 2027, the first audit a year later. Five steps worth taking in this order - and the mistakes that most often surface during audits.
Read more// no results