Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 141

All research.

OWASP ASI07 Explained: Insecure Inter-Agent Communication
Adversarial & AI SecurityJun 23, 2026·13 min

OWASP ASI07 Explained: Insecure Inter-Agent Communication

OWASP ASI07 (Insecure Inter-Agent Communication) explained: how agents trust each other too much, relay malicious instructions, and amplify prompt injection.

Read
OWASP ASI09 Explained: Human-Agent Trust Exploitation
Jun 19, 2026·11 min

OWASP ASI09 Explained: Human-Agent Trust Exploitation

OWASP ASI09 (Human-Agent Trust Exploitation) explained: how AI agents exploit anthropomorphism, authority bias, and confirmation fatigue to drive harmful approvals.

Read
OWASP ASI06 Explained: AI Memory & Context Poisoning
Jun 16, 2026·11 min

OWASP ASI06 Explained: AI Memory & Context Poisoning

OWASP ASI06 (Memory and Context Poisoning) explained: RAG corruption, vector store attacks, persistent context bias. How to defend AI agent memory layers.

Read
Postmark MCP Supply-Chain Attack: ASI04 in Production
Jun 12, 2026·11 min

Postmark MCP Supply-Chain Attack: ASI04 in Production

September 2025 Postmark MCP supply-chain attack: trojanised npm package BCC'd every email to attacker. The OWASP ASI04 worked example, fully analysed.

Read
OWASP ASI03 Explained: AI Agent Identity & Privilege
Jun 9, 2026·10 min

OWASP ASI03 Explained: AI Agent Identity & Privilege

OWASP ASI03 (Identity and Privilege Abuse) explained: how AI agents inherit, share, and escalate authority. Real CVEs, multi-tenant bypasses, and mitigations.

Read
EscapeRoute Explained: Anthropic Filesystem MCP CVEs
Jun 5, 2026·13 min

EscapeRoute Explained: Anthropic Filesystem MCP CVEs

CVE-2025-53109 & CVE-2025-53110 (EscapeRoute): symlink and path-prefix bypass in Anthropic's Filesystem MCP. Mechanism, impact, sandbox lessons.

Read
OWASP ASI01 Explained: AI Agent Goal Hijacking
Adversarial & AI SecurityJun 2, 2026·12 min

OWASP ASI01 Explained: AI Agent Goal Hijacking

OWASP ASI01 (Agent Goal Hijack) explained: how prompt injection redirects AI agent objectives. Direct, indirect, and tool-mediated patterns with mitigations.

Read
Agentic DeFi security: when AI agents control treasury, trading, and liquidations
Adversarial & AI SecurityJun 1, 2026·21 min

Agentic DeFi security: when AI agents control treasury, trading, and liquidations

AI agents now autonomously control DeFi treasuries, execute trades, and trigger liquidations. The cross-layer attack surface that contract audits cannot see.

Read
The Case for Interactive-Only Pedagogy: How Zealynx Academy Teaches Differently
Zealynx NewsJun 1, 2026·14 min

The Case for Interactive-Only Pedagogy: How Zealynx Academy Teaches Differently

Zealynx Academy uses no videos, no slides, no passive content. Every section is interactive. Here's the pedagogical argument for why that works better for Web3 builders — and the specific design patterns behind it.

Read
CVE-2025-49596: Anthropic MCP Inspector RCE Explained
Adversarial & AI SecurityMay 29, 2026·12 min

CVE-2025-49596: Anthropic MCP Inspector RCE Explained

CVE-2025-49596 (CVSS 9.4 Critical): unauthenticated RCE in Anthropic's MCP Inspector. How the proxy architecture failed, the patch (v0.14.1), and lessons for MCP dev tools.

Read
How to Build Compound V2 From Scratch (18 Sections, Line by Line)
DeFi Protocol AnalysisMay 28, 2026·13 min

How to Build Compound V2 From Scratch (18 Sections, Line by Line)

Rebuild Compound V2 from scratch — cTokens, Comptroller, InterestRateModel, and liquidation logic. The second-most-forked DeFi protocol, understood end to end.

Read
Long-Lived Agents: Delayed Execution Risk
Adversarial & AI SecurityMay 27, 2026·14 min

Long-Lived Agents: Delayed Execution Risk

Why long-lived AI agents fail across time, not just prompts. Practical audit checks for delayed execution, stale approvals, and memory-driven authority drift.

Read