23/07/2025CVE-2025-29927 - Next.js VulnerabilityOverview In March 2025, security researchers Rachid Allam and Yasser Allam publicly disclosed a critical vulnerability identified as CVE-2025-29927,…
12/07/2025Summary of Hacking LLM Workshop at Code Europe 2025I hosted a workshop on Hacking LLMs at Code Europe 2025, where participants were tasked with two labs: Supply chain...
09/07/20252022 Optus Data Breach IncidentIncident Analysis: 2022 Optus Data Breach Overview In September 2022, Optus, Australia’s third-largest telecommunications provider, suffered a…
04/06/2025Progress Telerik UI Unsafe DeserializationIn November 2024, a critical remote code execution (RCE) vulnerability was disclosed in Progress Telerik UI for WinForms, registered as...
15/05/2025NIST - Guidelines for API Protection for Cloud-Native SystemsGuidelines for API Protection for Cloud-Native Systems In March 2025 the National Institute of Standards and Technology (NIST) released a...
29/03/2025LLM to RCE using "broken pickles"In February 2025, researchers from Reverse Engineering Labs uncovered malicious ML models hosted on Hugging Face. These models exploited ‘broken’...
18/03/2025LLM security is broken, here is the dataIt became apparent to me that there are fundamental security problems with LLMs, which make them very difficult to secure....
03/03/2025What is wrong with Escaping or Input SanitizationThe earliest documented instance of Path Traversal vulnerability is Windows 95 “Dot Dot” bug that goes back to October 1995....
12/12/2024OWASP Mobile Top 10 Secure Coding ChallengesPlease find below a list of secure coding challenges for OWASP Mobile Top 10. The goal in each challenge is...