Everything
Sharing this for anyone that may find it helpful.
- The Evolution of Penetration TestingDay 9 of 100 · AI cybersecurity
I used to spend most of my time testing web applications. My first look at AI pentesting products suggests the market is moving from point-in-time reports toward continuous, context-rich security testing.
- MCP Attacks on Xata and GitHub MCP: Read-Only Bypass and Issue InjectionDay 8 / 100 · AI cybersecurity
A first-person walkthrough of two MCP attack labs: a Xata-style read-only SQL bypass and a GitHub public-issue injection that exposed the difference between model safety and application security.
- The MCP confused deputy problemDay 6 / 100 · AI cybersecurity
A hands-on MCP lab showed how a valid tenant key can still retrieve another tenant's project when the server never checks resource ownership.
- MCP security labs: path bypasses and poisoned tool responsesDay 7 / 100 · AI cybersecurity
Two MCP labs showed different failures at the same boundary: a filesystem server trusted a string prefix, while a facts server poisoned the agent's next tool call.
- MCP security: when prompt injection gets a toolDay 5 / 100 · AI cybersecurity
MCP makes it easier for AI systems to use external tools. It also connects model behaviour to permissions, private data, and real actions.
- Poisoning an AI assistant's memoryDay 4 / 100 · AI cybersecurity
Lakera's MindfulChat challenge made persistent memory feel like a real application attack surface, not just a model prompt.
- An interactive playground for LLM security testingDay 3 / 100 · AI cybersecurity
I worked through an interactive OWASP LLM Top 10 playground and found a useful starting map, a few strong concepts, and several labs that needed more explanation.
- Web LLM attacks, deeper into indirect prompt injectionDay 2 / 100 · AI cybersecurity
Indirect prompt injection and insecure output handling showed me that an LLM can turn ordinary application content into an attack path.
- Web LLM attacksDay 1 / 100 · AI cybersecurity
Mapping an LLM's tools first turned two PortSwigger labs into the same repeatable web-testing method.
I spent a year at EY breaking mobile apps, then built one at MacroScope and had to defend against everything I used to find. The one lesson that carried across both sides.
How I got onto a red team that did not exist yet, and the printer that got us onto a network that thought it was locked down.
I applied for one job, had one interview, and got it. What the first year of pen testing actually looked like.























