<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Ryan Sacatani</title>
  <link>https://sacatani.com/</link>
  <description>Simply curious about the world, constantly building and breaking things for fun.</description>
  <language>en</language>
  <atom:link href="https://sacatani.com/feed.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>The Evolution of Penetration Testing</title>
    <link>https://sacatani.com/writing/ai-pentesting-continuous-testing/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/ai-pentesting-continuous-testing/</guid>
    <pubDate>Wed, 23 Sep 2026 12:00:00 GMT</pubDate>
    <description>I used to spend most of my time testing web applications. My first look at AI pentesting products suggests the market is moving from point-in-time reports toward continuous, context-rich security testing.</description>
  </item>
  <item>
    <title>MCP Attacks on Xata and GitHub MCP: Read-Only Bypass and Issue Injection</title>
    <link>https://sacatani.com/writing/mcp-tools-trust-too-much/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/mcp-tools-trust-too-much/</guid>
    <pubDate>Tue, 22 Sep 2026 12:00:00 GMT</pubDate>
    <description>A first-person walkthrough of two MCP attack labs: a Xata-style read-only SQL bypass and a GitHub public-issue injection that exposed the difference between model safety and application security.</description>
  </item>
  <item>
    <title>The MCP confused deputy problem</title>
    <link>https://sacatani.com/writing/mcp-confused-deputy-problem/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/mcp-confused-deputy-problem/</guid>
    <pubDate>Sun, 20 Sep 2026 12:00:00 GMT</pubDate>
    <description>A hands-on MCP lab showed how a valid tenant key can still retrieve another tenant's project when the server never checks resource ownership.</description>
  </item>
  <item>
    <title>MCP security labs: path bypasses and poisoned tool responses</title>
    <link>https://sacatani.com/writing/mcp-filesystem-prefix-bypass-response-poisoning/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/mcp-filesystem-prefix-bypass-response-poisoning/</guid>
    <pubDate>Sun, 20 Sep 2026 12:00:00 GMT</pubDate>
    <description>Two MCP labs showed different failures at the same boundary: a filesystem server trusted a string prefix, while a facts server poisoned the agent's next tool call.</description>
  </item>
  <item>
    <title>MCP security: when prompt injection gets a tool</title>
    <link>https://sacatani.com/writing/mcp-security-new-attack-surface/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/mcp-security-new-attack-surface/</guid>
    <pubDate>Sat, 19 Sep 2026 12:00:00 GMT</pubDate>
    <description>MCP makes it easier for AI systems to use external tools. It also connects model behaviour to permissions, private data, and real actions.</description>
  </item>
  <item>
    <title>Poisoning an AI assistant's memory</title>
    <link>https://sacatani.com/writing/poisoning-mindfulchat-memory/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/poisoning-mindfulchat-memory/</guid>
    <pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate>
    <description>Lakera's MindfulChat challenge made persistent memory feel like a real application attack surface, not just a model prompt.</description>
  </item>
  <item>
    <title>An interactive playground for LLM security testing</title>
    <link>https://sacatani.com/writing/interactive-playground-llm-security/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/interactive-playground-llm-security/</guid>
    <pubDate>Wed, 16 Sep 2026 12:00:00 GMT</pubDate>
    <description>I worked through an interactive OWASP LLM Top 10 playground and found a useful starting map, a few strong concepts, and several labs that needed more explanation.</description>
  </item>
  <item>
    <title>Web LLM attacks, deeper into indirect prompt injection</title>
    <link>https://sacatani.com/writing/web-llm-attacks-deeper/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/web-llm-attacks-deeper/</guid>
    <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
    <description>Indirect prompt injection and insecure output handling showed me that an LLM can turn ordinary application content into an attack path.</description>
  </item>
  <item>
    <title>Web LLM attacks</title>
    <link>https://sacatani.com/writing/web-llm-attacks/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/web-llm-attacks/</guid>
    <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
    <description>Mapping an LLM's tools first turned two PortSwigger labs into the same repeatable web-testing method.</description>
  </item>
  <item>
    <title>Building and breaking mobile applications</title>
    <link>https://sacatani.com/writing/secure-systems-for-mobile-applications/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/secure-systems-for-mobile-applications/</guid>
    <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
    <description>I spent a year at EY breaking mobile apps, then built one at MacroScope and had to defend against everything I used to find. The one lesson that carried across both sides.</description>
  </item>
  <item>
    <title>Senior in 18 months, and a red team built from nothing</title>
    <link>https://sacatani.com/writing/senior-and-a-red-team-from-scratch/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/senior-and-a-red-team-from-scratch/</guid>
    <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
    <description>How I got onto a red team that did not exist yet, and the printer that got us onto a network that thought it was locked down.</description>
  </item>
  <item>
    <title>My first offensive security job</title>
    <link>https://sacatani.com/writing/joining-ey-as-an-associate-pentester/</link>
    <guid isPermaLink="true">https://sacatani.com/writing/joining-ey-as-an-associate-pentester/</guid>
    <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
    <description>I applied for one job, had one interview, and got it. What the first year of pen testing actually looked like.</description>
  </item>
</channel>
</rss>
