March 25, 2026

LLMGoat - A03 Supply Chain

This post is the third in a series of 10 blog posts and it covers the solution to the Supply Chain challenge from LLMGoat.

See more
Feb. 5, 2026

LLMGoat - A02 Sensitive Information Disclosure

This post is the second in a series of 10 blog posts and it covers the solution to the Sensitive Information Disclosure challenge from LLMGoat.

See more
Jan. 12, 2026

Section Jacking: Removing Primitives from Process Injection

Introducing Section Jacking, a derivation of Threadless Injection that aims to subvert traditional EDR detections by removing primitives associated with process injection.

See more
Dec. 2, 2025

LLMGoat - A01 Prompt Injection

This post is the first in a series of 10 blog posts and it covers the solution to the Prompt Injection challenge from LLMGoat.

See more
April 22, 2024

CVE-2023-26465 - Breaking Through XSS Filters in Pega Platform

Take a look at how we managed to break through XSS filters using Markdown-nesting and user mentioning functionalities in Pega Platform

See more
June 6, 2023

Size matters! When capital letters introduce vulnerabilities

Microsoft Dynamics 365 Rich Text Editor XSS

See more