Writing
pwnloop, fifty-one machines
A month after the first root, the autonomous loop has taken fifty-one lab machines from an IP to root and cleared a Pro Lab the platform itself certified. The count is the proof. The meth...
"Not worth a CVE": the mailpit deny-list, and CVE-2026-84697
A maintainer read my report, agreed with every claim in it, shipped the fix in two minutes and declined to request an identifier. I think the decision was defensible and still wrong, and ...
CVE-2026-84207: a good SSRF guard that two WebSocket paths never called
The SSRF I reported in heym: an egress guard that handles NAT64, 6to4, Teredo and DNS rebinding, and two dials that never ask it anything. The predicate was never the problem — the wiring...
CVE-2026-73530: reaching loopback through the IPv6 unspecified address
An SSRF guard bypass I reported in flyto-core: the denylist blocks 0.0.0.0 twice over and its IPv6 twin :: not at all — and the stack routes :: straight to the local host.
CVE-2026-64941: an open redirect in the guard that prevents open redirects
The open redirect I reported in Phoenix LiveView — in validate_local_url!/2, the guard whose entire job is keeping a redirect target on your own origin. It never looked at the three chara...
pwnloop, one week in
Eight days ago it was a container and a 200-line skill file. It has since rooted seventeen machines and taken a Pro Lab end to end — and every path it had to work out on the way is now wr...
pwnloop lab mode: a Pro Lab in four and a half hours
Campaign mode points the loop at a network instead of a box — a frontier, a credential matrix, tunnels that prove themselves. Its first run took HTB's free Puppet mini Pro Lab end to end:...
pwnloop: an autonomous engagement loop for lab machines
Hand it an IP and it runs recon to root to cleanup to report without checking in — then rewrites its own methodology before it is allowed to finish.
I ran a full cloud forensic investigation with an AI agent. It cost $67.
And 99% of that bill was the model re-reading context it had already been given. If you budget for this work by counting what the model writes, you will be wrong by roughly 7×.
Cloud Forensics in the Age of AI Agents: A Field Report
One compromised credential, twenty days, seventeen regions — reconstructed twice from independent sources. What the agent changed, where it was confidently wrong, and what a human still h...
Securing Fintech Apps in 2025: Addressing Modern Threats with Adaptive Defenses
Fintech is at the center of today’s digital transformation, blending finance and technology at a breakneck pace. As attackers get more sophisticated and compliance pressure increases, sec...
Cultivating a Cost-Aware Culture for High-Performance Payment Systems on AWS
In the world of digital payments, businesses must maintain high performance, scalability, and reliability while keeping cloud costs under control. Amazon Web Services (AWS) provides a pow...