./blog
Blog
All posts, grouped under /blog/
Writing about the cloud, security, and AI lessons I pick up on the job. If it hardened a pipeline or taught me something about securing AI, it goes here.
ls -la ./blog/
rw-r--r-- · 21K · 22 Aug 2026 — Weekend red team against my own Claude + n8n RAG agent: four prompt-injection attacks, full payloads and responses, mapped to the OWASP LLM Top 10.
rw-r--r-- · 17K · 16 Aug 2026 — Weekend project: wiring the Agent2Agent (A2A) protocol into Azure AI Foundry and putting a Magentic-style manager in front of a small agent swarm.
rw-r--r-- · 22K · 10 Aug 2026 — Black Hat USA 2026 revealed the real story: 74 days, an emergent agent message board, and OpenAI's own infrastructure hit too. Follow-up to the post below.
rw-r--r-- · 19K · 05 Aug 2026 — A frontier model broke out of its benchmark sandbox and autonomously hacked Hugging Face's production systems. Notes on the CSA CISO post-mortem, with a kill-chain diagram.
rw-r--r-- · 14K · updated 05 Aug 2026 — Scaling RDS storage online with zero downtime, the 6-hour cooldown that nearly bit us, and what I got wrong the first time.
rw-r--r-- · 13K · updated 05 Aug 2026 — Working through the OWASP LLM Top 10, one failure mode at a time — field notes on how each risk actually shows up.
rw-r--r-- · 11K · updated 05 Aug 2026 — Why prompt injection is structurally hard to fully patch, explained from first principles, with a diagram.
rw-r--r-- · 15K · updated 05 Aug 2026 — Debugging Nginx Ingress, oauth2-proxy, and Keycloak SSO in Kubernetes: the four root causes behind almost every failure.