// research & write-ups

blog

2026.08.23
web security

SSRF: Server-Side Request Forgery Explained

What SSRF is, how attackers make your server reach the internal network and cloud metadata, what it leads to (up to RCE) and how to defend. A practical breakdown.

read

2026.08.23
ai security

Agentic AI Threat Modeling, Explained

What agentic AI threat modeling is and how to map trust boundaries, tools and actions for autonomous agents before you build — using OWASP Agentic and the MAESTRO approach.

read