MCP tool poisoning hides instructions in a tool's description so an AI agent obeys the attacker while appearing to do your task. How it works and how to defend.
A breakdown of the OWASP API Security Top 10: BOLA, broken authentication, excessive data exposure and more. How APIs are attacked and how to secure them.
What SSRF is, how attackers make your server reach the internal network and cloud metadata, what it leads to (up to RCE) and how to defend. A practical breakdown.
What XSS is, how reflected, stored and DOM-based differ, how attackers steal sessions and data, and how to defend your site. A practical breakdown of cross-site scripting.
What IDOR (Insecure Direct Object Reference) is, how attackers reach other users' data by swapping an id, what it leads to and how to defend. A practical breakdown.
What agentic AI threat modeling is and how to map trust boundaries, tools and actions for autonomous agents before you build — using OWASP Agentic and the MAESTRO approach.
What an LLM jailbreak is, the main techniques (role-play, encoding, multi-turn), and how to defend the model. Why guardrails are a barrier, not a wall.