the lab notebook. writeups land here when the work holds up, not a day before.
2026-09-12
The anti-phishing group that jacks your Ollama to write its reports
an llmjacking honeypot, a quarter-million captured requests, and the anti-phishing org that showed up in its own prompt. 250k inference requests from one ip, ten languages per domain, and a tls cert that named the sender.
2026-09-03
The detection rules that passed every test and never fired once
i detonated a full ad attack chain against my own wazuh + sysmon lab and scored every phase: detect vs void. two custom rules passed the vendor's own logtest and had never fired in production. three stacked bugs, one green check.
2026-07-16
The nvidia-smi line that hid a botnet's wallet
a too-permissive sudo shim, a sealed detonation lab, and four rounds of fake C2 to pull a diicot cryptomining crew's live zephyr wallet out of a $6 honeypot.
[01]
P25 side channels
what a control channel gives away through timing, power, and iq, before anyone touches an encrypted frame.
[02]
WPA3 downgrade
how far a modern client can be pushed back down the sae handshake, and where it holds.
[03]
LLM agent security
where a tool-calling agent can be steered: injected prompts, poisoned context, and the paths that leak out.