RESEARCH & NOTES
Blog
Notes from engagements, breakdowns of what's showing up in the Threat Intelligence feed, and our take on how the three surfaces actually fail in practice.
Internal RAG
The RAG Permission Blind Spot Nobody Tests For
Why retrieval quietly ignoring document-level permissions is the most common finding in RAG assessments — and the cheapest one to have caught early.
Read the post →
Coming soon
Agentic Workflows
[Draft] What Goal-Hijacking Actually Looks Like in a Tool-Calling Agent
[Placeholder — replace with a real post once written. Suggested angle: a walkthrough of a realistic tool-chain abuse scenario and the least-privilege fix.]
Coming soon
Customer Chatbots
[Draft] Why Channel-Consistency Is the Overlooked Chatbot Vulnerability
[Placeholder — replace with a real post once written. Suggested angle: how attackers probe the weakest of web/mobile/voice rather than the strongest.]