Technical writeups, disclosures, and deep-dives from our team.
An autonomous agent reached cluster-admin on Hugging Face's production infrastructure in a weekend. There was no adversary, just a model optimizing for a benchmark score. What the timeline confirms about agentic attackers, and why it raises the bar for trusting your detection stack.
Read writeup →A penetration test is a photograph: one environment, one narrow window, one team. Why a point-in-time test can't describe an attack surface that changes every day, and the case for continuous validation.
Read writeup →A plain-language explainer on what a large language model actually is: a next-token predictor scaled up until prediction starts to look like competence. Where LLMs came from, how they're trained, what they can't do alone, and why that matters for security tooling.
Read writeup →The threat-hunting feedback loop works because attackers repeat themselves. Agentic attackers don't. We read the hunt from the offensive side and show where it breaks when the adversary generates a signature-free variant per target.
Read writeup →We pointed an agentic bypass generator at a major commercial WAF under bug-bounty safe harbor. It produced 652 reproducible edge evasions, and showed why static rules lose to a loop that learns.
Read writeup →We publish what we find so defenders can fix it first. Want this applied to your environment? Talk to us about ThreatWell.