All posts
Topic
Llm Security
4 articles on llm security.
When Correct Security Controls Still Leak: The CONTINUITY Paper on Composable Agent Security
A plain-English CISO read of CONTINUITY (arXiv:2609.05269): why individually correct LLM-agent security controls fail to compose, the "security-context discontinuity" failure mode, how CONTINUITY carries authenticated context across every boundary, and its result โ zero harmful effects across 2,560 attack instances while completing all benign tasks and escalating every ambiguous case.
September 7, 2026
OWASP MCP Governance & Risk: Should You Let That MCP Server Into Your Environment?
A CISO guide to the OWASP MCP Governance & Risk Project: the four non-negotiable gates (owner, logging, scope, review), the Tier 0-4 classification, the eight-factor risk model, and how it maps to the OWASP MCP Top 10, LLM Top 10, NIST AI RMF, ISO 42001 and SOC 2. Plus a free tool that runs the check for a specific server.
September 7, 2026
Abliterated Models Explained: What Refusal-Removed LLMs Like GLM-5.3-Cybersecurity Mean for Your Threat Model
A CISO guide to abliterated models: how "abliteration" surgically removes an LLM's refusal behaviour without retraining, why refusal-removed offensive-security releases such as GLM-5.3-CYBERSECURITY-FP8 are spreading on Hugging Face, where the real risk sits (shadow AI on laptops and agents with tools), how to detect them in your environment, and a free calculator that scores the risk of a specific deployment.
September 6, 2026
AI Recon on AI Infrastructure: What Hackers Are Looking For (and How to Defend It)
As AI becomes operational infrastructure, attackers are developing reconnaissance techniques specifically targeting AI APIs, model endpoints, embedding stores, and training pipelines. Here's what the threat surface looks like.
July 13, 2026