0xSebin

home-banner-background home-banner-background
0xSebin

0xSebin

  • HOME
  • CATEGORIES
  • TAGS
  • LINKS
  • HOME
  • CATEGORIES
  • TAGS
  • LINKS
47
Tags
8
Categories
21
Posts
0xSebin
Normal one. Normal days.
Tags Categories
Sebin Thomas
47
Tags
8
Categories
21
Posts
  • LLM02: Sensitive Information Disclosure

    LLM02: Sensitive Information Disclosure

    This is my running logbook for LLM02: Sensitive Information Disclosure - #2 in the OWASP Top 10 for LLM Applications (2026). Same format as the Prompt Injection log: a new hands-on writeup here eac...
      2026-08-22  
    • AI Security 
     
    • Security 
    • | AI Security 
    • | LLM Security 
    Read moreLLM02: Sensitive Information Disclosure 
  • LLM10: Improper Output Handling

    LLM10: Improper Output Handling

    This is my running logbook for LLM10: Improper Output Handling - #10 in the OWASP Top 10 for LLM Applications (2026), and the most “classic AppSec” of the lot. Same format as the Prompt Injection l...
      2026-08-22  
    • AI Security 
     
    • Security 
    • | AI Security 
    • | LLM Security 
    Read moreLLM10: Improper Output Handling 
  • PortSwigger Web LLM Attacks: Lab Index & Writeups

    PortSwigger Web LLM Attacks: Lab Index & Writeups

    PortSwigger’s Web Security Academy has a small, sharp topic called Web LLM attacks - four labs on attacking LLM-backed web apps: mapping what a model can reach, abusing its tools, and treating its ...
      2026-08-21  
    • AI Security 
     
    • Security 
    • | AI Security 
    • | LLM Security 
    Read morePortSwigger Web LLM Attacks: Lab Index & Writeups 
  • LLM03: Excessive Agency

    LLM03: Excessive Agency

    This is my running logbook for LLM03: Excessive Agency - #3 in the OWASP Top 10 for LLM Applications (2026), and the biggest climber on the 2026 list. Same format as the Prompt Injection log: a new...
      2026-08-21  
    • AI Security 
     
    • Security 
    • | AI Security 
    • | LLM Security 
    Read moreLLM03: Excessive Agency 
  • LLM01: Prompt Injection

    LLM01: Prompt Injection

    This is my running logbook for LLM01: Prompt Injection - the top entry in the OWASP Top 10 for LLM Applications (2026). One vulnerability class, lots of different disguises. Rather than write a sep...
      2026-08-14  
    • AI Security 
     
    • Security 
    • | AI Security 
    • | LLM Security 
    Read moreLLM01: Prompt Injection 
  • OWASP Top 10 for LLM Applications (2026): A Beginner's Field Guide

    OWASP Top 10 for LLM Applications (2026): A Beginner's Field Guide

    Every company I look at these days has quietly wired a language model into something that matters. A support bot that can read the ticketing system. A coding copilot with access to the repo. An “as...
      2026-08-14  
    • AI Security 
     
    • Security 
    • | AI Security 
    • | LLM Security 
    Read moreOWASP Top 10 for LLM Applications (2026): A Beginner's Field Guide 
  • Common Active Directory Misconfigurations and Where to Find Them

    Common Active Directory Misconfigurations and Where to Find Them

    “You don’t need a zero-day. You just need to look harder.” Every time I drop into an internal network during a pentest or a red team engagement, the story is always the same - the domain is a gol...
      2025-12-26  
    • Real-World Pentest 
     
    • Security 
    • | Active Directory 
    • | Red Team 
    Read moreCommon Active Directory Misconfigurations and Where to Find Them 
  • Gophish - Setting up without Evilginx - Part 2

    Gophish - Setting up without Evilginx - Part 2

    GoPhish End-to-End Setup for Credential CaptureIn this second part, I will be configuring GoPhish from start to end, up to the point where we successfully capture the credentials of a phished user....
      2025-12-25  
    • Phishing 
     
    • Phishing 
    • | Red Teaming 
    • | GoPhish 
    Read moreGophish - Setting up without Evilginx - Part 2 
123
© 2024 - 2026    Sebin Thomas

21 posts in total 51.3k words in total

POWERED BY Hexo THEME Redefine v2.9.0
Blog up for days hrs Min Sec
EXIF