1. Blacksec

    Agent Red Teaming 2026: Static Benches Die

    Hey hackers - agent red teaming outgrew the prompt fuzzer somewhere between the first tool call and the first exploit chain that never touched the user's input. The scoring harness now decides what "secure" means, and modern agent red teaming lives or dies by what that harness can see. In 2026...
  2. Blacksec

    Indirect Prompt Injection 2026: The Web Fights Back

    Hey hackers - indirect prompt injection went from research curiosity to the top line of the OWASP agentic risk register in about eighteen months. The payload never touches your prompt. It waits in an email, a web page, a log line, an ad - and the agent reads it for you. TL;DR: Google's threat...
  3. Blacksec

    Memory Poisoning 2026: The Write That Outlives the Session

    Hey hackers - the memory poisoning of 2026 is a single adversarial write that outlives the session, the prompt, and often the vendor's own filters. A memory poisoning attack in 2026 needs no direct memory access - the agent writes the payload itself, then retrieves it next Tuesday without you in...
  4. Blacksec

    MCP Supply Chain 2026: One STDIO Interface to Rule Them All

    Hey hackers - the mcp supply chain of 2026 is one STDIO interface, ten CVEs, and a protocol vendor calling arbitrary command execution expected behavior. An mcp supply chain attack in 2026 does not need a memory corruption bug - it needs a JSON field called command, an argument called args, and...