DEV Community

Cor E profile picture

Cor E

I'm an automation engineer, pentester, dev, network arch & *nix guru I curate & create my own content. AI helps draft/edit some posts — final review & editorial judgment are mine.

Location Tokyo, Japan Joined Joined on  Personal website https://skyblue-soft.com/blog/

Work

Freelance Dev, Pentester, Automation Work, Network Architect - Founder of Sentinel-Proxy AI Firewall

GhostSplice Isn't a Jailbreak, It's a Reminder That LLMs Can't Do Access Control

GhostSplice Isn't a Jailbreak, It's a Reminder That LLMs Can't Do Access Control

1
Comments
3 min read

Want to connect with Cor E?

Create an account to connect with Cor E. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
OpenAI Paused Astra for Cyber Risk. Your Agent's Sandbox Escape Is the Same Problem, Smaller Scale

OpenAI Paused Astra for Cyber Risk. Your Agent's Sandbox Escape Is the Same Problem, Smaller Scale

2
Comments
5 min read
A Sandbox Got Popped at Black Hat. Nobody Should Be Shocked.

A Sandbox Got Popped at Black Hat. Nobody Should Be Shocked.

1
Comments
3 min read
CSS Was Never "Just Styling," and Your AI Email Agent Just Found That Out the Hard Way

CSS Was Never "Just Styling," and Your AI Email Agent Just Found That Out the Hard Way

1
Comments
3 min read
A CVSS 10.0 in Your AI Coding Agent Is Just TOCTOU Wearing a Hoodie

A CVSS 10.0 in Your AI Coding Agent Is Just TOCTOU Wearing a Hoodie

1
Comments
3 min read
'PleaseFix': When Your AI Browser Trusts a Web Page More Than It Trusts You

'PleaseFix': When Your AI Browser Trusts a Web Page More Than It Trusts You

1
Comments
5 min read
'I Own This Server': How Attackers Are Talking AI Coding Agents Into Helping Them

'I Own This Server': How Attackers Are Talking AI Coding Agents Into Helping Them

1
Comments
6 min read
Sentinel now protects Gemini, Grok, and OpenAI agents too (not just Claude)

Sentinel now protects Gemini, Grok, and OpenAI agents too (not just Claude)

1
Comments
2 min read
I Built the Thing My Last Article Said Didn't Exist Yet

I Built the Thing My Last Article Said Didn't Exist Yet

2
Comments
4 min read
Your Sandbox Has a Hole in It, and the AI Agent Found It

Your Sandbox Has a Hole in It, and the AI Agent Found It

Comments
4 min read
The npm Worm That Learned to Trust Your AI Agent

The npm Worm That Learned to Trust Your AI Agent

Comments
3 min read
Your AI Scam Detector Trusts Fake Reviewers More Than You Think

Your AI Scam Detector Trusts Fake Reviewers More Than You Think

1
Comments
3 min read
No, Claude Didn't 'Go Rogue.' Someone Gave It Root and Wi-Fi.

No, Claude Didn't 'Go Rogue.' Someone Gave It Root and Wi-Fi.

1
Comments
3 min read
An LLM Attacked a Lab, Then Got Turned Around. That's Not the Scary Part.

An LLM Attacked a Lab, Then Got Turned Around. That's Not the Scary Part.

1
Comments
3 min read
trust_remote_code Was Always a Dare, Not a Safeguard

trust_remote_code Was Always a Dare, Not a Safeguard

1
Comments
3 min read
Wiring SlopScan into Claude Code — A Skill, a Hook, and a Bug I Almost Shipped

Wiring SlopScan into Claude Code — A Skill, a Hook, and a Bug I Almost Shipped

1
Comments
8 min read
Your Voice Assistant Can Be Social-Engineered Too, and Nobody's Watching For It

Your Voice Assistant Can Be Social-Engineered Too, and Nobody's Watching For It

1
Comments 4
3 min read
An "Autonomous" AI Attack Got Caught Because It Left the Door Open

An "Autonomous" AI Attack Got Caught Because It Left the Door Open

2
Comments 1
3 min read
Your Sandbox Isn't a Sandbox If It Can Reach Production

Your Sandbox Isn't a Sandbox If It Can Reach Production

1
Comments
3 min read
AI Harnesses Are Just Middleware, and Middleware Trust Bugs Are Older Than Your Career

AI Harnesses Are Just Middleware, and Middleware Trust Bugs Are Older Than Your Career

1
Comments 2
3 min read
Pironman 5 case fan stuck on after a Raspberry Pi OS kernel update? Here's the fix

Pironman 5 case fan stuck on after a Raspberry Pi OS kernel update? Here's the fix

1
Comments
4 min read
Copilot for Word Will Copy Its Own Poison Into Every Document It Touches

Copilot for Word Will Copy Its Own Poison Into Every Document It Touches

3
Comments
5 min read
Adversarial Comments Are Now a Vulnerability Detection Bypass Technique

Adversarial Comments Are Now a Vulnerability Detection Bypass Technique

1
Comments
5 min read
The Rogue AI Story Isn't About Rogue AI. It's About Credentials You Forgot Existed

The Rogue AI Story Isn't About Rogue AI. It's About Credentials You Forgot Existed

1
Comments
3 min read
BloodHound for AI Agents Means We've Officially Given Up Pretending This Is Simple

BloodHound for AI Agents Means We've Officially Given Up Pretending This Is Simple

2
Comments 6
3 min read
An AI Escaped a Sandbox to Cheat on Its Own Exam. Let's Not Bury That Lede.

An AI Escaped a Sandbox to Cheat on Its Own Exam. Let's Not Bury That Lede.

1
Comments
4 min read
The Irony Nobody's Talking About: US Frontier Models Needed a Chinese Model to Defend Against Themselves

The Irony Nobody's Talking About: US Frontier Models Needed a Chinese Model to Defend Against Themselves

2
Comments
3 min read
Your AI Guardrails Speak English Only — Here's the Multilingual Jailbreak Gap

Your AI Guardrails Speak English Only — Here's the Multilingual Jailbreak Gap

1
Comments
4 min read
An AI "Escaped Its Sandbox" — Or We Just Built a Bad Sandbox

An AI "Escaped Its Sandbox" — Or We Just Built a Bad Sandbox

1
Comments 2
3 min read
Your Safety Guardrails Just Became an Incident Response Blocker

Your Safety Guardrails Just Became an Incident Response Blocker

1
Comments
3 min read
The AI Supply Chain Attack Surface Nobody's Actually Checking

The AI Supply Chain Attack Surface Nobody's Actually Checking

2
Comments
13 min read
How an Autonomous Agent Breached Hugging Face — And What a RAG Poisoning Filter Would Have Stopped

How an Autonomous Agent Breached Hugging Face — And What a RAG Poisoning Filter Would Have Stopped

2
Comments 2
7 min read
We Just Handed AI Agents the Keys to the Password Vault. What Could Go Wrong?

We Just Handed AI Agents the Keys to the Password Vault. What Could Go Wrong?

1
Comments
3 min read
Your AI Coding Assistant Isn't Reading Your Code, It's Mailing It Home

Your AI Coding Assistant Isn't Reading Your Code, It's Mailing It Home

2
Comments 1
3 min read
Your AI Agent's Memory Is Now an Attack Surface, and Nobody Designed for That

Your AI Agent's Memory Is Now an Attack Surface, and Nobody Designed for That

1
Comments
3 min read
HalluSquatting: How Attackers Turn AI Coding Agents Into a Botnet Without Touching a Single Victim

HalluSquatting: How Attackers Turn AI Coding Agents Into a Botnet Without Touching a Single Victim

1
Comments 1
5 min read
GitLost Is a Preview of Every Agentic Workflow Breach You'll See This Year

GitLost Is a Preview of Every Agentic Workflow Breach You'll See This Year

1
Comments
3 min read
AI-Run Ransomware: The Autopilot Was Impressive, the Pilot Still Booked the Flight

AI-Run Ransomware: The Autopilot Was Impressive, the Pilot Still Booked the Flight

1
Comments
3 min read
183 Local Tools, Zero Guardrails: What Local MCP Gets Wrong About 'Privacy'

183 Local Tools, Zero Guardrails: What Local MCP Gets Wrong About 'Privacy'

Comments
3 min read
Your Coding Agent Is a New Attack Surface and Most Devs Aren't Ready for It

Your Coding Agent Is a New Attack Surface and Most Devs Aren't Ready for It

1
Comments
3 min read
Phantom Squatting: When AI Hallucinated Domains Become Attacker Infrastructure

Phantom Squatting: When AI Hallucinated Domains Become Attacker Infrastructure

1
Comments
5 min read
Agentjacking: How Fake Bug Reports Are Hijacking AI Coding Agents — and How to Stop It

Agentjacking: How Fake Bug Reports Are Hijacking AI Coding Agents — and How to Stop It

1
Comments 1
5 min read
282 AI Apps Are Handing Strangers Your API Bill — And Calling It a Product

282 AI Apps Are Handing Strangers Your API Bill — And Calling It a Product

1
Comments
3 min read
Your AI Agent Is Being Fed Lies, and Your Logs Won't Tell You

Your AI Agent Is Being Fed Lies, and Your Logs Won't Tell You

2
Comments
3 min read
GuardFall: When Decades-Old Shell Injection Tricks Beat Modern AI Safety Guardrails

GuardFall: When Decades-Old Shell Injection Tricks Beat Modern AI Safety Guardrails

1
Comments
5 min read
BioShocking: How AI Browsers Were Tricked Into Handing Over Your Passwords

BioShocking: How AI Browsers Were Tricked Into Handing Over Your Passwords

2
Comments
5 min read
Your AI Agents Are Privileged Identities. You're Treating Them Like Interns.

Your AI Agents Are Privileged Identities. You're Treating Them Like Interns.

1
Comments 1
3 min read
Palo Alto Unit 42 Caught Indirect Prompt Injection in the Wild — Here's What Your Agent Firewall Needs to Stop It

Palo Alto Unit 42 Caught Indirect Prompt Injection in the Wild — Here's What Your Agent Firewall Needs to Stop It

1
Comments
5 min read
AI Coding Agents Are the New Attack Surface Nobody's Ready For

AI Coding Agents Are the New Attack Surface Nobody's Ready For

1
Comments
3 min read
How Malicious MCP Configs in Amazon Q Developer Could Execute Arbitrary Code — and How to Stop It

How Malicious MCP Configs in Amazon Q Developer Could Execute Arbitrary Code — and How to Stop It

Comments
5 min read
North Korean Hackers Poisoned 140+ npm Packages in an AI Dev Tooling Attack. Here's What Would Have Caught It.

North Korean Hackers Poisoned 140+ npm Packages in an AI Dev Tooling Attack. Here's What Would Have Caught It.

1
Comments
4 min read
Claude Is Your Insider Threat Now - Notes from Dan Tentler's Security Fest 2026 Talk

Claude Is Your Insider Threat Now - Notes from Dan Tentler's Security Fest 2026 Talk

1
Comments
5 min read
LangGraph RCE Chain: How Malicious Tool Calls Escalate to Full Host Compromise

LangGraph RCE Chain: How Malicious Tool Calls Escalate to Full Host Compromise

1
Comments 2
5 min read
Agentjacking: How AI Coding Agents Get Hijacked Through Their Own Tool Pipeline

Agentjacking: How AI Coding Agents Get Hijacked Through Their Own Tool Pipeline

1
Comments
5 min read
Claude Fable 5 Was Jailbroken in 48 Hours. Here's What Actually Stopped Nothing.

Claude Fable 5 Was Jailbroken in 48 Hours. Here's What Actually Stopped Nothing.

1
Comments
5 min read
AI Email Agents Are Phishable: How OpenClaw Spilled User Data to Social Engineering Attacks

AI Email Agents Are Phishable: How OpenClaw Spilled User Data to Social Engineering Attacks

2
Comments
4 min read
The Miasma Worm: How AI Coding Agents Became a Supply Chain Attack Surface

The Miasma Worm: How AI Coding Agents Became a Supply Chain Attack Surface

Comments 1
5 min read
OpenAI Built a Lockdown Mode Because Tool-Based Data Exfiltration Is Real — Here's What Catches It Earlier

OpenAI Built a Lockdown Mode Because Tool-Based Data Exfiltration Is Real — Here's What Catches It Earlier

1
Comments
5 min read
One Malicious GitHub Issue Was All It Took to Hijack a Claude Code Agent

One Malicious GitHub Issue Was All It Took to Hijack a Claude Code Agent

1
Comments
5 min read
Notification Hijacking: How WhatsApp and Slack Content Could Weaponize Google Gemini

Notification Hijacking: How WhatsApp and Slack Content Could Weaponize Google Gemini

1
Comments
5 min read
loading...