Posts on ai-security
5 posts on ai-security. Notes from public sources and my own test lab.
Prompt Injection Cannot Be Solved With Classical Security Models
Prompt injection is not a parsing error; it is the natural consequence of an LLM's inability to distinguish between instruction and data, and therefore a permanent patch should not be expected.
Invisible Danger: The Ghost in the Images and AI Agents
A deep dive into how 'Ghostcommit' turns simple image uploads into sophisticated prompt injection attacks against AI-driven DevSecOps workflows.
New Eye in the Terminal: Can Claude Code Actually Spot Security Vulns?
I put Anthropic’s new Claude Code CLI to the test. Here’s how its agentic workflow stacks up against traditional tools in finding real-world bugs.
Claude Code Terminale İndi: Kodun İçindeki Açıkları Bulmak Artık Çocuk Oyuncağı mı?
Claude Code duyuruldu ve işler iyice kızıştı. Peki bu yeni AI aracı gerçekten güvenlik açıklarını yakalayabiliyor mu yoksa sadece gürültü mü yapıyor?
Claude Code is Here: Hunting Vulnerabilities Directly from Your Terminal
Testing Claude Code from a security perspective—why this new CLI tool is more than just another chatbot for your workflow.