Skip to main content
Ryan Orban

Ryan Orban

Subject
73 entries

Security

Bookmarks

  1. Kernel Managed Auth: secure authentication for AI agents

    Kernel's Managed Auth gives AI agents a secure way to handle login flows — 2FA, SSO, 1Password integration — without ever exposing credentials to the LLM. Solves one of the least-discussed blockers for autonomous web agents.

  2. OpenClaw Exposure Watchboard: tracking exposed AI agent deployments

    The OpenClaw Exposure Watchboard tracks 569K+ publicly reachable AI agent instances — many with leaked credentials, CVEs, and active threat actor interest. Useful for checking if your own deployment is inadvertently public.

  3. Shuru: local-first microVM sandbox for AI agents

    Shuru is a local-first microVM sandbox for AI agents on macOS — gives agents an isolated environment to execute code without touching the host system. Addresses the core risk of agents with shell access running on your actual machine.

  4. Exploitation-Validator: LLM sub-agent vulnerability analysis

    exploitation-validator uses LLM sub-agents to find and validate code vulnerabilities through a five-stage pipeline that explicitly cross-checks findings against actual source code to eliminate hallucinations before generating PoC exploits.

  5. Safe Yolo Mode: running LLM agents in isolated VMs

    A guide to running LLM agents with full auto-approval permissions inside libvirt/virsh VMs, so risky operations are contained without restricting what the agent can do. The sandbox is the safety rail, not permission restrictions.

  6. IronClaw: secure personal AI assistant from NEAR AI

    IronClaw is a privacy-focused personal AI assistant from NEAR AI, implemented in Rust with WASM sandboxing for untrusted tools, credential protection at the host boundary, and hybrid search memory. Your data never leaves your control.

  7. Destructive Command Guard (dcg): hook for blocking dangerous agent commands

    Destructive Command Guard (dcg) is a sub-millisecond hook that intercepts dangerous commands before AI agents execute them — git resets, rm -rf, DROP TABLE, kubectl deletes. 49+ security packs, SIMD-accelerated, never false-blocks.

  8. Matchlock: AI agents in ephemeral microVMs

    Matchlock runs AI agents in ephemeral microVMs with network allowlisting and MITM-based secret injection — your API keys never enter the VM. Full Linux environment that boots under a second, vanishes when done.

  9. amla-sandbox: WASM capability sandbox for AI agents

    amla-sandbox is a WASM sandbox with capability enforcement for AI coding agents — no Docker, no VM, one binary. Agents can only call explicitly provided tools. Addresses the arbitrary code execution risk in most agent frameworks.

  10. Descope: identity platform for humans and AI agents

    Descope is an External IAM platform that handles identity for both human users and AI agents — the same system covers user auth, business customer identity, MCP server auth, and agentic workflows. Identity as the control plane for human+agent systems.

  11. fnox: secret manager for mise workflows

    fnox is a new secret management tool designed to pair with mise in dev workflows — storing secrets outside dotfiles and injecting them at runtime. Announced by the mise author as a companion to mise's tool/runtime management.

  12. Trap bots on your server

    Maurycy's writeup on setting up a bot honeypot on your server — serving intentionally garbled content and endless links to trap and slow down scrapers. A practical defensive technique for server operators dealing with aggressive crawlers.

  13. Clutch Security: Non-Human Identity Security

    Clutch Security specializes in Non-Human Identity (NHI) security — protecting service accounts, API keys, machine identities, and now AI agents across digital environments. NHI is becoming the dominant attack surface as automated systems proliferate.

  14. Agent-Honeypot: LLM vs. LLM Adversarial Testing

    Agent-Honeypot is an automated red-teaming platform where an attacker LLM generates adversarial prompts against a defender LLM — testing alignment safeguards via authority claims, emergency framing, and incremental requests. A systematic way to stress-test LLM safety before deployment.

  15. Keycard: Identity and Access Control for AI Agents

    Keycard is a security control plane for AI agents — every action an agent attempts is evaluated against policy before credentials are issued. Short-lived scoped tokens replace long-lived permissions, and every agent interaction is auditable back to a human identity.

  16. Universal Radio Hacker (URH): Wireless Protocol Analysis

    Universal Radio Hacker (URH) is a comprehensive SDR suite for investigating wireless protocols — demodulation, protocol inference, fuzzing, and simulation in one tool. The go-to tool for reverse-engineering radio signals from weather stations to IoT devices.

  17. Resilient Cyber's Collection of AI Security Resources

    Resilient Cyber's curated collection of AI security resources: interviews, publications, and frameworks covering LLM threat models, red teaming, and AI-specific attack surfaces. A useful aggregation point for the AI security practitioner landscape.

  18. OPSEC Guide: operational security for individuals

    An operational security guide covering digital privacy practices — likely covering threat modeling, personal information reduction, secure communications, and metadata hygiene. Community-produced OPSEC reference for privacy-conscious individuals.

  19. Bjorn: Raspberry Pi Network Scanner with e-Paper Display

    Bjorn is a network scanning and offensive security tool for Raspberry Pi with a 2.13-inch e-Paper HAT display — discovers targets, identifies open ports and vulnerable services, and shows results on the tiny screen. A self-contained portable pentesting device for the hobbyist security researcher.

  20. Autonomous Hacker: LLM-Powered Security Research Agent

    The autonomous-hacker module in R3DRUN3's sploitcraft demonstrates using LLMs as autonomous security research agents — scanning, identifying vulnerabilities, and generating exploits with minimal human input. An educational proof of concept for LLM-assisted offensive security.

  21. Internal Constrained PKI: Safe TLS CA for .internal Networks

    internal-constrained-pki creates a TLS root CA for .internal networks with X.509 Name Constraints — the CA is cryptographically prevented from signing certificates for public domains, making it safe to share with team members without compromising internet trust.

  22. SOPS: Secrets OPerationS

    SOPS (Secrets OPerationS) encrypts secret files using cloud KMS or PGP/age keys while keeping key names visible for diffs and version control. It's the standard tool for storing encrypted secrets in git without a centralized secrets server.

  23. Secrets Management Overview

    A comparative overview of 10 secrets management tools across on-premises, SaaS, and hybrid deployment models, from open-source options like Ansible Vault and Conjur to commercial platforms like HashiCorp Vault, Doppler, and Akeyless.

  24. AWS Nitro Enclaves Attack Surface

    Trail of Bits analysis of AWS Nitro Enclaves' attack surface, covering vsock vulnerabilities, side-channel risks, entropy issues, and the trust model's assumptions. Essential reading before building confidential computing workloads on Nitro.

  25. ai-llm-agent-solver: Autonomous Gandalf Challenge Solver

    An LLM-powered agent that autonomously solves the Gandalf AI challenge — a prompt injection security game where you try to extract a secret password from a guarded AI. Uses OpenAI API and agent-based reasoning.

  26. jailbreak_llms: CCS'24 Jailbreak Prompt Dataset

    A dataset of 15,140 ChatGPT prompts including 1,405 jailbreak prompts collected from Reddit, Discord, and open-source datasets — published at CCS 2024. The most comprehensive public collection of real-world jailbreak attempts against LLMs.

  27. YOU'VE JUST BEEN FUCKED BY PSYOPS (37C3 Talk)

    Trevor Paglen's 37C3 talk connecting Cold War psychological operations history to algorithmic targeting, synthetic media, and 'PSYOP Capitalism' — the era of AI-enabled mass manipulation. Includes CYCLOPS, an interactive game threaded through the conference.

  28. Data Exfiltration from Writer.com via Indirect Prompt Injection

    PromptArmor and Kai Greshake demonstrate data exfiltration from Writer.com via indirect prompt injection — where malicious content in a document the AI assistant processes causes it to leak user data. A concrete case study of the class of attack affecting all document-processing LLM applications.

  29. PostgreSQL Encryption: The Available Options

    Matt Palmer's comprehensive overview of PostgreSQL encryption options — covers full-disk encryption, TLS in transit, column-level encryption with pgcrypto, and the tradeoffs between each. A clear-headed reference for teams navigating database encryption requirements.

  30. Supabase Vault: Secrets and Encryption in PostgreSQL

    Supabase Vault is a PostgreSQL extension for managing secrets and encrypted data inside the database — built on pgsodium and Libsodium, it handles key management and column encryption without application-layer complexity.

  31. AI Adversarial Attacks: Automated Jailbreaks via Text Suffixes

    Ars Technica covers the Universal Adversarial Attacks paper from CMU/Center for AI Safety — automated adversarial suffixes appended to prompts reliably bypass safety training on GPT-4, Claude, and open-source models. The attacks are transferable and potentially unstoppable with current alignment techniques.

  32. Mithril Security: Confidential AI Inference with BlindAI

    Mithril Security builds BlindAI — an open-source AI inference solution using Trusted Execution Environments (TEEs) so you can run AI on sensitive data without exposing it to the model provider. Addresses the tension between AI utility and data privacy.

  33. AI Browser Extensions Are a Security Nightmare

    Kolide's analysis of why AI browser extensions are a security and privacy risk — they require broad DOM access permissions that give them access to every page you visit, including sensitive internal tools. A practical warning for enterprise security teams evaluating AI productivity tools.

  34. Prompt Injection Attacks Against GPT-3

    Simon Willison's September 2022 post naming and describing prompt injection attacks against GPT-3 — one of the first clear articulations of the attack class where malicious content in the environment overrides the developer's system prompt. The post that put the term 'prompt injection' into common use.

  35. Canarytokens Docker — Self-Hosted Honeytokens

    Thinkst's Canarytokens Docker setup lets you self-host your own canarytoken server — tripwires that alert you when someone accesses a file, URL, or credential they shouldn't know about. The DIY version of Thinkst's hosted canary service.

  36. The Move Prover: A Practical Guide

    OtterSec's practical guide to the Move Prover — a formal verification tool for the Move smart contract language used on Sui and Aptos. Covers writing specifications that the prover can check, bridging the gap between formal methods theory and blockchain developer practice.

  37. Best Practices for Ethereum Beacon Chain Staking (September 2022)

    Reddit thread from r/ethstaker documenting best practices for staking on the Ethereum Beacon Chain in September 2022 — just before The Merge. Covers client diversity, slashing prevention, key management, and hardware choices for home validators.

  38. Signing Git Commits with Your SSH Key

    A walkthrough of using your existing SSH key to sign Git commits instead of a GPG key — a feature added in Git 2.34. Signing git commits is good practice for supply chain security, and SSH keys are already part of most developers' daily workflow, making this a low-friction upgrade over GPG.

  39. Pentester's Promiscuous Notebook (PPN)

    Pentester's Promiscuous Notebook (PPN) is a comprehensive personal pentesting reference by snovvcrash covering Active Directory attacks, post-exploitation, privilege escalation, and tool usage. One of the most practical field-guide style pentesting references available.

  40. Finding Bugs Automatically in Smart Contracts with Parameterized Invariants

    A 2020 WIP paper from Certora describing a framework of reusable parameterized invariants for automatically finding bugs in smart contracts, with the Certora Prover discovering two real bugs in MakerDAO's Multi-Collateral Dai. The core insight is that the hardest problem in formal verification is specification, and smart contracts are unusually amenable to shared invariants — enabling a community network effect.

  41. Using the Kani Rust Verifier on a Firecracker Example

    Kani is AWS's Rust model checker — a formal verification tool that proves correctness properties of Rust code by exhaustively exploring execution paths. This post shows it applied to Firecracker, AWS's microVM hypervisor, demonstrating industrial-scale use of formal methods.

  42. Formal Verification of an OS Kernel

  43. DeFi Safety — Protocol Security Reviews

    DeFi Safety is a security review and rating service for DeFi protocols, scoring them on code quality, documentation, admin key controls, and testing practices. One of the few systematic attempts to give DeFi users a reliable signal about protocol security posture.

  44. EVM Puzzles: Solutions Walkthrough

    Solutions walkthrough for EVM Puzzles — a set of interactive challenges that teach the Ethereum Virtual Machine by requiring you to craft calldata or value that makes specific bytecode sequences succeed. Effective hands-on EVM education for smart contract developers.

  45. Flash Boys 2.0: Frontrunning, Transaction Reordering, and Consensus Instability in Decentralized Exchanges

    Daian et al. document how arbitrage bots exploit transaction ordering in decentralized exchanges through priority gas auctions, introducing the concept of miner extractable value (MEV). The paper shows that MEV isn't just a trading problem — it creates measurable consensus-layer security risks for Ethereum.

  46. Privacy-Preserving Machine Learning with Fully Homomorphic Encryption for Deep Neural Networks

    This paper demonstrates running deep neural network inference entirely on encrypted data using fully homomorphic encryption, so the server never sees plaintext inputs or outputs. It makes encrypted ML inference practical by combining FHE with approximation-friendly neural network architectures.

  47. EVM EIPs and Hard Forks Reference

    Trail of Bits' learning resource mapping Ethereum EIPs to the hard forks that introduced them — essential context for auditors and developers who need to know which EVM opcodes and behaviors are available at different protocol versions. Part of the building-secure-contracts curriculum.

  48. Smart Contract Development Topics and Issues

    A survey of smart contract development topics and common issues, covering the technical challenges, security vulnerabilities, and tooling landscape for writing and deploying contracts on blockchain platforms. Useful as a structured overview of what goes wrong in smart contract development and why.

  49. Slither-simil: ML-Assisted Smart Contract Audits

    Trail of Bits introduces Slither-simil, a tool that uses ML embeddings to find smart contracts similar to a known-vulnerable one — dramatically accelerating audits by surfacing candidate contracts before manual review. An early example of applying ML to the smart contract security problem.

  50. Sec3 Pro Auto Auditor: Automated Solana Security

    Sec3 (formerly Soteria) launches their automated smart contract auditor for Solana programs — static analysis for Anchor/native Rust programs targeting common vulnerability classes. One of the first automated security tools built specifically for the Solana/Rust ecosystem.

  51. ScanMyCode: Code Security Scanner

    ScanMyCode is a code security scanner with smart contract support — static analysis for Solidity and general code security issues. Likely saved alongside the other smart contract security tools (Slither, Sec3, Quantstamp) as part of an audit tooling survey.

  52. Quantstamp Audits Portfolio

    Quantstamp's audit portfolio page showcasing their security work across major protocols including ETH2.0, OpenSea, and MakerDAO. Quantstamp was one of the first institutional smart contract audit firms and helped establish what professional blockchain security work looks like.

  53. Brave Browser Hardening Guide

    CHEF-KOCH's GitLab guide for hardening Brave Browser beyond its defaults — covering flags, extension recommendations, and configuration changes to minimize fingerprinting and data leakage. Useful reference for privacy-focused browser setup.

  54. Smart Contract Vulnerability Detection via Information Graph and Ensemble Learning

    Zhang, Wang et al. propose SCVDIE, a smart contract vulnerability detection method combining seven neural networks with information graphs via ensemble learning. By pretraining on an information graph and ensembling diverse architectures, they achieve higher accuracy on small vulnerability datasets than individual models or static analysis tools.

  55. Agoric: JavaScript Smart Contracts with Object-Capability Security

    Agoric is a smart contract platform built on JavaScript with a hardened security model — uses object-capability security to make contracts composable and safe by construction. An unusual approach in a space dominated by Solidity and Rust.

  56. Warpgate: Smart SSH Bastion

    Warpgate is an open-source SSH bastion server written in Rust — sits in front of your SSH targets, handles authentication centrally, and records sessions. Unlike traditional bastion hosts, it works with any standard SSH client without requiring a custom client or VPN.

  57. Byzantine-Robust Learning on Heterogeneous Datasets via Bucketing

    EPFL researchers show that existing Byzantine-robust aggregation rules (Krum, coordinate-wise median, RFA) fail catastrophically on non-iid data, then fix the problem with a one-step bucketing scheme that randomly groups worker updates before aggregation. The first result with provable convergence guarantees for Byzantine robustness under realistic data heterogeneity.

  58. DNS Paper (April 2022)

    A paper on DNS (Domain Name System) saved in April 2022. The Unix timestamp in the filename (1649775033 = April 12, 2022) suggests it was auto-named at download time. DNS research spans security (cache poisoning, DDoS amplification, DNSSEC), privacy (DNS-over-HTTPS, DNS-over-TLS), and infrastructure reliability.

  59. Personal Security Checklist

    Lissy93's personal security checklist on GitHub — 300+ categorized tips for protecting digital security and privacy. A practical reference for hardening accounts, devices, and browsing habits without becoming a full-time security researcher.

  60. Enclave: Zero-Trust Overlay Networking

    Enclave is a zero-trust overlay networking product that creates software-defined private networks between machines without VPN infrastructure — each machine gets a cryptographic identity and point-to-point encrypted tunnels replace network perimeters.

  61. High Assurance Rust

    High Assurance Rust is a free online book teaching systems security through Rust — covering memory safety, type systems, cryptography, and formal verification. Aimed at developers who want to write software that's provably hard to exploit.

  62. SSH Certificates: Why You're Doing SSH Wrong

    Smallstep's case for SSH certificates over authorized_keys — short-lived certificates issued by a CA eliminate the credential sprawl that makes SSH key management a compliance nightmare. The practical alternative to key-based SSH at scale.

  63. Stytch: Passwordless Authentication Infrastructure

    Stytch is a developer-focused authentication platform specializing in passwordless methods — magic links, one-time passcodes, biometrics, and OAuth. Competes with Auth0 and Clerk by betting on passwords being a security and UX problem worth eliminating.

  64. Tunneling Tunnels: Multi-Hop VPN with Multitun

    cryptostorm's writeup on multitun — nesting multiple VPN tunnels inside each other for layered anonymity. The multi-hop VPN pattern separates entry and exit knowledge, so no single provider can link your identity to your traffic.

  65. Enabling SSL in Your Local Network

    A practical approach to getting proper SSL certificates for local network services using Let's Encrypt wildcard certs and DNS validation — avoiding the browser warnings of self-signed certs without exposing services to the internet. Clean solution for anyone running internal homelab services.

  66. btc-heist — Bitcoin Key Generation Educational Tool

    btc-heist is a toy Bitcoin key generation tool that generates random private/public key pairs and checks if the address matches any in a list of addresses with non-zero balances. An educational demonstration of why Bitcoin's 2^256 key space makes brute-force impossible in practice.

  67. Security Data Science Papers

    Covert.io's curated list of academic papers applying data science and machine learning to security problems — covering network intrusion detection, malware classification, anomaly detection, and more. A reference for practitioners working at the intersection of ML and cybersecurity.

  68. Hackers Backdoor the Human Brain

    ExtremeTech coverage of researchers demonstrating that a consumer EEG headset could be used to extract sensitive information (PINs, locations) from subjects without their explicit cooperation — essentially a side-channel attack on the human brain. An early marker of privacy concerns in BCI technology.

  69. The Matasano Crypto Challenges

    Maciej Cegłowski's Pinboard post recommending the Matasano Crypto Challenges — a set of progressively harder cryptography exercises that teach you to break real cryptographic constructions. The most effective way to understand why cryptography is hard.

  70. My First 5 Minutes On A Server; Or, Essential Security for Linux Servers

    Bryan Kennedy's definitive guide to the essential security hardening steps for a new Linux server — create a non-root user, set up SSH keys, disable root login, configure ufw, enable automatic updates, install fail2ban. One of the most bookmarked sysadmin articles of its era.

  71. VPN Services That Take Your Anonymity Seriously — 2013 Edition

    TorrentFreak's annual survey of VPN providers that maintain genuine no-log policies — the 2013 edition. The canonical reference for evaluating VPN privacy claims before the category was commoditized.

  72. Keyless BMW Cars Prove to Be Very Easy to Steal

    Hackaday's 2012 coverage of the relay attack on BMW keyless entry: two cheap radios extend the key fob's short-range signal across a parking lot, fooling the car into thinking the key is nearby. Still the standard theft method for passive-entry luxury cars today.

  73. Exploit Exercises (Exploit Education)

    Exploit Education (formerly Exploit Exercises) provides progressively harder virtual machine challenges for learning binary exploitation, privilege escalation, and memory corruption — from Linux basics through heap exploitation and modern mitigations. The canonical self-study path for systems security.

All bookmarks