
Jul 29, 2026 · 15 min read
A Security Analysis of Amazon S3 Vectors and Its Use in LLM Retrieval Pipelines
Ioan Criste & Emanuel Ioniță
News and research on cloud attack patterns, AI advancements, and real-world security validation.

Jul 29, 2026 · 15 min read
Ioan Criste & Emanuel Ioniță

Jul 22, 2026 · 8 min read
Hugging Face’s AI-driven breach shows why hosted frontier models fail for offensive security and incident response—and why sovereign, domain-specific validation AI is required.
OFFENSAI

Jul 8, 2026 · 8 min read
We pointed our autonomous offensive agent, AgentO, at Datadog's new Pathfinding Labs and it solved all 122 live AWS privilege-escalation labs — no human in the loop, no access to the answers, average 9 turns. Here's what made it work.
Ioan Criste, Dragos Stanescu & Eduard Agavriloae

Jul 3, 2026 · 4 min read
OFFENSAI has joined the Wiz Integration Network (WIN), bringing Cloud-Native Adversarial Exposure Validation to the Wiz ecosystem so teams prove which exposures attackers can actually exploit.
Karen Nguyen

Jun 18, 2026 · 12 min read
AWS shipped Console Sign-In restrictions via resource control policies. Here are 5 attack paths that bypass them, and how OFFENSAI maps them.
Dragos Stanescu

May 20, 2026 · 12 min read
scopeshift demonstrates that Claude Code and other AI coding agents can be tricked into running unauthorized pentests through network-layer deception alone — no adversarial prompts required. The agent thinks it's probing localhost, but the traffic lands on a real third-party target.
Eduard Agavriloae

Apr 28, 2026 · 7 min read
AI isn't creating a new vulnerability crisis. It's exposing the one security teams were already living in: too much noise, too little exploitability proof, and too much uncertainty.
Karen Nguyen
By submitting the form you are agreeing to our privacy policy.

Apr 7, 2026 · 8 min read
AWS IAM eventual consistency gives attackers a 4-second window after credential revocation. notyet is an open-source tool to test IR containment playbooks.
Eduard Agavriloae

Feb 24, 2026 · 12 min read
Standard AWS IR containment fails against attackers exploiting IAM eventual consistency. This article presents an SCP-enforced technique that makes identity-level containment attacker-resistant.
Eduard Agavriloae

Feb 3, 2026 · 18 min read
Adversarial Exposure Validation (AEV) proves what's exploitable right now, tests detection during execution, and re-runs the same path after fixes to verify closure.
OFFENSAI
Move from cloud exposure detection to controlled validation, technical evidence, and risk-based prioritization, powered by AI.
