ToxSec
@toxsec.bsky.social
AI Security Engineer @ Amazon.
M.S. Cybersecurity, CISSP.
Ex-NSA, USMC.
M.S. Cybersecurity, CISSP.
Ex-NSA, USMC.
Excessive Agency is an OWASP Top 10 Threat. Make sure you watch what permissions you are giving your Agents.
Remember to apply principles of least privilege and audit their actions closely.
#ai #cybersecurity #technology
Remember to apply principles of least privilege and audit their actions closely.
#ai #cybersecurity #technology
November 9, 2025 at 6:43 PM
Excessive Agency is an OWASP Top 10 Threat. Make sure you watch what permissions you are giving your Agents.
Remember to apply principles of least privilege and audit their actions closely.
#ai #cybersecurity #technology
Remember to apply principles of least privilege and audit their actions closely.
#ai #cybersecurity #technology
Traditional cybersecurity attack are still here for LLMs. I’ve seen several new logic attacks that are pretty effective especially when connected to a RAG.
Think Forkbomb for your chatbot. Reeaaaaallly pricy if you don’t have failsafes and ways to detect it.
Think Forkbomb for your chatbot. Reeaaaaallly pricy if you don’t have failsafes and ways to detect it.
November 7, 2025 at 5:49 PM
Traditional cybersecurity attack are still here for LLMs. I’ve seen several new logic attacks that are pretty effective especially when connected to a RAG.
Think Forkbomb for your chatbot. Reeaaaaallly pricy if you don’t have failsafes and ways to detect it.
Think Forkbomb for your chatbot. Reeaaaaallly pricy if you don’t have failsafes and ways to detect it.
Reading “Chip Wars” and got me thinking, with all the data centers spinning up, I hope we got the best of the best on call haha.
November 6, 2025 at 5:46 PM
Reading “Chip Wars” and got me thinking, with all the data centers spinning up, I hope we got the best of the best on call haha.
The #1 biggest threat to your ai product.
November 4, 2025 at 6:26 PM
The #1 biggest threat to your ai product.
TLDR: China’s firewall just leaked 500 + GB of its internal censorship tech. Big win for transparency, big red-flag for digital repression tools going global.
November 2, 2025 at 10:12 PM
TLDR: China’s firewall just leaked 500 + GB of its internal censorship tech. Big win for transparency, big red-flag for digital repression tools going global.
Stop trusting headers. Force the alg, own the app.
Learn JWT security: www.toxsec.com/p/hacking-jw...
#AppSec #InfoSec
Learn JWT security: www.toxsec.com/p/hacking-jw...
#AppSec #InfoSec
October 17, 2025 at 1:33 AM
Stop trusting headers. Force the alg, own the app.
Learn JWT security: www.toxsec.com/p/hacking-jw...
#AppSec #InfoSec
Learn JWT security: www.toxsec.com/p/hacking-jw...
#AppSec #InfoSec
GenAI apps break differently. Learn the Top 10 ways here:
www.toxsec.com/p/owasp-top-...
#GenAI #Cybersecurity #OWASP
www.toxsec.com/p/owasp-top-...
#GenAI #Cybersecurity #OWASP
October 9, 2025 at 4:34 AM
GenAI apps break differently. Learn the Top 10 ways here:
www.toxsec.com/p/owasp-top-...
#GenAI #Cybersecurity #OWASP
www.toxsec.com/p/owasp-top-...
#GenAI #Cybersecurity #OWASP
Cyber Security Awareness Month!
Resilience > perimeter. One bad update took down the world—do you have a kill-switch and a rollback? www.toxsec.com/p/toxsec-cyb...
#SecOps #Resilience
Resilience > perimeter. One bad update took down the world—do you have a kill-switch and a rollback? www.toxsec.com/p/toxsec-cyb...
#SecOps #Resilience
October 3, 2025 at 1:33 AM
Cyber Security Awareness Month!
Resilience > perimeter. One bad update took down the world—do you have a kill-switch and a rollback? www.toxsec.com/p/toxsec-cyb...
#SecOps #Resilience
Resilience > perimeter. One bad update took down the world—do you have a kill-switch and a rollback? www.toxsec.com/p/toxsec-cyb...
#SecOps #Resilience
New Article Concept art lol.
September 30, 2025 at 4:20 PM
New Article Concept art lol.