Blog

Writing about AI security, red teaming, and things I find interesting.

18 May 2026 · Video · NahamSec

This GitHub README Hijacks Your AI and Spreads Like a Virus

I sat down with NahamSec to walk through a self-propagating prompt injection chain that hides inside an innocuous-looking README and hijacks AI coding agents that read it.

10 May 2026

Extracting a flag from MetaHelper with 194 chars of Japanese

I was the only person to solve MetaCTF's hard prompt-extraction tier, with a 194-character Japanese prompt that finished as the shortest hard solution overall.