Skip to content
fm.
Blog Series Categories Tags Search About EN / PT
  1. / Tags
  2. / security

security

  • npm's supply chain is broken — the Axios attack explains why

    Technical analysis of the Axios npm supply chain attack in March 2026: what happened, what the malware did, why CI/CD is the real target, and how to protect yourself.

    Apr 2
  • When AI Stops Being a Tool and Becomes an Attack Surface

    When AI becomes an attack surface: prompt injection, end-to-end attack chains, at-risk architectures, and defensive actions.

    Mar 22
  • Fackel: an autonomous pentest framework powered by ReAct agents

    Fackel: a multi-agent pentest framework where LLMs decide strategy. Architecture walkthrough, design decisions, and lessons learned.

    Mar 9
  • Device Code Phishing + Vishing: How Attackers Compromise Microsoft Entra Accounts Using Legit Login Pages

    Device code phishing combined with vishing targeting Microsoft Entra: how the OAuth flow gets abused, what to monitor, and how to mitigate.

    Feb 20
  • The State of the Art in AI Agents (2026): What ‘Modern’ Actually Means

    A practical overview of modern AI agent systems: tool use, retrieval, memory, verification, multi-agent patterns, evaluation, and security.

    Feb 20
  • Security Implications of Probabilistic Reasoning in Generative AI

    A rigorous analysis of how probabilistic reasoning in generative models shapes security risk, failure modes, and robustness.

    Feb 4
  • The Cost of Abstraction: When Layers Hide Security and Reliability Risks

    Argues that abstraction layers can obscure failure modes, shift risk across boundaries, and weaken assurance unless their assumptions are made explicit.

    Feb 3
  • Why Traditional Threat Modeling Breaks Down in Generative AI Systems

    Probabilistic behavior, distributional risk, and system composability invalidate core assumptions of classical threat modeling for generative AI.

    Jan 4

flaviomilan.dev — deep, practical notes on software engineering: systems, architecture, reliability, and leadership.

Blog Series Categories RSS GitHub X LinkedIn

© 2026 Flavio Milan. All rights reserved.