Prompt-injection testing for AI apps
A test plan for web apps that call an LLM: threat model, what to instrument, OWASP-mapped test cases, and evidence engineering can act on.
Read it →Notes from real engagements, sanitised. No listicles, no vendor comparisons, no "5 cyber threats to watch". If we write something up, it is because we saw it more than once and the fix is worth knowing.
A test plan for web apps that call an LLM: threat model, what to instrument, OWASP-mapped test cases, and evidence engineering can act on.
Read it →Identity, sessions, multi-tenant authorisation and API access control — the SaaS-specific failures a general web application test tends to miss.
Read it →How to tell a report that found something from one padded with scanner output: severity inflation, no reproduction steps, and no verified impact.
Read it →The vulnerability classes hiding in a custom checkout that no automated scanner will flag: price tampering, coupon races, and forged payment webhooks.
Read it →We send a note when there is something worth sending. That is a handful of times a year, not a Tuesday newsletter.