Research
Writeups on AI offensive security — the chains we find, and the changes that break them.
9 Aug 2026 · 4 min read · Prompt injection · SSRF · RAG
A public technique, start to finish: how untrusted text in a RAG index becomes a request to the cloud metadata endpoint — and why the fix does not live at the model.
← Back to home