Testing Instruction Hierarchy and Prompt Override Attacks
Over the past few months, I’ve written extensively about AI Red Teaming, prompt injection, and the techniques attackers use to probe the security boundaries of […]
Over the past few months, I’ve written extensively about AI Red Teaming, prompt injection, and the techniques attackers use to probe the security boundaries of […]
Authentication has changed dramatically over the past decade. Not long ago, attackers focused primarily on stealing usernames and passwords because that was all they needed […]
Authentication in SharePoint Server has gone through a lot of changes over the years. Most of us started with Windows authentication using NTLM or Kerberos, […]
Throughout this series, we’ve looked at how attackers manipulate AI systems by changing context rather than exploiting traditional software vulnerabilities. We’ve explored how safety boundaries […]
For years, most identity security conversations have focused on protecting the authentication process. We have moved from passwords to multifactor authentication, Conditional Access, device compliance, […]
In Part 1, we explored how AI security boundaries are created and why they are fundamentally different from traditional security controls. We also looked at […]
Artificial intelligence has introduced one of the biggest shifts in enterprise technology since organizations first moved to the cloud. Large Language Models (LLMs) are now […]
Large Language Models have become far more capable over the past few years, but those improvements have introduced a new category of security problem. These […]
Artificial intelligence continues to reshape cybersecurity, not only in how organizations defend themselves but also in how security technologies are being built. Over the past […]
For years, organizations have invested heavily in endpoint protection, multifactor authentication, Conditional Access, email security, and network controls. All of those technologies are important, but […]
There is something about a road trip that changes your perspective. Maybe it is the endless hours staring through a windshield, maybe it is seeing […]
Artificial intelligence has changed the cybersecurity landscape faster than most organizations anticipated. Over the past decade, security teams have become accustomed to protecting cloud environments, […]
If you’ve spent any amount of time using AI, you’ve probably experienced both ends of the spectrum. Sometimes the response is exactly what you needed, […]
If you’ve spent any time exploring AI over the past year, you’ve almost certainly come across prompt frameworks. Whether you’re using ChatGPT, Microsoft Copilot, Claude, […]
The common misconception is that AI red teaming is about finding one “magic prompt” that breaks a model, the social-media version. Professional AI security assessment […]
In the previous article, we shifted our focus from prompt engineering to behavioral analysis. Rather than treating prompts as isolated interactions, we explored how experienced […]
One of the questions I hear most frequently from organizations beginning their CMMC journey is whether they should build a CMMC Level 2 enclave or […]
Over the past month, Microsoft has made several announcements worth every Microsoft 365 administrator’s attention. While many updates are incremental, a handful have the potential […]
For the past several years, organizations supporting the U.S. Defense Industrial Base (DIB) have been working toward Cybersecurity Maturity Model Certification (CMMC). The phased rollout […]
If you’ve been following Microsoft’s identity roadmap over the past few years, this latest announcement shouldn’t come as a surprise. Microsoft has been steadily moving […]
In the previous articles in this series, we explored what AI red teaming is, why it has become an essential part of responsible AI development, […]
The common misconception is that AI red teaming is about finding one “magic prompt” that breaks a model, the social-media version. Professional AI security assessment […]
In Part 2, we focused on planning effective AI red team exercises by understanding the AI system, identifying business risks, developing realistic threat scenarios, and […]
Every 4th of July, Americans celebrate the Declaration of Independence as the bold birth certificate of a new nation. It is remembered as the moment […]
In Part 1, we explored what AI red teaming is, how it differs from traditional penetration testing and governance activities, and why generative AI introduces […]