SECURITY CIPHER · BLOG

AI Security

Posts from SecurityCipher.

PIYUSH KUMAWAT · August 25, 2026

The CVE Flood Is a Lie: How to Hunt When AI Dumps 36% More Bugs But Exploitation Only Grows 10%

Your vulnerability scanner ran overnight. Your inbox has 47 new CVE alerts. Slack is pinging you about a “critical” flaw in a…

PIYUSH KUMAWAT · August 3, 2026

I Ran Codex Security on a Shop API Lab: 14 Bugs, $1.64, Full Playbook

Hands-on OpenAI Codex Security CLI guide: scan a Flask shop API, get 14 findings, threat model, remediations, GitHub bulk-scan, and a real…

PIYUSH KUMAWAT · July 17, 2026

Is AI Killing Bug Bounty? What the 2026 CVE Flood Really Means for Hunters

Ask any bug bounty hunter how 2026 is going and you will get one of two answers. Either “I have never found…

PIYUSH KUMAWAT · July 16, 2026

AI Pentest Tools in 2026: What Actually Works (T3MP3ST, PentestGPT, Caido and More)

Half the bug bounty writeups on my feed this week were not about a new vulnerability class – they were about a…

PIYUSH KUMAWAT · July 15, 2026

LLM Red Teaming in 2026: A Practical garak + PyRIT Workflow

You shipped an LLM feature. A support chatbot, a “summarize this document” button, an agent that can call tools. Now the obvious…

PIYUSH KUMAWAT · July 14, 2026

Indirect Prompt Injection in 2026: Hacking AI Through the Content It Reads

Most people picture prompt injection as someone typing “ignore your instructions” into a chatbot. That is the direct kind, and it is…

PIYUSH KUMAWAT · July 7, 2026

From Prompts to AI Security Loops: A Practical Playbook

Most teams are still treating AI like a better prompt box. "Review this code for vulnerabilities." "Write a Sigma rule for this…