SECURITY CIPHER · BLOG

AI Security

Posts from Security Cipher.

PIYUSH KUMAWAT · July 16, 2026

AI Pentest Tools in 2026: What Actually Works (T3MP3ST, PentestGPT, Caido and More)

Half the bug bounty writeups on my feed this week were not about a new vulnerability class – they were about a…

PIYUSH KUMAWAT · July 15, 2026

LLM Red Teaming in 2026: A Practical garak + PyRIT Workflow

You shipped an LLM feature. A support chatbot, a “summarize this document” button, an agent that can call tools. Now the obvious…

PIYUSH KUMAWAT · July 14, 2026

Indirect Prompt Injection in 2026: Hacking AI Through the Content It Reads

Most people picture prompt injection as someone typing “ignore your instructions” into a chatbot. That is the direct kind, and it is…

PIYUSH KUMAWAT · July 8, 2026

MCP Server Security (2026): A Practical Pentester’s Testing Playbook

If you are running Cursor, Claude Desktop, Windsurf, or a home-grown agent stack in 2026, you almost certainly have MCP servers in…

PIYUSH KUMAWAT · July 7, 2026

From Prompts to AI Security Loops: A Practical Playbook

Most teams are still treating AI like a better prompt box. "Review this code for vulnerabilities." "Write a Sigma rule for this…

PIYUSH KUMAWAT · July 1, 2026

AI Bug Bounty in 2026: How Hunters Use Claude Code and Automation to Find Bugs Faster

AI bug bounty in 2026: how hunters use Claude Code, Burp MCP and automation to find bugs faster, with honest accuracy numbers…

PIYUSH KUMAWAT · June 30, 2026

Agentjacking: How Attackers Hijack AI Coding Agents Like Cursor and Claude

Agentjacking lets attackers hijack AI coding agents like Cursor, Claude Code and Codex via poisoned error data. Here's how it works and…

PIYUSH KUMAWAT · June 21, 2026

AutoJack: How One Web Page Can Hijack Your AI Agent and Own Your Machine

Microsoft's AutoJack shows how a single malicious web page can hijack an AI agent and run code on your machine. Here's how…