How to prevent token misuse in LLM integrations

Preventing prompt injection and token abuse in LLM integrations: a Chrome-extension example attack, then defenses including input validation, narrow prompts, output filters, token limits, rate limiting, and LangChain for pre/post-processing and usage tracking.

July 22, 2025 · 6 min
Solving the XLMRat Blue team challenge

Solving the XLMRat Blue team challenge

A blue-team walkthrough of the CyberDefenders XLMRat challenge: tracing the first-stage download URL and hosting provider from the PCAP, hashing the loader and executable payloads, and identifying the malware family and the LOLBin used for stealthy execution.

June 28, 2025 · 6 min

A pint with Jimothy: on fear, ego, and hiring smarter

A reconstructed conversation with an engineering manager who hesitates to hire a candidate sharper than himself, on the fear and ego behind hiring calls, and why hiring people stronger than you is the smarter move.

June 12, 2025 · 4 min
Billion-dollar brains: the real cost of AI

Billion-dollar brains: the real cost of AI

The hidden cost behind AI-assisted coding: the GPUs, power, and data-center infrastructure that make it work, whether current pricing reflects real demand, why providers lose money at scale, and what that means for you.

May 26, 2025 · 4 min
Solving the BlueSky Ransomware Blue team challenge

Solving the BlueSky Ransomware Blue team challenge

A blue-team walkthrough of the CyberDefenders BlueSky ransomware challenge: analyzing the PCAP to find the port-scan source IP, the targeted account, C2 process injection, the downloaded payload, and the registry keys used to disable Windows Defender.

May 18, 2025 · 11 min
When Slack starts to feel like a DDoS attack

When Slack starts to feel like a DDoS attack

Borrowing “exponential back-off” from networking to handle communication overload as an engineering lead: how to triage the constant stream of Slack pings, reviews, and requests with informal priority classes and respond with intention.

May 7, 2025 · 3 min
DanaBot blue team challenge

Solving the DanaBot Blue team challenge

A blue-team walkthrough of the CyberDefenders DanaBot challenge: using PCAP and threat intel to trace the initial-access IP, identify the malicious files and their SHA-256/MD5 hashes, and the process used to execute the banking trojan.

May 4, 2025 · 5 min
AI for Engineering managers: adapt now or trail behind

AI for Engineering managers: adapt now or trail behind

How AI is reshaping engineering management: tracking impact instead of story points, budgeting for capacity instead of headcount, hiring abstraction thinkers, cutting dead process, and a 90-day pivot plan to stay relevant.

April 19, 2025 · 4 min
Impostor syndrome: kicking self-doubt to the curb

Impostor syndrome: kicking self-doubt to the curb

Recognizing and handling impostor syndrome in the moments it hits hardest, drawing on Aviv Ben-Yosef’s “The Tech Executive Operating System”, with techniques like asking yourself Socratic questions.

March 23, 2025 · 2 min
The unboring NIST SP 800-190

The unboring NIST SP 800-190

Practical, non-boring takeaways from NIST SP 800-190 for container security: image scanning and vulnerability management, controlled image provenance, least-privilege runtime restrictions, network segmentation, runtime threat detection, and host-OS hardening.

March 18, 2025 · 3 min