Next Kick Labs
Subscribe
Sign in
Home
Notes
Archive
About
Latest
Top
Discussions
OWASP FinBot: An Agentic AI Security Test Range
OWASP FinBot is an intentionally vulnerable multi-agent app that scores exploits on real business state, turning agentic AI security claims into…
Jul 22
•
Fernando Lucktemberg
Things I got wrong about agent security
Agent security frameworks name risks in full but rarely validate the defense. Threat modeling and infrastructure matter more than this month's…
Jul 15
•
Fernando Lucktemberg
1
2
5
Q2 2026: 184 Subscribers, a Solo Quarter, and the Number That Actually Matters
An honest accounting of Q2 2026: 184 email subscribers, 728 followers, a solo quarter with no viral moments, and the Agentic AI Security Stack…
Jul 8
•
Fernando Lucktemberg
1
June 2026
AI Security Testing as a Chain of Trust
AI security testing becomes credible when benchmarks, scanners, and guardrails compose into a chain of trust validated by application runtime telemetry.
Jun 24
•
Fernando Lucktemberg
4
There is no NMAP for LLMs yet
LLM security tools produce different evidence. This lab shows how garak, promptfoo, DeepTeam, and Augustus should be scoped and interpreted.
Jun 17
•
Fernando Lucktemberg
1
CyberSecEval on a Consumer GPU: What My Local Setup Could Actually Measure
A local CyberSecEval lab shows why response fields, harness state, and server configuration matter as much as model scores.
Jun 10
•
Fernando Lucktemberg
1
In AI Vulnerability Research, the Pipeline Is Becoming the Product
Open-source AI vulnerability research tooling now covers discovery, proof construction, patching, triage, and evaluation, but verifiable pipelines…
Jun 3
•
Fernando Lucktemberg
1
May 2026
When the Research Tool and the Attack Tool Are the Same System
AI agents are now automating exploit chain construction at production scale. Learn how this shifts the economics of vulnerability triage and…
May 26
•
Fernando Lucktemberg
Treat Coding Agents as Privileged Build Participants
Coding agents are now tool-using systems with repository access. Learn how to secure the agentic runtime and protect your software supply chain.
May 21
•
Fernando Lucktemberg
Detecting Shadow AI in the Enterprise: The MCP stdio Gap
Close the detection gap for Shadow AI. Learn why the Model Context Protocol stdio transport bypasses CASBs and how to use endpoint telemetry for…
May 19
•
Fernando Lucktemberg
The Three-Day Breach: The AI Security Gap That Isn't About Prompt Injection
A fictional composite incident exploring how machine-speed AI agents bypass traditional security detection. Learn why the detection tempo gap is more…
May 14
•
Fernando Lucktemberg
1
Orchestrator-to-Orchestrator Is the Next Agentic Trust Boundary
Orchestrator-to-Orchestrator (O2O) delegation creates a new class of third-party risk. This article explores how to secure agent handoffs and horizontal…
May 12
•
Fernando Lucktemberg
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts