Security Researcher @ Zenity
A closer look at custom-code guardrail sandbox-escape (CVE–2026-40217) activity in the wild
A closer look at api_base SSRF (CVE-2024-6587) activity in the wild, and its nested variant
Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild
Threat actors attempting to hijack Ollama & LiteLLM endpoints to run pentesting agents, tools and web reverse-engineering
What we can learn from observing real attacks, made by real Adversaries