This is a site about the collision of two fields that used to sit apart: artificial intelligence and offensive security. It covers how AI is changing the way systems are attacked and tested, and how the AI systems now being deployed everywhere can themselves be broken. It is written for the people who do the work: penetration testers, red teamers, security engineers, and the developers shipping AI features who have to live with the consequences.
There is a great deal of noise in this space. Every tool claims to find every vulnerability with AI, and every breach is blamed on it. The aim here is the opposite of that: to separate what is genuinely new and important from what is marketing, and to write about it plainly enough that someone can act on it.
Two Subjects, Kept Separate
The phrase “AI in security” bundles together two different disciplines, and confusing them is the first mistake. The first is using AI to do security work: language models that read code, sift reconnaissance, draft exploits and summarise findings. The second is testing AI itself: probing the chatbots, agents and pipelines that organisations are putting in front of customers and wiring into their own operations. The techniques, the risks and the skills are different, and this site treats them as the separate things they are.

Why It Needs Covering
The reason this matters now is timing. Organisations are deploying AI features faster than they are securing them. A support chatbot is wired into a customer database; an agent is given tools and left to act on its own; a model is asked to summarise documents that arrive from strangers. Each of these is a new attack surface, with failure modes that a standard testing methodology was never designed to find.
These are not theoretical risks. A model that cannot tell its instructions apart from the data it reads can be talked out of its rules by a sentence hidden in an email. A model given tools does not just say the wrong thing when it is fooled; it does the wrong thing. The systems are live, the techniques for testing them are immature, and the people deploying them frequently do not know what they have exposed. That gap is what this site exists to close.

What You Will Find Here
Explainers. How the attacks and defences actually work, in plain language, with diagrams you can put in front of people who are not specialists.
Offensive AI. Using AI to test: where it genuinely speeds up the work, and where it will confidently mislead you if you let it.
Testing AI Systems. Red-teaming language models and agents: prompt injection, jailbreaks, data disclosure, tool abuse, and how to assess them methodically rather than by poking at a chat box.
Defence. Securing AI systems and the tools they call, built on the assumption that the model will sometimes be fooled and that this has to be survivable.
Tooling. The AI security tools on the market, sorted by how well they hold up in practice rather than by how they are advertised.
How This Site Works
A few principles shape everything published here.
Independent, with nothing to sell. This site does not sell a product or promote one. Where an article discusses tools or techniques, it describes what works and why, and leaves the choice to the reader. If that ever changes, it will be stated on the page.
Practical over theoretical. The test of any piece here is whether a working practitioner can do something with it. The goal is guidance that survives contact with a real system, not a survey of everything that could go wrong.
Claims are checked. AI is a field where confident, wrong statements are cheap to produce. Facts here are verified rather than generated, and where something is uncertain it is marked as uncertain rather than dressed up as settled.
The writing is deliberately unattributed. The subject matters more than the byline, and keeping the focus on the work rather than the author is a choice, not an oversight.