<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://haind03.github.io/</id><title>HaiND's Blog</title><subtitle>Cybersecurity researcher focused on vulnerability research, reverse engineering, and digital forensics. Threat hunter | CTF player | AI vuln.</subtitle> <updated>2026-10-08T00:47:13+07:00</updated> <author> <name>HaiND</name> <uri>https://haind03.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://haind03.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://haind03.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 HaiND </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Lesson 1.5: Why LLMs cannot separate instructions from data</title><link href="https://haind03.github.io/posts/ai-1-5-instructions-vs-data/" rel="alternate" type="text/html" title="Lesson 1.5: Why LLMs cannot separate instructions from data" /><published>2026-10-08T11:40:00+07:00</published> <updated>2026-10-08T00:35:14+07:00</updated> <id>https://haind03.github.io/posts/ai-1-5-instructions-vs-data/</id> <content type="text/html" src="https://haind03.github.io/posts/ai-1-5-instructions-vs-data/" /> <author> <name>HaiND</name> </author> <category term="LLM Security" /> <category term="Part 01 · LLM Foundations" /> <summary>If you remember only one lesson from this series, make it this one. Almost every LLM vulnerability, from prompt injection to excessive agency, comes from a single architectural limitation. A prepared statement keeps commands and data in two channels. An LLM receives everything as one token stream. What 50 years of security teach: keep commands apart from data The history of injection in sof...</summary> </entry> <entry><title>Lesson 1.4: Tool calling, agents and MCP</title><link href="https://haind03.github.io/posts/ai-1-4-tool-calling-agents-mcp/" rel="alternate" type="text/html" title="Lesson 1.4: Tool calling, agents and MCP" /><published>2026-10-08T11:20:00+07:00</published> <updated>2026-10-08T00:35:14+07:00</updated> <id>https://haind03.github.io/posts/ai-1-4-tool-calling-agents-mcp/</id> <content type="text/html" src="https://haind03.github.io/posts/ai-1-4-tool-calling-agents-mcp/" /> <author> <name>HaiND</name> </author> <category term="LLM Security" /> <category term="Part 01 · LLM Foundations" /> <summary>A chatbot that only produces text can only cause harm through text. The current trend is the agent: an LLM that is given tools so it can act. It can query a database, send email, run commands, call APIs and browse the web. At that point the model output is no longer harmless text. It is a command that gets executed. This is where LLM vulnerabilities move from saying the wrong thing to doing the...</summary> </entry> <entry><title>Lesson 1.3: Embeddings and RAG</title><link href="https://haind03.github.io/posts/ai-1-3-embeddings-and-rag/" rel="alternate" type="text/html" title="Lesson 1.3: Embeddings and RAG" /><published>2026-10-08T11:00:00+07:00</published> <updated>2026-10-08T00:35:14+07:00</updated> <id>https://haind03.github.io/posts/ai-1-3-embeddings-and-rag/</id> <content type="text/html" src="https://haind03.github.io/posts/ai-1-3-embeddings-and-rag/" /> <author> <name>HaiND</name> </author> <category term="LLM Security" /> <category term="Part 01 · LLM Foundations" /> <summary>A model only knows what is in its training data and in its context window. To make it answer from your own documents, such as an internal handbook or a knowledge base, people use RAG (Retrieval-Augmented Generation). RAG is the most common LLM architecture today, and it introduces two OWASP entries of its own (LLM04 data poisoning and LLM08 vector and embedding weaknesses). Understanding RAG is...</summary> </entry> <entry><title>Lesson 1.2: Anatomy of a prompt</title><link href="https://haind03.github.io/posts/ai-1-2-anatomy-of-a-prompt/" rel="alternate" type="text/html" title="Lesson 1.2: Anatomy of a prompt" /><published>2026-10-08T10:40:00+07:00</published> <updated>2026-10-08T00:35:14+07:00</updated> <id>https://haind03.github.io/posts/ai-1-2-anatomy-of-a-prompt/</id> <content type="text/html" src="https://haind03.github.io/posts/ai-1-2-anatomy-of-a-prompt/" /> <author> <name>HaiND</name> </author> <category term="LLM Security" /> <category term="Part 01 · LLM Foundations" /> <summary>When you chat with an assistant, it seems you send exactly one sentence. In fact the application places your sentence inside a much larger structure before it reaches the model. Understanding that structure shows you where to attack and where to patch. Three role messages are joined by the chat template into one flat token sequence with boundary tokens. Three roles: system, user, assistant ...</summary> </entry> <entry><title>Lesson 1.1: How an LLM works</title><link href="https://haind03.github.io/posts/ai-1-1-how-an-llm-works/" rel="alternate" type="text/html" title="Lesson 1.1: How an LLM works" /><published>2026-10-08T10:20:00+07:00</published> <updated>2026-10-08T00:35:14+07:00</updated> <id>https://haind03.github.io/posts/ai-1-1-how-an-llm-works/</id> <content type="text/html" src="https://haind03.github.io/posts/ai-1-1-how-an-llm-works/" /> <author> <name>HaiND</name> </author> <category term="LLM Security" /> <category term="Part 01 · LLM Foundations" /> <summary>To attack or defend an LLM, you do not need the math of the transformer. You do need to understand three things, because every vulnerability in this series comes from them. The model only predicts the next token, it does so by probability, and it has no memory beyond the text it is given. Text becomes tokens, the model produces a probability distribution, one token is sampled and appended, an...</summary> </entry> </feed>
