14 Jan 26
We exploited a lack of isolation mechanisms in multiple agentic browsers to perform attacks ranging from the dissemination of false information to cross-site data leaks. These attacks resurface decades-old patterns of vulnerabilities that the web security community spent years building effective defenses against.
06 Dec 25
25 Nov 25
08 Nov 25
07 Nov 25
27 Oct 25
Local LLMs prioritize privacy over security. Our research reveals a 95% backdoor injection success rate. If you’re running a local LLM for privacy and security, you need to read this
24 Oct 25
This weblog features the work of developer Simon Willison, primarily focusing on the latest developments in AI, large language models (LLMs), prompt injection vulnerabilities, coding agents, and related software and security topics.
28 Sep 25
12 Aug 25
It’s a good idea to use AI to review the security of your code, although you may get surprising results!
09 Aug 25
A really good presentation on the security vulnerabilities of today
06 Aug 25
15 Jul 25
14 Jul 25
13 Jul 25
02 Jun 25
Web review of Ervin