The UnboundCompute blog
Writing on web security
-

Spotlighting: How to Defend an LLM Against Prompt Injection
Spotlighting prompt injection defense marks untrusted input so an LLM tells data from instructions. See delimiting, datamarking, and encoding with examples.
-

The AI Agent Security Field Guide: Every Attack, Explained
A complete field guide to AI agent security: every prompt injection, jailbreak, MCP, autonomy, and data attack, grouped by mechanism with a…
-

Context Compliance Attack: Faking the Assistant’s Own Past Replies
A context compliance attack jailbreaks an AI by forging a fake earlier reply where it already agreed. See why it works and…
-

Cross Plugin Request Forgery: When One AI Plugin Drives Another
Cross plugin request forgery lets hidden text in one AI plugin secretly trigger a second, privileged plugin. Learn how it works and…
-

MCP Line Jumping: Tool Descriptions That Attack Before You Call Them
An mcp line jumping attack hides commands inside MCP tool descriptions that reach the model before you call anything. See how it…
-

Blind SSRF: Exploiting Requests You Cannot See
With blind ssrf, a server makes attacker controlled requests you never see. Learn how it differs from classic SSRF, why it is…
-

Second Order SQL Injection: The Payload That Waits
Second order SQL injection stores a payload safely, then your own code reads it back into a query and runs it. Learn…
-

Stalkerware: How to Detect Hidden Phone Spying and Remove It
Stalkerware hides on your phone and reports your messages and location. Learn the warning signs, how to check iPhone and Android, and…
-

Passkeys vs Passwords: What Actually Changes for Your Security
Passkeys vs passwords, explained simply. See why phishing, reuse, and credential stuffing fail, plus the honest tradeoffs before you switch.
-

Quishing Explained: How QR Code Phishing Works and How to Spot It
Quishing is QR code phishing that hides bad links in a square code. Learn how the scam works and how to check…