<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>NullSquare blog</title>
  <link>https://nullsquare.net/blog/</link>
  <atom:link href="https://nullsquare.net/blog/rss.xml" rel="self" type="application/rss+xml" />
  <description>Field notes from NullSquare on AI security testing and security operations.</description>
  <language>en</language>
  <lastBuildDate>Sat, 20 Jun 2026 00:00:00 GMT</lastBuildDate>
  <item>
    <title>The Fable ban is really a scope-control warning</title>
    <link>https://nullsquare.net/blog/anthropic-fable-ban-prompt-injection-scope/</link>
    <guid>https://nullsquare.net/blog/anthropic-fable-ban-prompt-injection-scope/</guid>
    <description>Anthropic Fable 5 showed the hard truth of frontier AI safety: stronger coding and bug-finding models are also stronger cyber systems.</description>
    <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Evidence quality is the real security signal</title>
    <link>https://nullsquare.net/blog/evidence-quality-security-findings/</link>
    <guid>https://nullsquare.net/blog/evidence-quality-security-findings/</guid>
    <description>Security findings only create momentum when evidence is reproducible, scoped, understandable, and easy to retest after a fix lands.</description>
    <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Private runners make internal testing practical</title>
    <link>https://nullsquare.net/blog/private-runners-internal-security-testing/</link>
    <guid>https://nullsquare.net/blog/private-runners-internal-security-testing/</guid>
    <description>Internal security testing needs local reach, strict authorization, and evidence handling that works without exposing private networks.</description>
    <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>The annual pentest myth breaks in the glass-door era</title>
    <link>https://nullsquare.net/blog/ai-agents-hacker-defender-continuous-security/</link>
    <guid>https://nullsquare.net/blog/ai-agents-hacker-defender-continuous-security/</guid>
    <description>When AI agents can attack and defend continuously, companies need living security evidence instead of one annual pentest report.</description>
    <pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Prompt injection testing has to leave the chat box</title>
    <link>https://nullsquare.net/blog/prompt-injection-testing-real-workflows/</link>
    <guid>https://nullsquare.net/blog/prompt-injection-testing-real-workflows/</guid>
    <description>AI security testing works best when prompt injection is tested across documents, tools, memory, permissions, and real workflow boundaries.</description>
    <pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>AI security testing works best when it becomes a release gate</title>
    <link>https://nullsquare.net/blog/ai-security-release-gates/</link>
    <guid>https://nullsquare.net/blog/ai-security-release-gates/</guid>
    <description>A practical model for using AI-assisted security testing before release without slowing engineering teams down.</description>
    <pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate>
  </item>
  <item>
    <title>Continuous AI security testing needs a tighter feedback loop</title>
    <link>https://nullsquare.net/blog/continuous-ai-security-testing/</link>
    <guid>https://nullsquare.net/blog/continuous-ai-security-testing/</guid>
    <description>How AI-assisted offensive testing turns one-off assessments into a repeatable operating rhythm for security teams.</description>
    <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
  </item>
</channel>
</rss>
