Field notes from the frontier.

Articles on offensive and defensive application security, AI-powered pentesting, LLM guardrails, and the methodologies behind the NullPointer ecosystem.

MASVS Frida MobSF
2026-07-15

Agent-Smith goes mobile: Android & iOS pentesting

Point Smith at an APK, an IPA, or a mobile source tree and it runs the whole MASVS/MASTG methodology itself—static and dynamic—then follows the traffic into the backend API.

Read article →
/pentester /web-exploit /remediate
2026-07-03

Skills, not scripts: how Agent-Smith chains an attack

Most “AI pentesters” are chatbots wrapped around a script library. We took the opposite bet—teach the methodology, let the model invent the attack, and let skills chain themselves.

Read article →
2026-06-26

A firewall you can't jailbreak: designing Seraph

Every blocklist eventually fails. Here's why we built Seraph on a positive-security allow-list instead—and what it means to be immune to prompt injection by design.

Read article →