Marco Pedrinazzi

Research & Experiments

A collection of my security research and experiments. Some of this work is associated with the company I work for, and some comes from independent research I do in my own time.

  1. Prompt, Publish, Phish: In-the-Wild Abuse of the Framer AI Website Builder
  2. Bypassing Amazon Bedrock Guardrails Content Filters
  3. The Payload Is in the Header: A New Prompt Injection Blind Spot
  4. Tales of an Ollama Honeypot (Part 4): LLMjacking for SSH Credential Recon
  5. Compromised YouTube Channel Uses “Free Unlimited Claude Opus 4.8” Lure to Deploy Malware
  6. RedTail Docker API Campaign Evolves: SSH-Based Payload Delivery
  7. DinDoor Is Back: Fake ChatGPT and Claude Installers Show MuddyWater-Linked Payloads
  8. Tales of an Ollama Honeypot (Part 3): More Traffic, More Findings
  9. Tales of an Ollama Honeypot (Part 2): LLMJacking
  10. Tales of an Ollama Honeypot (Part 1): Abuse Patterns
  11. How Nova Rules Are Automatically Validated and Tested
  12. ClawHavoc Pivot: AMOS Stealer Delivered via ClawHub Skill-Page Comments
  13. Skills Meet Osquery: Introducing Osquery-helper
  14. DARTS: Open Source AI Application Testing Framework
  15. TwistScan: detection of malicious domains using dnstwist permutations and urlscan.io analysis
  16. Exposed Fortinet Fortigate firewall interface leads to LockBit Ransomware (CVE-2024-55591)
  17. Weekend Plan: Cowrie Honeypot Log Analysis
  18. Automated Threat Intelligence Analysis with n8n and Security Onion