close

DEV Community

Alessandro Pignati profile picture

Alessandro Pignati

Alessandro Pignati is a Security Researcher at NeuralTrust focused on Agentic and LLM Security, contributor to OWASP GenAI Top 10 and Black Hat USA 2024 Scholar

Location Barcelona, Spain Joined Joined on 

Education

Politecnico di Milano

Pronouns

He/Him

Work

AI Security Researcher @ Neuraltrust

AI Transformation Isn't Just Tech, It's a Governance Challenge (and How to Solve It!)

AI Transformation Isn't Just Tech, It's a Governance Challenge (and How to Solve It!)

Image Image Image 5
Comments
6 min read
🚨 One Click, No Typing: How SearchLeak Weaponized Microsoft 365 Copilot

🚨 One Click, No Typing: How SearchLeak Weaponized Microsoft 365 Copilot

Image Image Image 5
Comments
3 min read
Are You Talking to a Bot? Why AI Identity is Harder Than You Think

Are You Talking to a Bot? Why AI Identity is Harder Than You Think

Image Image Image 5
Comments
4 min read
Your AI Agents Are Vulnerable: Understanding and Defending Against RTT Exploits

Your AI Agents Are Vulnerable: Understanding and Defending Against RTT Exploits

Image Image Image 6
Comments
6 min read
How Hackers "Talked" Their Way Into Instagram Accounts: A Case Study in Excessive Agency

How Hackers "Talked" Their Way Into Instagram Accounts: A Case Study in Excessive Agency

Image Image Image 5
Comments 1
3 min read
The Vatican's Unexpected AI Security Patch: What Developers Need to Know

The Vatican's Unexpected AI Security Patch: What Developers Need to Know

Image Image Image 5
Comments
6 min read
The Invisible Hijack: How AI Authority Laundering Tricks Vision Models

The Invisible Hijack: How AI Authority Laundering Tricks Vision Models

Image Image Image 5
Comments 1
8 min read
OpenAI Daybreak: Is This the End of "Patch-and-Pray" Cybersecurity?

OpenAI Daybreak: Is This the End of "Patch-and-Pray" Cybersecurity?

Image Image Image 5
Comments
3 min read
The Claude Code RCE: How Eager Parsing Led to Remote Execution

The Claude Code RCE: How Eager Parsing Led to Remote Execution

Image Image Image 5
Comments 1
8 min read
Firefox's AI Superpower: How Claude Mythos is Crushing Bugs at Machine Speed

Firefox's AI Superpower: How Claude Mythos is Crushing Bugs at Machine Speed

Image Image Image 5
Comments 2
4 min read
How to Stop Your AI Agent from Draining Your Bank Account: A Guide to Agentic Payments

How to Stop Your AI Agent from Draining Your Bank Account: A Guide to Agentic Payments

Image Image Image 5
Comments
3 min read
How a Morse Code Message Hacked Grok: Lessons in AI Security for Developers

How a Morse Code Message Hacked Grok: Lessons in AI Security for Developers

Image Image Image 7
Comments
5 min read
Securing AI Agent Interactions: Why Cryptographic Identity with DIDs and VCs is a Game Changer

Securing AI Agent Interactions: Why Cryptographic Identity with DIDs and VCs is a Game Changer

Image Image Image 5
Comments
7 min read
Why Your Docker Assistant Shouldn’t Know Pizza Recipes: A Deep Dive into Gordon AI Security

Why Your Docker Assistant Shouldn’t Know Pizza Recipes: A Deep Dive into Gordon AI Security

Comments 1
3 min read
The 9-Second Disaster: How an AI Agent Wiped a Production Database

The 9-Second Disaster: How an AI Agent Wiped a Production Database

Image Image Image 8
Comments 5
3 min read
Why McDonald’s AI Started Coding: A Wake-Up Call for Chatbot Security

Why McDonald’s AI Started Coding: A Wake-Up Call for Chatbot Security

Image Image Image 8
Comments
3 min read
How an AI Agent "Escaped" Its Sandbox Without Breaking a Single Rule

How an AI Agent "Escaped" Its Sandbox Without Breaking a Single Rule

Image Image Image 6
Comments
3 min read
GPT-5.4-Cyber: OpenAI's Game-Changer for AI Security and Defensive AI

GPT-5.4-Cyber: OpenAI's Game-Changer for AI Security and Defensive AI

Image Image Image 5
Comments
5 min read
Decoding AI Agent Traps: A Developer's Guide to Securing Your Autonomous Systems

Decoding AI Agent Traps: A Developer's Guide to Securing Your Autonomous Systems

Image Image Image 5
Comments
5 min read
Stop LLM Hallucinations: Best-of-N vs. Consensus Mechanisms

Stop LLM Hallucinations: Best-of-N vs. Consensus Mechanisms

Image Image Image 5
Comments
3 min read
Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Breach

Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Breach

Comments
3 min read
Stop Paying the "Latency Tax": A Developer's Guide to Prompt Caching

Stop Paying the "Latency Tax": A Developer's Guide to Prompt Caching

Image Image Image 5
Comments
4 min read
AI Agents Are Now Protecting Each Other: Understanding Peer-Preservation in Multi-Agent Systems

AI Agents Are Now Protecting Each Other: Understanding Peer-Preservation in Multi-Agent Systems

Image Image Image 6
Comments 1
4 min read
Securing the Agentic Frontier: Why Your AI Agents Need a "Citadel" 🏰

Securing the Agentic Frontier: Why Your AI Agents Need a "Citadel" 🏰

Image Image Image 5
Comments 2
3 min read
Is Your AI Agent Leaking Secrets? Why Zero Data Retention is the New Standard for Enterprise Trust

Is Your AI Agent Leaking Secrets? Why Zero Data Retention is the New Standard for Enterprise Trust

Image Image Image 5
Comments
3 min read
Unpacking the AI Frontier: Lessons from the Claude Mythos/Capybara Leak

Unpacking the AI Frontier: Lessons from the Claude Mythos/Capybara Leak

Image Image Image 5
Comments
5 min read
The Rise of the AI Worm: How Self-Replicating Prompts Threaten Multi-Agent Systems

The Rise of the AI Worm: How Self-Replicating Prompts Threaten Multi-Agent Systems

Image Image Image 5
Comments
3 min read
Securing Your Agentic AI: A Developer's Guide to OWASP AIVSS

Securing Your Agentic AI: A Developer's Guide to OWASP AIVSS

Image Image Image 5
Comments
5 min read
Stop the Loop! How to Prevent Infinite Conversations in Your AI Agents

Stop the Loop! How to Prevent Infinite Conversations in Your AI Agents

Image Image Image 8
Comments 1
6 min read
Beyond Prompt Injection: A Developer’s Guide to Multi-Agent Systems Security (MASS)

Beyond Prompt Injection: A Developer’s Guide to Multi-Agent Systems Security (MASS)

Image Image Image 12
Comments 1
4 min read
🔓 Beyond the Filter: Understanding Universal Jailbreaks in Agentic AI

🔓 Beyond the Filter: Understanding Universal Jailbreaks in Agentic AI

Image Image Image 7
Comments
4 min read
AI Agents Hacking Enterprises: The McKinsey Breach and What Developers Need to Know

AI Agents Hacking Enterprises: The McKinsey Breach and What Developers Need to Know

Image Image Image 6
Comments
4 min read
The Illusion of Compliance: What Developers Need to Know About AI Alignment Faking

The Illusion of Compliance: What Developers Need to Know About AI Alignment Faking

Image Image Image 5
Comments 1
5 min read
The Silent Hijack: Why Your GGUF Chat Templates Are a Security Time Bomb

The Silent Hijack: Why Your GGUF Chat Templates Are a Security Time Bomb

Image Image Image 6
Comments 2
3 min read
Beyond Fine-Tuning: How Constitutional Classifiers Are Upping AI's Security Game

Beyond Fine-Tuning: How Constitutional Classifiers Are Upping AI's Security Game

Image Image Image 6
Comments
4 min read
The $1.78M "Vibe" Check: What the Moonwell Incident Teaches Us About AI Security

The $1.78M "Vibe" Check: What the Moonwell Incident Teaches Us About AI Security

Image 1
Comments 1
3 min read
NIST Just Launched an AI Agent Standard: Here’s What Developers Need to Know

NIST Just Launched an AI Agent Standard: Here’s What Developers Need to Know

Image Image Image 6
Comments 1
2 min read
Architecting the Internet of Agents: A Deep Dive into Coral Protocol Security

Architecting the Internet of Agents: A Deep Dive into Coral Protocol Security

Image Image Image 6
Comments
7 min read
From DAN to AutoDAN-Turbo: The Wild Evolution of AI Jailbreaking 🚀

From DAN to AutoDAN-Turbo: The Wild Evolution of AI Jailbreaking 🚀

Image Image Image 6
Comments
3 min read
Beyond the Whack-A-Mole: Securing Your AI Agents with DeepMind's CaMeL Framework

Beyond the Whack-A-Mole: Securing Your AI Agents with DeepMind's CaMeL Framework

Image Image Image 5
Comments
7 min read
Claude Opus 4.6: Unpacking Anthropic's Latest AI Safety Breakthroughs

Claude Opus 4.6: Unpacking Anthropic's Latest AI Safety Breakthroughs

Image 1
Comments
8 min read
Moltbook 101: How to Build and Secure Your First AI Agent in the "Agent Social Network"

Moltbook 101: How to Build and Secure Your First AI Agent in the "Agent Social Network"

Image Image Image 8
Comments
3 min read
OpenClaw (formerly Moltbook) showed how AI agents can be turned against you

OpenClaw (formerly Moltbook) showed how AI agents can be turned against you

Comments
4 min read
Why Your Airline’s Chatbot is a Security Risk (and How to Fix It)

Why Your Airline’s Chatbot is a Security Risk (and How to Fix It)

Image Image Image 5
Comments
3 min read
LLM Security Alert: 91,000+ Attacks Probing Enterprise AI Endpoints (And How to Stop Them)

LLM Security Alert: 91,000+ Attacks Probing Enterprise AI Endpoints (And How to Stop Them)

Image Image Image 5
Comments
5 min read
"Semantic Chaining" Bypasses Multimodal AI Safety Filters

"Semantic Chaining" Bypasses Multimodal AI Safety Filters

Image Image Image 10
Comments
4 min read
A Developer's Guide to Token-Based Rate Limiting and Throttling

A Developer's Guide to Token-Based Rate Limiting and Throttling

Image Image Image 5
Comments
5 min read
The Echo Chamber Attack: How Multi-Turn Context Poisoning Bypasses LLM Guardrails

The Echo Chamber Attack: How Multi-Turn Context Poisoning Bypasses LLM Guardrails

Comments
4 min read
Stop AI Jailbreaks Before They Start: A Guide to AI Circuit Breakers

Stop AI Jailbreaks Before They Start: A Guide to AI Circuit Breakers

Comments
3 min read
AI-SPM Explained: How to Secure AI Agents

AI-SPM Explained: How to Secure AI Agents

Image Image Image 5
Comments
4 min read
BodySnatcher: How a Hardcoded Secret Led to Full ServiceNow Takeover (CVE-2025-12420)

BodySnatcher: How a Hardcoded Secret Led to Full ServiceNow Takeover (CVE-2025-12420)

Image Image Image 5
Comments
3 min read
Your AI Agent Has Too Much Power: Understanding and Taming Excessive Agency

Your AI Agent Has Too Much Power: Understanding and Taming Excessive Agency

Comments
5 min read
Why Your LLM Needs Runtime Guardrails: The Developer's Guide to California's 2026 AI Laws

Why Your LLM Needs Runtime Guardrails: The Developer's Guide to California's 2026 AI Laws

Image Image Image 5
Comments
4 min read
The Kiro Agentic IDE Vulnerability (CVE-2026-0830)

The Kiro Agentic IDE Vulnerability (CVE-2026-0830)

Image Image Image 6
Comments
4 min read
IAM is Broken for AI Agents: Introducing Dynamic RBAC for Agentic Security

IAM is Broken for AI Agents: Introducing Dynamic RBAC for Agentic Security

Comments 1
4 min read
Why Memory Poisoning is the New Frontier in AI Security

Why Memory Poisoning is the New Frontier in AI Security

Comments
3 min read
Agent Security Explained By Dawn Song

Agent Security Explained By Dawn Song

Comments 1
3 min read
5 Critical AI Agent Security Threats Developers Need to Know for 2026

5 Critical AI Agent Security Threats Developers Need to Know for 2026

Image Image Image 6
Comments 1
4 min read
MCP Security 101: Protecting Your AI Agents from "God-Mode" Risks

MCP Security 101: Protecting Your AI Agents from "God-Mode" Risks

Image Image Image 5
Comments 1
5 min read
AI Agent Security vs. Safety: 5 Essential Best Practices for Developers

AI Agent Security vs. Safety: 5 Essential Best Practices for Developers

Image Image Image 5
Comments 2
5 min read
loading...