
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Shellvoide Blog - AI-Powered Cybersecurity, Compliance &amp; Penetration Testing</title>
      <link>https://shellvoide.com/blog/blog</link>
      <description>The Shellvoide security blog: AI-driven penetration testing, vulnerability research, and application security insights from the team behind KLUE.</description>
      <language>en-us</language>
      <managingEditor>info@shellvoide.com (Shellvoide)</managingEditor>
      <webMaster>info@shellvoide.com (Shellvoide)</webMaster>
      <lastBuildDate>Fri, 17 Jul 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://shellvoide.com/blog/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://shellvoide.com/blog/blog/websocket-auth-bypass-bug-bounty-case-study</guid>
    <title>KLUE vs. a Hardened Target: One Bug, No Signature Required</title>
    <link>https://shellvoide.com/blog/blog/websocket-auth-bypass-bug-bounty-case-study</link>
    <description>A detailed bug bounty writeup. Our autonomous agent KLUE spent hours proving a hardened crypto-mining marketplace was hardened, then reverse-engineered its HMAC signing scheme, mapped a STOMP WebSocket buried in the authenticated app bundles, and discovered it performed no authentication at all, routing private per-tenant channels off a client-supplied parameter. An unauthenticated, cross-tenant data leak, responsibly disclosed and rewarded.</description>
    <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>klue</category><category>case-study</category><category>bug-bounty</category><category>ai-pentesting</category><category>websocket-security</category><category>broken-authentication</category><category>stomp</category><category>bola</category><category>idor</category><category>autonomous-security</category><category>appsec</category><category>pentesting</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/glm-deepseek-kimi-opus-pentest-benchmark</guid>
    <title>Low, Medium, Critical: How Four Frontier Models Graded the Same Live Target</title>
    <link>https://shellvoide.com/blog/blog/glm-deepseek-kimi-opus-pentest-benchmark</link>
    <description>We ran KLUE against the same live production target four times, once each behind GLM 5.2, DeepSeek V4 Pro, Kimi K2.7 and Opus 4.8, all on an identical thirty minute budget. Same target, same clock, four risk verdicts from Low to Critical. A field report on what each model sees, what it walks past, whether it got the severity right, and why the cheapest run came back with the most.</description>
    <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>ai-pentesting</category><category>klue</category><category>benchmark</category><category>glm</category><category>deepseek</category><category>kimi-k2</category><category>claude-opus</category><category>ptaas</category><category>autonomous-security</category><category>appsec</category><category>pentesting</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/klue-autonomous-pentest-six-cves</guid>
    <title>Six CVEs in 163 Minutes: An Autonomous Pentest, Reasoning Included</title>
    <link>https://shellvoide.com/blog/blog/klue-autonomous-pentest-six-cves</link>
    <description>We gave our autonomous pentesting agent, KLUE, one real engagement against a mature open-source codebase and 2 hours 43 minutes on the clock. It came back with six CVE-assigned vulnerabilities, including a chained second-order SQL injection and a template injection that reached a shell. This is the annotated reasoning trace.</description>
    <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>klue</category><category>case-study</category><category>ai-pentesting</category><category>autonomous-security</category><category>appsec</category><category>vulnerability-research</category><category>sql-injection</category><category>rce</category><category>ssti</category><category>ssrf</category><category>xss</category><category>penetration-testing</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/klue-dast-benchmark-juice-shop</guid>
    <title>Crawling Isn&#39;t Attacking: A Live-Fire DAST Benchmark</title>
    <link>https://shellvoide.com/blog/blog/klue-dast-benchmark-juice-shop</link>
    <description>We pointed OWASP ZAP, Burp Suite, Acunetix, and our own KLUE at the same live, deliberately-broken web app. Three of them crawled it and reported headers. One forged an admin token, dumped every user, and reset the admin password, all from two requests, unauthenticated. A field report on what dynamic scanners can and cannot reach.</description>
    <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>dast</category><category>dynamic-analysis</category><category>klue</category><category>benchmark</category><category>juice-shop</category><category>owasp-zap</category><category>burp-suite</category><category>acunetix</category><category>appsec</category><category>autonomous-security</category><category>ai-pentesting</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/klue-sast-benchmark-juice-shop</guid>
    <title>Four SAST Tools, One Broken App, and the AI That Hit Zero False Positives</title>
    <link>https://shellvoide.com/blog/blog/klue-sast-benchmark-juice-shop</link>
    <description>A SAST benchmark on OWASP Juice Shop pitting Semgrep, SonarQube, and Snyk Code against KLUE, our autonomous source code analysis platform. The story is in the precision column, and in the vulnerability classes that have no pattern to match at all.</description>
    <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>sast</category><category>static-analysis</category><category>klue</category><category>benchmark</category><category>juice-shop</category><category>semgrep</category><category>sonarqube</category><category>snyk-code</category><category>appsec</category><category>autonomous-security</category><category>ai-pentesting</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/kimi-k2-vs-claude-opus-pentest-benchmark</guid>
    <title>Could Kimi K2.6 Hold Its Own Against Claude Opus on Real Pentest Work?</title>
    <link>https://shellvoide.com/blog/blog/kimi-k2-vs-claude-opus-pentest-benchmark</link>
    <description>We ran four frontier models through the same autonomous pentest engagement. Recall, time to finish, and dollars per run all tell different stories, and Kimi K2.6 turned out to be the surprise on the leaderboard.</description>
    <pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>ai-pentesting</category><category>klue</category><category>benchmark</category><category>kimi-k2</category><category>claude-opus</category><category>ptaas</category><category>autonomous-security</category><category>appsec</category><category>pentesting</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/klue-61-minute-ai-pentest-case-study</guid>
    <title>Inside a 61 Minute Pentest: How KLUE Found 11 Critical Flaws in a Public Sector Web Application</title>
    <link>https://shellvoide.com/blog/blog/klue-61-minute-ai-pentest-case-study</link>
    <description>A case study from an autonomous AI pentest run by KLUE. Eleven confirmed findings in just over an hour, including a blind SQL injection that led to full database takeover. A practitioner walkthrough of the discoveries, the methodology, and the takeaways.</description>
    <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>ai-pentesting</category><category>sql-injection</category><category>cors</category><category>case-study</category><category>klue</category><category>ptaas</category><category>authorization-bypass</category><category>appsec</category><category>pentesting</category><category>autonomous-security</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/blockchain-fundamentals-a-security-engineers-mental-model</guid>
    <title>Blockchain Fundamentals for Security Engineers: Web3 Security Mental Model</title>
    <link>https://shellvoide.com/blog/blog/blockchain-fundamentals-a-security-engineers-mental-model</link>
    <description>Blockchain fundamentals for security engineers covering cryptographic primitives, block structure, consensus (PoW/PoS), Web3 tooling, transaction anatomy, and core Web3 security concepts.</description>
    <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>blockchain</category><category>web3</category><category>web3-security</category><category>cryptography</category><category>ethereum</category><category>smart-contracts</category><category>infosec</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/jwt-attacks-in-the-wild-from-decode-to-exploit</guid>
    <title>JWT Security Guide: Common JWT Vulnerabilities, Attacks, Exploits, and Defenses</title>
    <link>https://shellvoide.com/blog/blog/jwt-attacks-in-the-wild-from-decode-to-exploit</link>
    <description>A practical JWT security guide covering what JWT is, common JWT vulnerabilities, JWT attacks, exploit techniques, and defensive best practices for developers, pentesters, and API security teams.</description>
    <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>jwt-security</category><category>api-security</category><category>appsec</category><category>pentesting</category><category>oauth</category><category>authentication</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/api-pentesting-checklist-what-most-teams-miss</guid>
    <title>API Pentesting Checklist: What Most Teams Miss</title>
    <link>https://shellvoide.com/blog/blog/api-pentesting-checklist-what-most-teams-miss</link>
    <description>Complete API pentesting checklist with OWASP API Top 10 (2023), BOLA/IDOR tests, JWT and OAuth checks, GraphQL security testing, SSRF payloads, business logic abuse scenarios, and reporting guidance.</description>
    <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>api-security</category><category>api-pentesting-checklist</category><category>owasp-api-top-10</category><category>graphql-security</category><category>rest-api-security</category><category>jwt-security</category><category>idor</category><category>appsec</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/kali-cursor-fix</guid>
    <title>Fix Kali Linux Black Screen Blinking Cursor on Boot (VMware/VirtualBox)</title>
    <link>https://shellvoide.com/blog/blog/kali-cursor-fix</link>
    <description>Fix the Kali Linux black screen blinking cursor on boot in VMware or VirtualBox. Switch to a TTY, run startx, and get the desktop back fast.</description>
    <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>kali</category><category>linux</category><category>virtualbox</category><category>vmware</category><category>troubleshooting</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/aws-client-vpn-with-sso-interactive-setup-guide</guid>
    <title>AWS Client VPN with SSO (Interactive Setup Guide)</title>
    <link>https://shellvoide.com/blog/blog/aws-client-vpn-with-sso-interactive-setup-guide</link>
    <description>Interactive guide to set up AWS Client VPN with IAM Identity Center SSO.</description>
    <pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>aws</category><category>client-vpn</category><category>sso</category><category>iam-identity-center</category><category>network-security</category>
  </item>

  <item>
    <guid>https://shellvoide.com/blog/blog/setting-up-openclaw-on-docker</guid>
    <title>Deploying OpenClaw the Easy, Free, and Secure Way: In an Isolated Environment</title>
    <link>https://shellvoide.com/blog/blog/setting-up-openclaw-on-docker</link>
    <description>OpenClaw (ClawdBot) is powerful, but running it bare-metal on your host is a security gamble. In this guide, we skip the expensive Mac Mini route and deploy OpenClaw inside a Docker container: fully isolated, completely free, and set up with a single command.</description>
    <pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>cybersecurity</category><category>docker</category><category>ai</category><category>openclaw</category><category>tools</category><category>self-hosting</category>
  </item>

    </channel>
  </rss>
