Bringing world-class hackers and a CTF research ecosystem into an organization can make it stronger, but real security improvement requires turning offensive capability into governance and structural change.

Representative Foreword
The representative foreword of this blog: security now fails less at finding issues than at absorbing, sustaining, and acting on what has already been found.
This essay frames the entire site first. The posts on technical analysis, method, and governance all start from this same problem statement.

Detection, Method, Governance

Bringing world-class hackers and a CTF research ecosystem into an organization can make it stronger, but real security improvement requires turning offensive capability into governance and structural change.
A practical method for modeling vulnerabilities as attacker-relevant security state transitions and combining human intuition with bounded AI search

Package and container registry proxies are active trust boundaries for AI runtimes. This report turns incident evidence, public SSRF history, and runtime observations into an artifact egress control architecture.
In practical cryptography, failures often occur in the design—combining randomness, key management, operating modes, error handling, and authentication—rather than in the algorithms themselves. This post outlines criteria for auditing cryptographic implementations from the perspective of security assessors and reversers.
This article explains how I split an XSS security development specification for small local models into core/verify/dev/test overlays, and what I learned while connecting LLM-based judgment to regression-test generation and Jazzer/Jazzer.js fuzzing seeds.
A reading of Korea’s 2025 whole-of-government information protection plan through the structural parallel between the Nightingale myth and the white-hacker discourse. Policy is moving from dependence on individual ethics toward structural accountability, but the transition is not complete.
Through the Nightingale myth, the white-hacker discourse, the Sterbenz lemma, and browser exploit reasoning, this essay argues that the real change LLMs bring lies not in knowledge retrieval but in problem reframing.
The decisive front in national AI strategy is not GPU count alone, but who controls and can prove the flow of data, models, agents, permissions, logs, and verification running on top of those GPUs.
I designed sec-audit-static workflow v2.0, ran it against a real auth-server codebase, and missed two things. This is the record of how those misses were folded back into the tool — through v2.8.
Security controls already exist. The real problem is that we cannot decide which customer, at which moment, deserves how much friction. As the closing chapter of the CAPTCHA·ATO series, this post is about moving from quantity of controls to context of controls — adaptive security as an operational discipline.