PinnedFacundo Fernandez·Oct 11, 2025Why Webhooks Aren’t Enough to Secure LLM Systems — and What 4Node Is Doing About ItWhen teams start adding “security” to their LLM or agentic workflows, the first instinct is often to bolt on a webhook — a callback that…
PinnedFacundo Fernandez·Apr 22, 2025Security Vulnerabilities in Autonomous AI AgentsIntroA response icon2A response icon2
PinnedFacundo Fernandez·Aug 14, 2024How I Prevented a Data Breach by Reporting an IDOR in a System Exposing over 500,000 US PassportsIf we haven’t connected on LinkedIn yet, go ahead and send a request!A response icon3A response icon3
Facundo Fernandez·Oct 28, 2025The Hidden Risk in AI: Context Switching AttacksWhen we talk about AI vulnerabilities, most conversations focus on jailbreaks or prompt injections. But beneath the surface, there’s a far…
Facundo Fernandez·Sep 4, 202520 Prompt Injection Techniques Every Red Teamer Should TestPrompt injection is the SQLi of the LLM era. Every organization rushing to adopt agentic apps, copilots, and AI integrations is exposed to…A response icon4A response icon4
Facundo Fernandez·Jul 1, 2025Top 10 Ways to Achieve Remote Code Execution (RCE) on Web ApplicationsRemote Code Execution (RCE) is a severe security vulnerability that allows attackers to run arbitrary code on a target server over a…A response icon2A response icon2
Facundo Fernandez·Apr 4, 2025Guide to Identifying and Exploiting TOCTOU Race Conditions in Web ApplicationsBefore diving in, if you haven’t checked out my last article on how I hacked ServiceNow’s AI Agent and dumped 128K records — give it a…A response icon2A response icon2
Facundo Fernandez·Feb 26, 2025Full Customer DB dump in Service Now and they called it “Medium Risk” — what a jokeIf you haven’t connected with me on LinkedIn send me a request!A response icon2A response icon2
Facundo Fernandez·Feb 7, 2025Exploiting CSRF in GraphQL ApplicationsIf you haven’t sent me a LinkedIn request yet, send me a request I would love to work with you and do a collab! I will start writing…A response icon1A response icon1