$ aol.pm
Security research: how systems fail, how attackers think, and how to defend what we run.
Focus
- AI and agent security. Prompt injection, tool abuse, and keeping coding agents inside their lane.
- Self-hosted infrastructure. Hardening the boxes, tunnels and services we run ourselves.
- Identity and access. Passkeys, OIDC, multitenant isolation and the bugs that break it.
- Supply chain. Dependencies, build pipelines and what really ends up in production.
Principles
- Defensive first. Research here exists to make systems safer.
- Test only what we own or are authorized to test.
- Disclose responsibly and give vendors time to fix before publishing details.
- Show the evidence: a reproduction beats a claim.