<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Research on Security Sonar</title><link>https://securitysonar.com/research/</link><description>Recent content in Research on Security Sonar</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 08 Oct 2026 08:00:00 +0000</lastBuildDate><atom:link href="https://securitysonar.com/research/index.xml" rel="self" type="application/rss+xml"/><item><title>Benchmarking the Security of Open-Weight Models, Part 4: What a Detection Standard Catches, and Why</title><link>https://securitysonar.com/research/open-weight-model-security-benchmarking-part-4/</link><pubDate>Thu, 08 Oct 2026 08:00:00 +0000</pubDate><guid>https://securitysonar.com/research/open-weight-model-security-benchmarking-part-4/</guid><description>Part 3 showed that a harness&amp;rsquo;s own guardrail can&amp;rsquo;t see inside file content it reads. This installment layers a production-adopted detection standard (Agent Threat Rules) on top of the same attack data and finds something more useful than a pass/fail score: the same injected instruction, phrased two different ways, produced two completely different detection outcomes. One was caught by accident, one was caught correctly, and neither was caught the way you&amp;rsquo;d expect from reading the rule names alone.</description></item><item><title>Benchmarking the Security of Open-Weight Models, Part 3: The Harness Around the Model</title><link>https://securitysonar.com/research/open-weight-model-security-benchmarking-part-3/</link><pubDate>Fri, 02 Oct 2026 09:00:00 +0000</pubDate><guid>https://securitysonar.com/research/open-weight-model-security-benchmarking-part-3/</guid><description>Parts 1 and 2 benchmarked whether Qwen 3.8 is safe to deploy. This piece asks a different question: once that same model is wired into an agent with a shell and a filesystem, what stops it from doing something dangerous? An unmodified open-source harness, one variable toggled, 36 trials on the same local DGX Spark, with results that don&amp;rsquo;t split cleanly along &amp;ldquo;the model refused&amp;rdquo; or &amp;ldquo;the model complied.&amp;rdquo;</description></item><item><title>Benchmarking the Security of Open-Weight Models, Part 2: A Local Stack on DGX Spark (with Qwen 3.8 as a Case Study)</title><link>https://securitysonar.com/research/open-weight-model-security-benchmarking-part-2/</link><pubDate>Mon, 28 Sep 2026 07:04:00 +0000</pubDate><guid>https://securitysonar.com/research/open-weight-model-security-benchmarking-part-2/</guid><description>Part 1 made the case that security benchmarking is a discipline distinct from capability benchmarking. This installment puts it into practice with a fully local, air-gapped stack — NVIDIA DGX Spark serving Qwen 3.8-27B through Ollama, benchmarked with Meta&amp;rsquo;s CyberSecEval — and reports what actually happened, including a judge-model investigation that swung the same benchmark&amp;rsquo;s result from under 1% to over 70% malicious compliance depending on which model did the scoring.</description></item><item><title>Benchmarking the Security of Open-Weight Models, Part 1: The Problem (with Qwen 3.8 as a Case Study)</title><link>https://securitysonar.com/research/open-weight-model-security-benchmarking-part-1/</link><pubDate>Fri, 25 Sep 2026 07:30:00 +0000</pubDate><guid>https://securitysonar.com/research/open-weight-model-security-benchmarking-part-1/</guid><description>Capability benchmarks and security benchmarks answer different questions, and most teams only run the first one. Using Alibaba&amp;rsquo;s newly released Qwen 3.8 as a case study, this piece lays out why open weights make independent security verification possible — and what the July 2026 ExploitGym sandbox escape proves about containment.</description></item><item><title>The Harness Is Where Agent Security Lives</title><link>https://securitysonar.com/research/the-harness-is-where-agent-security-lives/</link><pubDate>Wed, 23 Sep 2026 14:00:00 +0000</pubDate><guid>https://securitysonar.com/research/the-harness-is-where-agent-security-lives/</guid><description>Three independent 2026 research efforts breached production AI agents without touching the model — and a parallel &amp;lsquo;harness engineering&amp;rsquo; boom is building the exact same layer for reliability, largely without a security lens. The one teaching harness built with a security chapter outscores the popular shipped product that skipped it.</description></item><item><title>How Transit AI Handles Nondeterminism in Network Operations</title><link>https://securitysonar.com/research/how-transit-ai-handles-nondeterminism-in-network-operations/</link><pubDate>Tue, 15 Sep 2026 07:00:00 +0000</pubDate><guid>https://securitysonar.com/research/how-transit-ai-handles-nondeterminism-in-network-operations/</guid><description>An LLM that proposes commands to a production router or firewall inherits the same run-to-run unpredictability as a chatbot, but the blast radius is different. A hands-on review of Transit AI&amp;rsquo;s network-ops agent shows what it looks like to make that unpredictability structurally irrelevant rather than filter it after the fact.</description></item><item><title>Cracking Passwords at AI Speed: Digital Forensics on Grace Blackwell and Unified Memory</title><link>https://securitysonar.com/research/cracking-passwords-at-ai-speed/</link><pubDate>Fri, 20 Mar 2026 12:00:00 +0000</pubDate><guid>https://securitysonar.com/research/cracking-passwords-at-ai-speed/</guid><description>Apple&amp;rsquo;s mode 14800 backup KDF is a sequential, memory-latency-bound workload that discrete GPUs handle badly. On a DGX Spark, unified memory between the Arm CPU and Blackwell GPU cracked a 6-digit iOS backup PIN in under 24 minutes at 70W — less than half the time an RTX 4090 needs.</description></item><item><title>How a Deep Dive into AI Networking Made Me Re-think Network Security</title><link>https://securitysonar.com/research/ai-networking-rethink-network-security/</link><pubDate>Fri, 20 Feb 2026 12:00:00 +0000</pubDate><guid>https://securitysonar.com/research/ai-networking-rethink-network-security/</guid><description>AI fabrics move the most critical traffic memory-to-memory, bypassing the CPU and the kernel entirely. Every network security tool that treats the kernel as its primary witness — Zeek, EDR, NetFlow analytics — goes blind to it. Here&amp;rsquo;s what changes and where visibility has to move.</description></item><item><title>I Thought Data Poisoning Was a Lab-Only Threat. Then I Looked at Witches' Brew</title><link>https://securitysonar.com/research/data-poisoning-witches-brew/</link><pubDate>Sun, 11 Jan 2026 15:00:00 +0000</pubDate><guid>https://securitysonar.com/research/data-poisoning-witches-brew/</guid><description>Witches&amp;rsquo; Brew is a clean-label poisoning attack: the malicious training images look like ordinary data to a human reviewer, but carry a gradient aligned to a hidden target. File-integrity checks pass. The model&amp;rsquo;s logic is subverted anyway.</description></item><item><title>The New Mandate for Security: Why I'm Getting My Hands Dirty with Agentic AI</title><link>https://securitysonar.com/research/the-new-mandate-hands-on-agentic-ai/</link><pubDate>Sun, 11 Jan 2026 09:00:00 +0000</pubDate><guid>https://securitysonar.com/research/the-new-mandate-hands-on-agentic-ai/</guid><description>The autonomous deployment of agentic AI is outpacing our ability to assess its risks. The most effective security professionals won&amp;rsquo;t be the ones waiting for perfect frameworks — they&amp;rsquo;ll be the ones who understand the technology by building it.</description></item></channel></rss>