Author name: ahmar.s3.imam

With over 8 years of hands-on experience in cloud security and application security design, I have successfully led projects for global enterprises to strengthen their security posture, enhance user authentication, and protect sensitive data.

Visual overview illustrating agent skill poisoning with a malicious SKILL.md file and an AI agent bot

Agent Skill Poisoning: What It Is & the ClawHavoc Attack

A new attack called agent skill poisoning let hackers hide malware inside 1,184 “harmless” plugins on ClawHub, the OpenClaw AI agent marketplace. Here’s how the ClawHavoc campaign worked, why normal security tools missed it, and what it means that “supply chain risk”, a term now also used against Anthropic by the Pentagon, has entered the AI world for the first time.

Agent Skill Poisoning: What It Is & the ClawHavoc Attack Read More »

Dashboard of an MCP server security scanner displaying overall security grade and vulnerability severity breakdown.

MCP Server Security Scanner: Why Do You Need Them

About the Author This article was written by Ahmar Imam with over a decade of combined experience in threat intelligence, identity protection, and incident response. Ahmar is a founder of D3C Consulting, where his team monitors emerging attack campaigns daily and works directly with enterprise security teams and individual consumers to mitigate data breach risks.

MCP Server Security Scanner: Why Do You Need Them Read More »

Laptop on a pedestal displaying the dashboard of a Vibe Coding Security Scanner highlighting detected AI code vulnerabilities.

Vibe Coding Security Scanner: Find AI Code Vulnerabilities

AI coding tools like Claude Code, Cursor, and Lovable ship features fast — but a growing body of research shows nearly half of AI-generated code contains a serious vulnerability. This post breaks down the most common flaws in “vibe-coded” apps, walks through the Moltbook breach in detail, and gives you a scanner and checklist to catch these issues before they reach production.

Vibe Coding Security Scanner: Find AI Code Vulnerabilities Read More »

Abstract glowing neon blue shield with a central padlock icon on a dark background, representing Frontier AI application security integration.

What Is Frontier AI? New Application Security Revolution

Frontier AI is moving from research labs into the heart of enterprise cybersecurity. This deep dive explains what frontier AI actually is, why traditional application security tools are hitting their limits, and how IBM’s new partnership with OpenAI, anchored by a new AI-driven application security service and the $5 billion Project Lightwell initiative, is redefining how enterprises detect, validate, and respond to vulnerabilities at machine speed.

What Is Frontier AI? New Application Security Revolution Read More »

A workflow diagram outlining the 5 steps of a deepfake voice attack chain, showing how a fraudster records a voice sample, clones it with AI, calls a bank, bypasses biometric verification, and gains illegal account access in under 2 minutes.

Deepfake Voices Are Breaking Bank Security

In 2026, a 30-second audio clip is all a fraudster needs to clone your customer’s voice. Deepfake technology has advanced so fast that bank call centers and biometric authentication systems can no longer tell the difference between a real person and an AI-generated copy. This guide breaks down exactly how these attacks work, which industries are at greatest risk, and what cybersecurity leaders must do right now.

Deepfake Voices Are Breaking Bank Security Read More »

A bold graphic displaying the text 'The #1 OWASP API Risk' hovering above a server and padlock icon, referencing the severity of Broken Object Level Authorization.

How Broken Object Level Authorization became the #1 API threat

Your API may be handing over private user data to anyone who asks — and you might not even know it.

Broken Object Level Authorization (BOLA) is the #1 threat on the OWASP API Security Top 10 list. It has been used to breach Uber, Facebook, Trello, and hundreds of other companies. Over 57% of organizations have faced some form of this attack.

In simple terms: your API checks if a user is logged in. But it doesn’t check if they’re allowed to see THAT specific record. One changed number in a URL can expose someone else’s data.

This guide breaks down what BOLA is, how it works, real-world breach case studies, and a step-by-step plan to fix it — written for developers, security teams, and business leaders alike

How Broken Object Level Authorization became the #1 API threat Read More »

A dark hero image featuring the text "Harvest Now, Decrypt Later" alongside a broken key icon inside an atomic/quantum symbol.

What are The ‘Harvest Now, Decrypt Later’ Attacks

Hackers don’t need to break your encryption today. They’re stealing your encrypted data right now and storing it, waiting for quantum computers to crack it open years from now. This silent strategy is called “harvest now, decrypt later,” and it may already be targeting your organization. Here’s everything you need to know.

What are The ‘Harvest Now, Decrypt Later’ Attacks Read More »

Illustration of a hacker with a mask and laptop, featuring icons for mobile security, physical intrusion, and quantum physics, titled "AiTM Proxy Attacks Explained."

AiTM Proxy Attacks Explained: How Hackers Bypass MFA, Steal Session Cookies, and Why the Quantum Threat Makes It Worse

Multi-factor authentication (MFA) was supposed to be the last line of defense. But a new class of attack, Adversary-in-the-Middle (AiTM) proxy phishing, has found a way around it. By acting as a silent relay between you and your trusted login page, attackers steal your session cookies the moment authentication completes. And with quantum computing on the horizon, today’s encryption may soon offer no protection at all. Here’s what you need to know.

AiTM Proxy Attacks Explained: How Hackers Bypass MFA, Steal Session Cookies, and Why the Quantum Threat Makes It Worse Read More »

A hooded hacker sitting at a computer with digital code overlays, titled Exploitation of Public-Facing Applications: How Attackers Break In and How to Stop Them.

Exploitation of Public-Facing Applications

Every internet-connected application is a potential entry point for attackers. In 2024 alone, exploitation of public-facing applications was one of the top initial access techniques used in real-world breaches. This guide breaks down exactly how these attacks happen, which applications are most at risk, and what your security team can do right now to reduce exposure, without breaking your business operations

Exploitation of Public-Facing Applications Read More »

Scroll to Top