<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Miller Engelbrecht -- Security Research</title>
    <link>https://millerengelbrecht.com</link>
    <description>Security research on AI systems, bug bounty, and prompt injection by Miller Engelbrecht.</description>
    <atom:link href="https://millerengelbrecht.com/rss.xml" rel="self" type="application/rss+xml"/>
    <language>en</language>
    <copyright>Miller Engelbrecht</copyright>

    <item>
      <title>Clone This Repo and I Own Your Machine</title>
      <link>https://millerengelbrecht.com/posts/dns-payload-claude-code.html</link>
      <description>How npm postinstall lifecycle hooks become a DNS command channel, silently executing attacker-controlled payloads on developer machines and CI runners.</description>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid isPermaLink="true">https://millerengelbrecht.com/posts/dns-payload-claude-code.html</guid>
      <category>ai-security</category>
      <category>bug-bounty</category>
    </item>

    <item>
      <title>The Commit Message You Can't Read</title>
      <link>https://millerengelbrecht.com/posts/invisible-unicode-injection.html</link>
      <description>How invisible Unicode Tag characters can be embedded in git commit messages to inject hidden instructions into AI coding agents that process repository metadata.</description>
      <pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate>
      <guid isPermaLink="true">https://millerengelbrecht.com/posts/invisible-unicode-injection.html</guid>
      <category>prompt-injection</category>
    </item>

  </channel>
</rss>
