<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>ADCL Research</title>
    <link>https://adcl.io/research.html</link>
    <atom:link href="https://adcl.io/research.xml" rel="self" type="application/rss+xml" />
    <description>Vulnerability research, disclosures, and technical deep-dives from Adaptive Cybersecurity Laboratory (ADCL): offensive techniques written up for defenders.</description>
    <language>en-us</language>
    <lastBuildDate>Thu, 23 Jul 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Why Traditional Penetration Testing Is Broken</title>
      <link>https://adcl.io/research/why-traditional-pentesting-is-broken.html</link>
      <guid isPermaLink="true">https://adcl.io/research/why-traditional-pentesting-is-broken.html</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Point-in-time penetration testing describes an environment that has already changed by the time the report lands. Why the snapshot model fails against a continuously shifting attack surface, and the case for continuous validation alongside periodic deep testing.]]></description>
      <category>Field Notes</category>
      <dc:creator>ADCL</dc:creator>
    </item>
    <item>
      <title>What Is an LLM?</title>
      <link>https://adcl.io/research/what-is-an-llm.html</link>
      <guid isPermaLink="true">https://adcl.io/research/what-is-an-llm.html</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A plain-language explainer on what a large language model actually is: a next-token predictor scaled up until prediction starts to look like competence. Where LLMs came from, how they are trained, what they cannot do on their own, and why that matters for security tooling.]]></description>
      <category>AI 101</category>
      <dc:creator>ADCL</dc:creator>
    </item>
    <item>
      <title>Signaturing Ghosts</title>
      <link>https://adcl.io/research/signaturing-ghosts.html</link>
      <guid isPermaLink="true">https://adcl.io/research/signaturing-ghosts.html</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The threat-hunting feedback loop works because attackers repeat themselves. Agentic attackers do not. When the adversary generates a signature-free variant per target, the loop keeps converting hard-won findings into detections for code that will never appear again. Here is the hunt, read from the offensive side, and where it breaks.]]></description>
      <category>Field Notes</category>
      <dc:creator>ADCL</dc:creator>
    </item>
    <item>
      <title>Your WAF's Rules Are Static. The Attacker Isn't.</title>
      <link>https://adcl.io/research/agentic-waf-bypass-generator.html</link>
      <guid isPermaLink="true">https://adcl.io/research/agentic-waf-bypass-generator.html</guid>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[An agentic bypass generator, run against a major commercial WAF under bug-bounty safe harbor, produced 652 reproducible edge evasions at a sustained ~25% rate. Why continuous adversarial generation beats static rules and static payload lists.]]></description>
      <category>Field Notes</category>
      <dc:creator>ADCL</dc:creator>
    </item>
  </channel>
</rss>
