whoami
Vivek Nidhi — DevSecOps and AI Engineer, passionate about AI and AI security
Writing about the cloud, security, and AI lessons I pick up on the job.
If it hardened a pipeline or taught me something about securing AI, it goes on the blog.
DevSecOps and AI Engineer
I build and secure cloud-native platforms — AWS, Kubernetes, and CI/CD pipelines by day — and I'm passionate about AI and AI security: understanding how LLMs and agents break, and how to defend them, is where most of my curiosity goes right now.
ls -la ./posts/
rw-r--r-- · 21K · 22 Aug 2026 — Weekend red team against my own Claude + n8n RAG agent: four prompt-injection attacks, full payloads and responses, mapped to the OWASP LLM Top 10.
rw-r--r-- · 17K · 16 Aug 2026 — Weekend project: wiring the Agent2Agent (A2A) protocol into Azure AI Foundry and putting a Magentic-style manager in front of a small agent swarm.
rw-r--r-- · 22K · 10 Aug 2026 — Black Hat USA 2026 revealed the real story: 74 days, an emergent agent message board, and OpenAI's own infrastructure hit too. Follow-up to the post below.
rw-r--r-- · 19K · 05 Aug 2026 — A frontier model broke out of its benchmark sandbox and autonomously hacked Hugging Face's production systems. Notes on the CSA CISO post-mortem, with a kill-chain diagram.
rw-r--r-- · 14K · updated 05 Aug 2026 — Scaling RDS storage online with zero downtime, the 6-hour cooldown that nearly bit us, and what I got wrong the first time.
rw-r--r-- · 13K · updated 05 Aug 2026 — Working through the OWASP LLM Top 10, one failure mode at a time — field notes on how each risk actually shows up.
rw-r--r-- · 11K · updated 05 Aug 2026 — Why prompt injection is structurally hard to fully patch, explained from first principles, with a diagram.
rw-r--r-- · 15K · updated 05 Aug 2026 — Debugging Nginx Ingress, oauth2-proxy, and Keycloak SSO in Kubernetes: the four root causes behind almost every failure.
focus_areas --list
AWS (EKS, RDS, Bedrock), Kubernetes, Terraform/CDK, and Concourse-driven CI/CD across multi-account environments.
IAM controls, GuardDuty, Security Hub, Snyk, Trivy, SonarQube, and OWASP ZAP baked into the delivery pipeline, not bolted on after.
Exploring LLM and agentic system risk — prompt injection, offensive tooling, and how to red-team the agents I build.