dr.chaos

Dr. Chaos is back — dark security, total chaos, and adversarial AI

Aamir Lakhani2 min read

The lab is back online.

Dr. Chaos has been the home of dark security and total chaos since 2013 — hundreds of articles on penetration testing, the dark web, malware analysis, and the tools of the trade. This relaunch keeps all of it (browse the legacy archive) and points the blog at the fight that defines this decade: adversarial and offensive AI.

What to expect

  • News & analysis — what's actually happening in AI-powered attacks and defense, without the vendor gloss.
  • Tutorials & demos — hands-on, lab-tested walkthroughs. Prompt injection, model red teaming, AI-assisted recon, and the classic offensive tradecraft that still works.
  • Editorials — opinions are ours and sometimes sharp. That's the point.
  • Podcast and videos — the Dr. Chaos podcast and conference talks, all in one place.

Stay in the loop

New articles land in the RSS feed the moment they publish, and subscribers get them by email. No spam, no tracking pixels, one-click unsubscribe.

Welcome back to the chaos.

Aamir Lakhani

Founder · Dr. Chaos

Aamir Lakhani is a leading senior security strategist responsible for providing IT security solutions to major enterprises and government organizations. He creates technical security strategies and leads security implementation projects for

~/related

Keep digging

More research along the same attack path.

Kimi K3 and K3 Swarm: An Open-Weight Model Review from the Red Team Chair

A balanced cybersecurity review of Moonshot's Kimi K3 and the multi-agent K3 Swarm. Not "is it smart" but the question a red team actually asks: does an open, self-hostable, agentic model make you more effective on an engagement, and what does it give you that Claude and GPT cannot? Data that stays in the room, no vendor holding your engagement hostage, cost at scale, and a swarm that fits the work, weighed honestly against where the closed frontier models still win.

Aamir Lakhani13 min read

Webshells, Start to Finish: Build One in a Lab, Use It, Then Catch Yourself

The webshell is the cockroach of offensive security: one line of code, arbitrary command execution, and still everywhere. A deep dive into what webshells are, how attackers plant and use them, how red and blue teams both put them to work, plus a hands-on Docker lab where you build a vulnerable app, drop a shell, use it, and then detect and defend against it three different ways.

Aamir Lakhani14 min read

The State of AI Automation: Zapier vs Make vs n8n, Through a Red Team Lens

AI automation quietly became critical infrastructure that security never signed off on. A deep look at where automation actually is in 2026, the real differences between Zapier, Make, and n8n, when to reach for each, and why every one of them is a beautiful new attack surface: standing credentials, unauthenticated webhooks, shadow automation, and prompt injection into agents that hold tools.

Aamir Lakhani15 min read