Aaron Ott
Cybersecurity leader & AI security researcher — helping teams bridge security, AI, and resilience.
I believe security should be human‑centered and AI‑resilient. That’s why I write, test, and share here.
Featured
How I Turned a Knowledge Gap Into a Quiz Game
Post
I'm bad at identifying flags, so I asked Claude to build me a quiz game. Ten minutes and some debugging later, I had a fully-featured learning tool.
Hacker Manifesto 40 Years Later
Post
It's been 40 years since The Mentor - Loyd Blankenship published 'The Conscience of a Hacker' in Phrack. Still rings true today. I was curious to see what Claude would do with it so I asked it. I think it went super well.
Pen Testing With Claude 4.5
Post
Claude 4.5 ran a 15 minute pen test on my lab, finding 21 real vulnerabilities — powerful but with notable blind spots like XSS.
About
I’m Aaron — OSCP/CISSP/CSSLP and an application‑security leader focused on building AI‑resilient systems. I write playbooks, ship tools, and help teams move fast without breaking everything important.
- Focus areas: NIST CSF 2.0, AppSec leadership, AI security & resilience
- Currently exploring: prompt‑injection labs, AI‑first DR, threat modeling for startups
- Human stuff: dogs, hiking, and whiskey
Latest writing
-
How I Turned a Knowledge Gap Into a Quiz Game
I'm bad at identifying flags, so I asked Claude to build me a quiz game. Ten minutes and some debugging later, I had a fully-featured learning tool.
-
Hacker Manifesto 40 Years Later
It's been 40 years since The Mentor - Loyd Blankenship published 'The Conscience of a Hacker' in Phrack. Still rings true today. I was curious to see what Claude would do with it so I asked it. I think it went super well.
-
AI Security in 2025: What I Learned, and What I'll Be Watching for in 2026
A weekend deep dive into three major AI security reports from 2025, what actually broke in the real world, and where security teams should focus their attention in 2026.
-
Learning n8n by Building: A Small Experiment With Big WYSIWYG Energy
A small morning-weather automation taught me how n8n thinks. It felt a lot like building with early WYSIWYG editors, only this time the output is real …
-
Pen Testing With Claude 4.5
I gave Claude 4.5 access to a Kali box and an intentionally vulnerable app. In 15 minutes it found 21 real vulnerabilities — useful, but with notable blind spots. When is AI useful for pentesting, and when should humans stay in the loop?