Hi there, I'm

Tony.

A cyber security student and researcher interested in offensive security and open source software. I document my CTF writeups, security research, homelab experiments, network architectures, and other hobby projects here.

Currently focusing on
RedteamingPurpleteamingAttack & Defense CTFsThreat Intel
All posts
🔍
research6 min read · Jul 2, 2026 · by Piraveen Kandiah, Tony Munzer

Identifying capability drift and profiling risks in unmanaged local AI infrastructure

Enterprises increasingly notice local AI deployments inside their networks without approval or onboarding, which results in a class of unmanaged Shadow AI. This paper identifies shadow AI capabilities, capability drift and how to profile risks.

shadow AIagentic AItracking capability driftTezcatLLMscontinuous security evaluationattack surface analysislocal AI infrastructurerisk profiling
project8 min read · Jun 14, 2026

Reviving the WHY2025 Badge, part 2: Emulators & Badge-to-Badge OTA

Part 2 of reviving the WHY2025 badge: porting NES, Game Boy and Sega Master System emulators to a RISC-V badge OS, fighting SPIRAM latency for every frame, and building a badge-to-badge OTA system that updates older badges over an open WiFi network with no PC in sight.

why2025badgeesp32-p4emulationnesgameboysegaotawifidnstlsbadgevmsembedded
project12 min read · Jun 5, 2026

Reviving the WHY2025 Badge, part 1: Firmware Port, Bluetooth & the LED Matrix

The WHY2025 camp is over, that doesn't mean it should collect dust. Part 1 mentions bringing BadgeVMS up to a newer firmware build, surviving the porting war stories, implementing Bluetooth Low Energy and support for the LED-matrix add-on.

why2025badgeesp32-p4esp32-c6firmwareembeddedbluetoothblebadgevmsreverse-engineering