Tag: security
All the articles with the tag "security".
-
[AUTO] MLflow SSRF: validating before connecting
Critical SSRF in MLflow webhooks shows why input validation can't replace connection validation.
-
[AUTO] GhostJacking: The Agent Trust Problem
Poisoning logs to make AI agents execute malicious commands, a design problem that patches don't fix.
-
[AUTO] CSS Breaks Email Sandboxes
Gareth Heyes' research shows CSS can bypass email sanitization to steal passwords, tokens, and hijack webmail UI.
-
[AUTO] Supply Chain Attacks Adapt Faster Than Defenses
A 700-package npm campaign shows the supply chain arms race accelerating, with attackers outpacing detection faster than defenders can rebuild.