IncidentKiro IDE Vulnerability: What Went Wrong
A prompt injection flaw in Amazon s Kiro IDE allowed attackers to exfiltrate source code and credentials through a feature meant to assist developers. Disclosed by Mindgard in late 2024, the vulnerabi
Expert perspectives on application security, compliance, and emerging threats
IncidentA prompt injection flaw in Amazon s Kiro IDE allowed attackers to exfiltrate source code and credentials through a feature meant to assist developers. Disclosed by Mindgard in late 2024, the vulnerabi
IncidentWhat Happened James Kettle from PortSwigger released HTTP Terminator, an AI-powered open source tool that discovered six previously unknown HTTP request-smuggling techniques. The tool uses machine lea
GeneralYour team just deployed an AI agent that drafts contracts, schedules meetings, and pulls customer data from three different systems. Someone asks: How does it authenticate? The answer you get back is
IncidentWhat Happened CERT/CC disclosed two critical vulnerabilities in Kaltura s HTML5 video player library (mwEmbed) that remain unpatched. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both resu
Get weekly security insights and compliance updates delivered to your inbox.
IncidentOn July 27, attackers began exploiting a critical vulnerability in Gitea, a popular self-hosted Git service. The flaw, tracked as CVE-2026-60004, allows remote attackers to execute arbitrary shell com
IncidentWhat Happened Attackers exploited CVE-2026-60004 , a critical code injection vulnerability in Gitea, to execute arbitrary shell commands on unpatched self-hosted instances. The attack chain was straig
IncidentOn a Tuesday morning, Wordfence disclosed CVE-2026-18431, a critical vulnerability in Avada that lets unauthenticated attackers execute arbitrary PHP code on your server. No phishing email. No stolen
IncidentOn a Tuesday morning, your monitoring alerts fire. An attacker is exploiting a vulnerability in your API authentication layer that your last pentest missed. The exploit code is sophisticated, targetin
IncidentOn February 5, 2025, Sonatype published advisory sonatype-2026-006746 about a technique bypassing Log4j s FilteredObjectInputStream deserialization control. They didn t assign it a CVE, and Apache did
IncidentA malicious website can rewrite your local AI model s behavior without you knowing. Researchers at Cyera discovered this vulnerability in Nvidia s NemoClaw AI assistant, highlighting the urgent need f
GeneralYour AI agents aren t just writing code anymore. They re generating gigabytes of execution traces that your compliance team wants to audit, your debugging team needs to query, and your infrastructure
IncidentOn August 25, 2026, Oasis Security revealed a vulnerability in NVIDIA NemoClaw that allows a webpage controlled by an attacker to take over a local Ollama instance on your machine. Although no exploit
IncidentWhat Happened NVIDIA s OpenClaw tool had a vulnerability allowing attackers to access the local model server without authentication via the Ollama API. This flaw enabled ongoing corruption of AI agent
IncidentTwo critical vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin allowed attackers to access WordPress admin panels without credentials. Although both flaws are now patched, exploitation
IncidentA security flaw in Marimo s Python notebook software allowed attackers to execute arbitrary Model Context Protocol (MCP) commands before any cell code ran. The vulnerability, tracked as CVE-2026-75149
IncidentYour Gitea instance just served cryptojacking malware to an attacker who never should have had access. This isn t hypothetical. CVE-2026-60004, a remote code execution vulnerability with a CVSS score