AI Security Agno and LMDeploy expose two critical AI runtime boundaries
CVE-2026-76832 escapes Agno's base_dir while CVE-2026-76850 abuses pickle in LMDeploy. We examine fixes, exposure and runtime isolation.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security CVE-2026-76832 escapes Agno's base_dir while CVE-2026-76850 abuses pickle in LMDeploy. We examine fixes, exposure and runtime isolation.
Vulnerabilities and CVEs Citrix fixed an authentication bypass and memory overflow in NetScaler ADC and Gateway. We explain SAML, SIP ALG, affected builds and HA rollout.
AI Security OpenAI is pairing frontier-model ZDR with private abuse-pattern detection. We analyse scope, the CSAM exception, customer keys and due-diligence questions.
Vulnerabilities and CVEs Three Splunk advisories dated 19 August cover 92 CVEs. We analyse RCE, unsafe deserialisation, SPL and SQL injection, roles and rollout priorities.
AI Security SkyWalking MCP 0.1.0 allowed a tool to change its backend URL and manipulate GraphQL. We analyse MCP boundaries, exposure and the 0.2.0 upgrade.
Vulnerabilities and CVEs Mozilla released Firefox 154 and new ESR builds with a substantial security package. We explain the major CVEs, enterprise exposure and rollout priorities.
AI Security OpenAI slowed frontier development after the Hugging Face incident and its Astra assessment. We examine sandboxes, CoT monitoring, cost and lab controls.
Vulnerabilities and CVEs Oracle's final bulletin contains 943 new fixes across databases, EBS, Middleware, Java and other products. Here is how to turn the matrix into a rollout plan.
Vulnerabilities and CVEs Apple released three major security updates on 17 August. We examine ImageIO, WebKit, Kernel and Telephony fixes and a practical MDM rollout plan.
Vulnerabilities and CVEs CVE-2026-15623 was disclosed on 17 August, although Google fixed it in SecOps 6.3.85 in May. We examine blind SQLi, chronology, risk and monitoring.
AI Security Three MLflow flaws combine redirect SSRF, lineage writes without UPDATE and cross-user artifact reads. We analyse the 3.15.0 fixes and hardening.
AI Security Two Onyx flaws exposed other users' MCP OAuth tokens and let curators extend access into another group's documents. We examine the mechanics, fixes and detection.
Identity and Access Three LemonLDAP::NG and Net::OAuth flaws show how state, oauth_verifier and pre-auth dispatch semantics can quietly move an SSO trust boundary.
Cloud, Infrastructure and DevSecOps A provider-cache symlink, expensive ZIP files and an older sensitive-value leak show why IaC directories and package sources are security inputs.
Penetration Testing and AppSec A wave of Scriban CVEs shows why LoopLimit and object filters are insufficient. We analyse DoS, CLR property writes and safer template execution.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.