All topics

vulnerability

67 pieces of writing

A single index change bypassed daily_stock_analysis's entire rate limiter
vulnerability7 min read

A single index change bypassed daily_stock_analysis's entire rate limiter

A self-hosted stock analysis platform trusted the leftmost X-Forwarded-For entry for rate limiting, letting attackers rotate IPs and brute-force the admin login at will.

security12 min read

Git tags, package registries and extension marketplaces share the same broken authentication model

vulnerability8 min read

gptme was passing API keys on the command line where any user could read them

Hermes Agent's worktree feature copied arbitrary files from your filesystem
security7 min read

Hermes Agent's worktree feature copied arbitrary files from your filesystem

Hermes Agent's worktree feature would copy arbitrary files from your filesystem if you cloned a repository with a crafted .worktreeinclude. A two-line path traversal that took four months to land in the codebase.

security7 min read

Summarize's localhost daemon accepted requests from any website

security11 min read

Prompt injection turned MCP-connected code assistants into attack proxies

I found SQL injection in Hugging Face's AI skills framework and got it fixed in nine days
vulnerability7 min read

I found SQL injection in Hugging Face's AI skills framework and got it fixed in nine days

An audit of Hugging Face's skills repository found five SQL injection vectors in a single file. The fix was merged in nine days.

Anthropic's Claude Code Security found 500 zero-days. The methodology was the problem.
security8 min read

Anthropic's Claude Code Security found 500 zero-days. The methodology was the problem.

OpenClaw gathered 150,000 stars and shipped no security model
security5 min read

OpenClaw gathered 150,000 stars and shipped no security model

When a GitHub Action rewrites its own history
security6 min read

When a GitHub Action rewrites its own history

A compromised GitHub Action silently rewrote every version tag to point at a single malicious commit - exposing secrets across 23,000 repositories in the process.

Weekly digests

Weekly threat intelligence digest — 2026-W12

Digest

Weekly threat intelligence digest — 2026-W11

Digest

Weekly threat intelligence digest — 2026-W10

Digest

Weekly threat intelligence digest — 2026-W09

Digest

Weekly threat intelligence digest — 2026-W08

Digest

Weekly threat intelligence digest — 2026-W07

Digest

Weekly threat intelligence digest — 2026-W06

Digest

Weekly threat intelligence digest — 2026-W05

Digest

Weekly threat intelligence digest — 2026-W04

Digest

Weekly threat intelligence digest — 2026-W03

Digest

Weekly threat intelligence digest — 2026-W02

Digest

Weekly threat intelligence digest — 2025-W52

Digest

Weekly threat intelligence digest — 2025-W51

Digest

Weekly threat intelligence digest — 2025-W50

Digest

Weekly threat intelligence digest — 2025-W49

Digest

Weekly threat intelligence digest — 2025-W48

Digest

Weekly threat intelligence digest — 2025-W47

Digest

Weekly threat intelligence digest — 2025-W46

Digest

Weekly threat intelligence digest — 2025-W45

Digest

Weekly threat intelligence digest — 2025-W44

Digest

Weekly threat intelligence digest — 2025-W43

Digest

Weekly threat intelligence digest — 2025-W42

Digest

Weekly threat intelligence digest — 2025-W41

Digest

Weekly threat intelligence digest — 2025-W40

Digest

Weekly threat intelligence digest — 2025-W39

Digest

Weekly threat intelligence digest — 2025-W38

Digest

Weekly threat intelligence digest — 2025-W37

Digest

Weekly threat intelligence digest — 2025-W36

Digest

Weekly threat intelligence digest — 2025-W35

Digest

Weekly threat intelligence digest — 2025-W34

Digest

Weekly threat intelligence digest — 2025-W33

Digest

Weekly threat intelligence digest — 2025-W32

Digest

Weekly threat intelligence digest — 2025-W31

Digest

Weekly threat intelligence digest — 2025-W30

Digest

Weekly threat intelligence digest — 2025-W29

Digest

Weekly threat intelligence digest — 2025-W28

Digest

Weekly threat intelligence digest — 2025-W27

Digest

Weekly threat intelligence digest — 2025-W26

Digest

Weekly threat intelligence digest — 2025-W25

Digest

Weekly threat intelligence digest — 2025-W24

Digest

Weekly threat intelligence digest — 2025-W23

Digest

Weekly threat intelligence digest — 2025-W21

Digest

Weekly threat intelligence digest — 2025-W20

Digest

Weekly threat intelligence digest — 2025-W19

Digest

Weekly threat intelligence digest — 2025-W17

Digest

Weekly threat intelligence digest — 2025-W16

Digest

Weekly threat intelligence digest — 2025-W15

Digest

Weekly threat intelligence digest — 2025-W13

Digest

Weekly threat intelligence digest — 2025-W12

Digest

Weekly threat intelligence digest — 2025-W11

Digest

Weekly threat intelligence digest — 2025-W10

Digest

Weekly threat intelligence digest — 2025-W07

Digest

Weekly threat intelligence digest — 2025-W06

Digest

Weekly threat intelligence digest — 2025-W05

Digest

Weekly threat intelligence digest — 2025-W03

Digest

Weekly threat intelligence digest — 2025-W02

Digest

Weekly threat intelligence digest — 2025-W01

Digest