Blog

The Pipe That Trusted EveryoneOpenAI
CVE-2026-35603: One Writable Folder, Every User CompromisedAnthropicCursorOpenAIGoogle
When a Web Search Becomes a Backdoor: RCE in Codex CLI via Prompt InjectionOpenAI
When AI Tools Become the Backdoor: Zero-Click RCE via Prompt InjectionAmazonCursorGitHubGoogleOpenAI
CVE-2025-64669: Uncovering Local Privilege Escalation in Windows Admin CenterMicrosoft
CVE-2026-32196: One-Click RCE via Windows Admin Center Control Flow HijackingMicrosoft
The Race to Ship AI Tools Left Security Behind. Part 1: Sandbox EscapeAnthropicGoogleOpenAI
Uncovered: Improper Attestation Signature Validation in Windows Admin CenterMicrosoft
InversePrompt: Turning Claude Against Itself, One Prompt at a TimeAnthropic
EscapeRoute: Breaking the Scope of Anthropic's Filesystem MCP ServerAnthropic
Path Traversal in AWS SSM Agent's Plugin ID ValidationAmazon
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure ADMicrosoft
How Cymulate Discovered an Abuse Risk in Google Cloud PlatformGoogle