<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Groundy — Security</title><description>Where AI infrastructure inherits the unpatched assumptions of the web stack beneath it, and trust boundaries collapse faster than disclosure timelines can keep up.</description><link>https://groundy.com/</link><item><title>OpenAI&apos;s New Safety Bug Bounty Pays Researchers for Jailbreaks and Policy Bypasses</title><link>https://groundy.com/articles/openais-new-safety-bug-bounty-pays-researchers-for-jailbreaks-and-policy/</link><guid isPermaLink="true">https://groundy.com/articles/openais-new-safety-bug-bounty-pays-researchers-for-jailbreaks-and-policy/</guid><description>OpenAI&apos;s safety bounties create a vendor-controlled disclosure market where NDAs silence participants, payouts trail serious red-team costs, and open publication has no lane.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-27T00:00:00.000Z</atom:updated><category>bug-bounty</category><category>jailbreak</category><category>prompt-injection</category><category>ai-safety</category><category>openai</category><category>red-teaming</category><category>responsible-disclosure</category><author>Groundy Editorial</author></item><item><title>Axios npm Compromise Forces Vercel Into Platform-Level Remediation</title><link>https://groundy.com/articles/axios-npm-compromise-forces-vercel-into-platform-level-remediation/</link><guid isPermaLink="true">https://groundy.com/articles/axios-npm-compromise-forces-vercel-into-platform-level-remediation/</guid><description>When compromised axios npm versions carried a North Korean RAT, Vercel blocked C2 egress at the deploy layer because the npm registry did not verify OIDC provenance.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-27T00:00:00.000Z</atom:updated><category>npm-supply-chain</category><category>axios</category><category>vercel</category><category>sapphire-sleet</category><category>oidc-provenance</category><category>package-security</category><author>Groundy Editorial</author></item><item><title>Next.js Dev Server CVE-2025-48068: Any Web Page Could Read Your Source Files</title><link>https://groundy.com/articles/next-js-dev-server-cve-2025-48068-any-web-page-could-read-your-source-files/</link><guid isPermaLink="true">https://groundy.com/articles/next-js-dev-server-cve-2025-48068-any-web-page-could-read-your-source-files/</guid><description>CVE-2025-48068 lets any webpage read source files from a running Next.js dev server via cross-origin script inclusion, exposing secrets loaded in .env files.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-27T00:00:00.000Z</atom:updated><category>nextjs</category><category>cve</category><category>cross-origin</category><category>dev-server</category><category>frontend-security</category><category>localhost</category><author>Groundy Editorial</author></item><item><title>MCP Tool Description Poisoning: New Benchmark Shows Agents Trust Manuals That Lie</title><link>https://groundy.com/articles/mcp-tool-description-poisoning-new-benchmark-shows-agents-trust-manuals-that-lie/</link><guid isPermaLink="true">https://groundy.com/articles/mcp-tool-description-poisoning-new-benchmark-shows-agents-trust-manuals-that-lie/</guid><description>A new MCP benchmark shows GPT-4o susceptible to nearly 100% of attacks where a tool&apos;s description lies about its purpose, a gap runtimes and scanners cannot detect.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-28T00:00:00.000Z</atom:updated><category>mcp</category><category>tool-description-poisoning</category><category>agent-security</category><category>llm-benchmark</category><category>prompt-injection</category><category>gpt-4o</category><author>Groundy Editorial</author></item><item><title>OpenAI Adds a GPT-5 System Card Addendum on Sensitive Conversations</title><link>https://groundy.com/articles/openai-adds-a-gpt-5-system-card-addendum-on-sensitive-conversations/</link><guid isPermaLink="true">https://groundy.com/articles/openai-adds-a-gpt-5-system-card-addendum-on-sensitive-conversations/</guid><description>OpenAI&apos;s GPT-5 addendum adds mental health evals and reports large safety gains between builds, but a buried extremism regression and scattered docs complicate compliance.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-28T00:00:00.000Z</atom:updated><category>gpt-5</category><category>system-cards</category><category>ai-safety</category><category>compliance</category><category>mental-health</category><category>openai</category><author>Groundy Editorial</author></item><item><title>Vercel Could Block React2Shell at the Edge. Its Next 13 CVEs Had No Shortcut.</title><link>https://groundy.com/articles/vercel-could-block-react2shell-at-the-edge-its-next-13-cves-had-no-shortcut/</link><guid isPermaLink="true">https://groundy.com/articles/vercel-could-block-react2shell-at-the-edge-its-next-13-cves-had-no-shortcut/</guid><description>Vercel shielded hosted React apps from React2Shell at the platform layer. Its May 2026 batch of 13 advisories, none fixable by WAF, proves that edge was the exception.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-28T00:00:00.000Z</atom:updated><category>react-server-components</category><category>react2shell</category><category>vercel</category><category>security-vulnerability</category><category>self-hosting</category><category>rce</category><category>cve</category><author>Groundy Editorial</author></item><item><title>Apple Names Claude in CVE Credit Line, Setting Vendor Attribution Precedent</title><link>https://groundy.com/articles/apple-names-claude-in-cve-credit-line-setting-vendor-attribution-precedent/</link><guid isPermaLink="true">https://groundy.com/articles/apple-names-claude-in-cve-credit-line-setting-vendor-attribution-precedent/</guid><description>Apple named Claude in a macOS Tahoe 26.5 CVE credit, the first major vendor to credit an LLM in a security advisory, forcing a decision on AI attribution across the industry.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-26T00:00:00.000Z</atom:updated><category>cve-attribution</category><category>ai-security-research</category><category>apple-security</category><category>bug-bounty</category><category>vulnerability-disclosure</category><category>claude</category><author>Groundy Editorial</author></item><item><title>CISA&apos;s Internal Data Leak Tests the Disclosure Standards It Sets for Others</title><link>https://groundy.com/articles/cisas-internal-data-leak-tests-the-disclosure-standards-it-sets-for-others/</link><guid isPermaLink="true">https://groundy.com/articles/cisas-internal-data-leak-tests-the-disclosure-standards-it-sets-for-others/</guid><description>CISA exposed cloud credentials on GitHub for months while preparing to mandate 72-hour breach reporting under CIRCIA, undermining its enforcement credibility.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-26T00:00:00.000Z</atom:updated><category>cisa</category><category>circia</category><category>breach-disclosure</category><category>credential-leak</category><category>cybersecurity-policy</category><category>incident-response</category><author>Groundy Editorial</author></item><item><title>TanStack npm Attack: When OIDC Trusted Publishing Becomes the Attack Vector</title><link>https://groundy.com/articles/tanstack-npm-attack-when-oidc-trusted-publishing-becomes-the-attack-vector/</link><guid isPermaLink="true">https://groundy.com/articles/tanstack-npm-attack-when-oidc-trusted-publishing-becomes-the-attack-vector/</guid><description>The TanStack npm attack published 84 malicious packages without a leaked token, exploiting OIDC trusted publishing so the CI workflow itself became the credential.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-26T00:00:00.000Z</atom:updated><category>supply-chain</category><category>oidc</category><category>npm</category><category>github-actions</category><category>trusted-publishing</category><category>security</category><author>Groundy Editorial</author></item><item><title>Nx s1ngularity Attackers Used Local Claude Code and Gemini CLI to Steal Developer Tokens</title><link>https://groundy.com/articles/nx-s1ngularity-attackers-used-local-claude-code-and-gemini-cli-to-steal/</link><guid isPermaLink="true">https://groundy.com/articles/nx-s1ngularity-attackers-used-local-claude-code-and-gemini-cli-to-steal/</guid><description>The s1ngularity attack used AI coding agents on developer machines to steal credentials from over 1,000 accounts, exposing a gap that npm scanning alone cannot close.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-26T00:00:00.000Z</atom:updated><category>supply-chain-security</category><category>ai-coding-agents</category><category>npm-security</category><category>credential-harvesting</category><category>developer-tools</category><category>s1ngularity-attack</category><author>Groundy Editorial</author></item><item><title>OpenAI Ships Lockdown Mode and Elevated Risk Labels for ChatGPT Sessions</title><link>https://groundy.com/articles/openai-ships-lockdown-mode-and-elevated-risk-labels-for-chatgpt-sessions/</link><guid isPermaLink="true">https://groundy.com/articles/openai-ships-lockdown-mode-and-elevated-risk-labels-for-chatgpt-sessions/</guid><description>OpenAI&apos;s Lockdown Mode kills ChatGPT network exfiltration paths at the infrastructure layer, conceding that model-level filtering cannot stop prompt injection.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-24T00:00:00.000Z</atom:updated><category>prompt-injection</category><category>chatgpt-security</category><category>lockdown-mode</category><category>ai-safety</category><category>data-exfiltration</category><category>enterprise-ai</category><author>Groundy Editorial</author></item><item><title>AI Jailbreaks Are Now a Reasoning Problem, Not a Prompt Problem</title><link>https://groundy.com/articles/metis-reframes-jailbreak-as-self-evolving-metacognitive-policy-optimization-not/</link><guid isPermaLink="true">https://groundy.com/articles/metis-reframes-jailbreak-as-self-evolving-metacognitive-policy-optimization-not/</guid><description>Metis rewrites its own jailbreak strategy mid-attack using causal diagnosis of refusals, hitting 76-78% ASR on O1 and GPT-5-chat. Static safety benchmarks now report a lower.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-24T00:00:00.000Z</atom:updated><category>llm-jailbreak</category><category>llm-security</category><category>red-teaming</category><category>safety-evaluation</category><category>adaptive-attack</category><category>policy-optimization</category><author>Groundy Editorial</author></item><item><title>Jailbreak Defense Now Lives in Model Weights, Not in Prompt Filters</title><link>https://groundy.com/articles/reflector-moves-jailbreak-defense-into-model-weights-via-step-wise-self/</link><guid isPermaLink="true">https://groundy.com/articles/reflector-moves-jailbreak-defense-into-model-weights-via-step-wise-self/</guid><description>REFLECTOR internalizes jailbreak defense in model weights via per-step reflection, hitting 90%+ DSR but tying protection to base-model size and penalizing smaller deployments.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-24T00:00:00.000Z</atom:updated><category>llm-security</category><category>jailbreak-defense</category><category>model-alignment</category><category>self-reflection</category><category>guardrail-architecture</category><category>icml-2026</category><author>Groundy Editorial</author></item><item><title>Vercel Blocks Deploys With Vulnerable next-mdx-remote by Default: Platform Mitigation Outpaces the CVE Cycle</title><link>https://groundy.com/articles/vercel-blocks-deploys-with-vulnerable-next-mdx-remote-by-default-platform/</link><guid isPermaLink="true">https://groundy.com/articles/vercel-blocks-deploys-with-vulnerable-next-mdx-remote-by-default-platform/</guid><description>Vercel blocks deploys with vulnerable next-mdx-remote at build time, cutting CVE mitigation from weeks to hours while claiming unilateral control over dependency versions.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-24T00:00:00.000Z</atom:updated><category>vercel</category><category>supply-chain-security</category><category>next-mdx-remote</category><category>cve-2026-0969</category><category>dependency-management</category><category>paas</category><author>Groundy Editorial</author></item><item><title>Vercel&apos;s Next.js Middleware Bypass Postmortem: What the Fix Reveals About Edge Runtime Auth</title><link>https://groundy.com/articles/vercels-next-js-middleware-bypass-postmortem-what-the-fix-reveals-about-edge/</link><guid isPermaLink="true">https://groundy.com/articles/vercels-next-js-middleware-bypass-postmortem-what-the-fix-reveals-about-edge/</guid><description>Two separate Next.js production failures, a header bypass CVE and an Edge Runtime mismatch, show middleware is not a reliable sole auth layer for self-hosted deployments.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-23T00:00:00.000Z</atom:updated><category>nextjs</category><category>middleware</category><category>edge-runtime</category><category>cve-2025-29927</category><category>authorization</category><category>self-hosting</category><category>web-security</category><author>Groundy Editorial</author></item><item><title>OpenAI&apos;s New Agent Defense Post Concedes Prompt Injection Is Architectural, Not Patchable</title><link>https://groundy.com/articles/openais-new-agent-defense-post-concedes-prompt-injection-is-architectural-not/</link><guid isPermaLink="true">https://groundy.com/articles/openais-new-agent-defense-post-concedes-prompt-injection-is-architectural-not/</guid><description>OpenAI&apos;s March 2026 guide concedes prompt injection is a permanent architectural constraint, forcing expensive containment for any agent that reads untrusted data.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-23T00:00:00.000Z</atom:updated><category>prompt-injection</category><category>ai-agents</category><category>ai-security</category><category>defense-in-depth</category><category>openai</category><category>llm-security</category><author>Groundy Editorial</author></item><item><title>When Stronger Backdoor Triggers Backfire: An arXiv Theory Paper Inverts a Core Defense Assumption</title><link>https://groundy.com/articles/when-stronger-backdoor-triggers-backfire-an-arxiv-theory-paper-inverts-a-core/</link><guid isPermaLink="true">https://groundy.com/articles/when-stronger-backdoor-triggers-backfire-an-arxiv-theory-paper-inverts-a-core/</guid><description>A May 2026 arXiv paper proves backdoor attack success peaks at intermediate trigger strength then declines. Detectors built for strong triggers miss the attacks near the peak.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-23T00:00:00.000Z</atom:updated><category>backdoor-attacks</category><category>adversarial-ml</category><category>model-security</category><category>backdoor-detection</category><category>trigger-strength</category><category>ml-safety</category><author>Groundy Editorial</author></item><item><title>DPrivBench: LLMs Score 99.5% on Textbook DP but Collapse on Advanced Reasoning</title><link>https://groundy.com/articles/dprivbench-llms-score-99-5-on-textbook-dp-but-collapse-on-advanced-reasoning/</link><guid isPermaLink="true">https://groundy.com/articles/dprivbench-llms-score-99-5-on-textbook-dp-but-collapse-on-advanced-reasoning/</guid><description>DPrivBench tests 11 LLMs on 713 differential-privacy instances. GPT-5-High hits 0.995 on textbook checks, but the best model reaches only F1 0.829 on advanced DP, and fails.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-19T00:00:00.000Z</atom:updated><category>differential-privacy</category><category>llm-benchmarks</category><category>ai-security</category><category>privacy-auditing</category><category>machine-learning</category><author>Groundy Editorial</author></item><item><title>Catching Graph Neural Net Backdoors by Influence, Not Pattern</title><link>https://groundy.com/articles/praetorian-cuts-gnn-backdoor-success-to-0-55-by-measuring-trigger-subgraph/</link><guid isPermaLink="true">https://groundy.com/articles/praetorian-cuts-gnn-backdoor-success-to-0-55-by-measuring-trigger-subgraph/</guid><description>PRAETORIAN cuts GNN backdoor attack success to 0.55% by measuring structural influence instead of trigger patterns, forcing adaptive attackers into a stealth-vs-effectiveness.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-18T00:00:00.000Z</atom:updated><category>graph-neural-networks</category><category>backdoor-defense</category><category>machine-learning-security</category><category>adversarial-ml</category><category>gnn</category><category>graph-learning</category><author>Groundy Editorial</author></item><item><title>TrustFall: One Keypress in Claude Code, Gemini CLI, Cursor, and Copilot CLI Triggers Unsandboxed RCE</title><link>https://groundy.com/articles/trustfall-one-keypress-in-claude-code-gemini-cli-cursor-and-copilot-cli/</link><guid isPermaLink="true">https://groundy.com/articles/trustfall-one-keypress-in-claude-code-gemini-cli-cursor-and-copilot-cli/</guid><description>A committed.claude/settings.json bypassed Claude Code&apos;s workspace trust dialog (CVE-2026-33068, CVSS 7.7), granting bypassPermissions silently. Fixed in v2.1.53.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-18T00:00:00.000Z</atom:updated><category>claude-code</category><category>workspace-trust</category><category>mcp-security</category><category>permission-bypass</category><category>ci-security</category><category>trustfall</category><category>cve-2026-33068</category><author>Groundy Editorial</author></item><item><title>Mini Shai-Hulud Ships the First Malicious npm With Valid SLSA Provenance</title><link>https://groundy.com/articles/mini-shai-hulud-ships-the-first-malicious-npm-with-valid-slsa-provenance/</link><guid isPermaLink="true">https://groundy.com/articles/mini-shai-hulud-ships-the-first-malicious-npm-with-valid-slsa-provenance/</guid><description>TeamPCP compromised TanStack&apos;s CI to publish 84 malicious npm packages with valid SLSA Build Level 3 provenance, proving that cryptographic attestation cannot protect a.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-18T00:00:00.000Z</atom:updated><category>supply-chain</category><category>npm</category><category>slsa-provenance</category><category>oidc</category><category>ci-cd</category><category>github-actions</category><category>tanstack</category><author>Groundy Editorial</author></item><item><title>MultiBreak Benchmark: 10,389 Multi-Turn Jailbreak Prompts Raise ASR 54pp on DeepSeek-R1-7B</title><link>https://groundy.com/articles/multibreak-benchmark-10-389-multi-turn-jailbreak-prompts-raise-asr-54pp/</link><guid isPermaLink="true">https://groundy.com/articles/multibreak-benchmark-10-389-multi-turn-jailbreak-prompts-raise-asr-54pp/</guid><description>MultiBreak&apos;s multi-turn benchmark lifts attack success 54 percentage points on DeepSeek-R1-7B, showing single-turn refusal rates understate real conversational risk.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-18T00:00:00.000Z</atom:updated><category>security</category><category>llm-safety</category><category>jailbreak</category><category>adversarial-ml</category><category>deepseek</category><category>ai-alignment</category><category>benchmark</category><author>Groundy Editorial</author></item><item><title>Next.js CVE-2026-44578: WebSocket Upgrade SSRF Hits 79,000 Self-Hosted Instances From 13.4.13 Onward</title><link>https://groundy.com/articles/next-js-cve-2026-44578-websocket-upgrade-ssrf-hits-79-000-self-hosted-instances/</link><guid isPermaLink="true">https://groundy.com/articles/next-js-cve-2026-44578-websocket-upgrade-ssrf-hits-79-000-self-hosted-instances/</guid><description>Next.js 15.5.16 and 16.2.5 patch an unauthenticated WebSocket upgrade SSRF. A single absolute-form URL request proxies internal traffic, exposing 79,000 self-hosted instances.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-18T00:00:00.000Z</atom:updated><category>next-js</category><category>ssrf</category><category>websocket</category><category>cve</category><category>self-hosted</category><category>vulnerability</category><category>patch-management</category><author>Groundy Editorial</author></item><item><title>PraisonAI CVE-2026-44338: Legacy Flask API Ships With AUTH_ENABLED=False, First Scan in 3h44m</title><link>https://groundy.com/articles/praisonai-cve-2026-44338-legacy-flask-api-ships-with-auth-enabled-false-first/</link><guid isPermaLink="true">https://groundy.com/articles/praisonai-cve-2026-44338-legacy-flask-api-ships-with-auth-enabled-false-first/</guid><description>PraisonAI hard-coded AUTH_ENABLED=False in its legacy Flask server across 2.5.6–4.6.33. CVE-Detector/1.0 probed the open /agents endpoint 3h44m after the May 11 advisory.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-18T00:00:00.000Z</atom:updated><category>praisonai</category><category>authentication-bypass</category><category>cve-2026-44338</category><category>ai-agent-security</category><category>rapid-exploitation</category><category>flask</category><category>vulnerability-disclosure</category><author>Groundy Editorial</author></item><item><title>Microsoft Semantic Kernel Patches Two RCE Paths: eval() in Vector Filter, DownloadFileAsync Escape to Host</title><link>https://groundy.com/articles/microsoft-semantic-kernel-patches-two-rce-paths-eval-in-vector-filter/</link><guid isPermaLink="true">https://groundy.com/articles/microsoft-semantic-kernel-patches-two-rce-paths-eval-in-vector-filter/</guid><description>Microsoft discloses two CVSS 9.9 Semantic Kernel RCE bugs from tool-design flaws. Trust boundary is each annotated tool method, and all agent frameworks need auditing.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-17T00:00:00.000Z</atom:updated><category>semantic-kernel</category><category>prompt-injection</category><category>rce</category><category>agent-security</category><category>trust-boundary</category><category>cve</category><author>Groundy Editorial</author></item><item><title>Windsurf CVE-2026-30615 Is the Only Zero-Click in the April MCP RCE Wave: HTML Rewrites the Config</title><link>https://groundy.com/articles/windsurf-cve-2026-30615-is-the-only-zero-click-in-the-april-mcp-rce-wave-html/</link><guid isPermaLink="true">https://groundy.com/articles/windsurf-cve-2026-30615-is-the-only-zero-click-in-the-april-mcp-rce-wave-html/</guid><description>CISA-ADP scored CVE-2026-30615 CVSS 8.0 HIGH, making Windsurf the sole zero-click IDE in the April MCP RCE wave: attacker HTML silently rewrites mcp.json with no user.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>mcp-security</category><category>cve-2026-30615</category><category>windsurf</category><category>remote-code-execution</category><category>ai-ide-security</category><category>prompt-injection</category><category>zero-click</category><author>Groundy Editorial</author></item><item><title>Paperclip CVE-2026-41208: Agents Can Mutate Their Own provisionCommand Into Server-Side Shell Injection</title><link>https://groundy.com/articles/paperclip-cve-2026-41208-agents-can-mutate-their-own-provisioncommand/</link><guid isPermaLink="true">https://groundy.com/articles/paperclip-cve-2026-41208-agents-can-mutate-their-own-provisioncommand/</guid><description>Any valid Paperclip Agent API key lets a holder overwrite provisionCommand so the server executes arbitrary shell commands during workspace provisioning without admin access.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>security</category><category>paperclip</category><category>cve-2026-41208</category><category>agent-orchestration</category><category>shell-injection</category><category>trust-boundary</category><category>api-security</category><author>Groundy Editorial</author></item><item><title>Spring AI 1.0.6 Patches Five CVEs Including CVSS 8.8 SQL Injection in CosmosDBVectorStore.doDelete</title><link>https://groundy.com/articles/spring-ai-1-0-6-patches-five-cves-including-cvss-8-8-sql-injection/</link><guid isPermaLink="true">https://groundy.com/articles/spring-ai-1-0-6-patches-five-cves-including-cvss-8-8-sql-injection/</guid><description>Spring AI 1.0.6 patches five CVEs including SQL injection and filter-expression escapes across 14+ vector stores, proving that RAG retrieval layers are not sanitized database.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>spring-ai</category><category>cve</category><category>sql-injection</category><category>rag-security</category><category>vector-store</category><category>filter-expression</category><category>patch-release</category><author>Groundy Editorial</author></item><item><title>LMDeploy CVE-2026-33626: Vision-LLM SSRF Exploited Within 12 Hours of GHSA (see also SSRF exploited) Publication</title><link>https://groundy.com/articles/lmdeploy-cve-2026-33626-vision-llm-ssrf-exploited-within-12-hours-of-ghsa/</link><guid isPermaLink="true">https://groundy.com/articles/lmdeploy-cve-2026-33626-vision-llm-ssrf-exploited-within-12-hours-of-ghsa/</guid><description>CVE-2026-33626 in LMDeploy&apos;s vision endpoint was exploited 12.5 hours after GHSA disclosure, with attackers targeting AWS IMDS and Redis via the image-fetch SSRF path.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>ssrf</category><category>lmdeploy</category><category>vision-llm</category><category>cloud-security</category><category>inference-security</category><category>cve-2026-33626</category><category>aws-imds</category><author>Groundy Editorial</author></item><item><title>Vercel&apos;s April 2026 Database Leak Pivoted From Lumma Stealer at Context AI via a Chrome Extension</title><link>https://groundy.com/articles/vercels-april-2026-database-leak-pivoted-from-lumma-stealer-at-context-ai-via/</link><guid isPermaLink="true">https://groundy.com/articles/vercels-april-2026-database-leak-pivoted-from-lumma-stealer-at-context-ai-via/</guid><description>Vercel&apos;s April 2026 breach began with Lumma Stealer at Context AI and pivoted through a Chrome extension OAuth token. Browser extensions are an unaudited supply-chain vector.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>vercel-breach</category><category>supply-chain-attack</category><category>chrome-extension</category><category>oauth-security</category><category>lumma-stealer</category><category>browser-security</category><author>Groundy Editorial</author></item><item><title>InstructLab CVE-2026-6859: Hardcoded trust_remote_code=True Turns Any HuggingFace Model Into RCE</title><link>https://groundy.com/articles/instructlab-cve-2026-6859-hardcoded-trust-remote-code-true-turns-any/</link><guid isPermaLink="true">https://groundy.com/articles/instructlab-cve-2026-6859-hardcoded-trust-remote-code-true-turns-any/</guid><description>InstructLab CVE-2026-6859 hardcodes trust_remote_code=True in transformers, enabling RCE from any HuggingFace repo. Existing supply-chain scanners cannot detect this vector.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>security</category><category>instructlab</category><category>cve-2026-6859</category><category>supply-chain</category><category>huggingface</category><category>trust-remote-code</category><category>rce</category><author>Groundy Editorial</author></item><item><title>PickleScan 1.0.4 Patches a CVSS 10.0 pkgutil.resolve_name Bypass and Six Missing Stdlib RCE Modules</title><link>https://groundy.com/articles/picklescan-1-0-4-patches-a-cvss-10-0-pkgutil-resolve-name-bypass-and-six/</link><guid isPermaLink="true">https://groundy.com/articles/picklescan-1-0-4-patches-a-cvss-10-0-pkgutil-resolve-name-bypass-and-six/</guid><description>PickleScan 1.0.4 patched three critical bypasses, but the fixes expose a deeper flaw: denylist scanning cannot keep pickle safe. The structural fix is safetensors migration.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>security</category><category>picklescan</category><category>safetensors</category><category>hugging-face</category><category>python</category><category>machine-learning</category><category>cve</category><author>Groundy Editorial</author></item><item><title>Mercor&apos;s 4TB Lapsus$ Breach Hands Voice-Clone Attackers 40,000 Pre-Verified Targets</title><link>https://groundy.com/articles/mercors-4tb-lapsus-breach-hands-voice-clone-attackers-40-000-pre-verified/</link><guid isPermaLink="true">https://groundy.com/articles/mercors-4tb-lapsus-breach-hands-voice-clone-attackers-40-000-pre-verified/</guid><description>Mercor&apos;s LiteLLM breach exposed interviews with IDs and 2-5 minute voice samples, collapsing the cost of voice-clone phishing by pairing clean audio with verified identities.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>security</category><category>voice-cloning</category><category>supply-chain</category><category>biometric-privacy</category><category>phishing</category><category>litellm</category><author>Groundy Editorial</author></item><item><title>Bitwarden CLI Compromise Extends the Checkmarx Supply-Chain Campaign to Credential Tooling</title><link>https://groundy.com/articles/bitwarden-cli-compromise-extends-the-checkmarx-supply-chain-campaign/</link><guid isPermaLink="true">https://groundy.com/articles/bitwarden-cli-compromise-extends-the-checkmarx-supply-chain-campaign/</guid><description>A trojanized @bitwarden/cli release spent 93 minutes on npm April 22. The Checkmarx-themed payload harvested credentials via preinstall hook, exposing vault session tokens.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-29T00:00:00.000Z</atom:updated><category>supply-chain</category><category>bitwarden</category><category>npm-malware</category><category>credential-theft</category><category>developer-security</category><category>ci-cd</category><category>checkmarx</category><author>Groundy Editorial</author></item><item><title>Flowise&apos;s CVE-2026-41264: LLM-Written `import` Becomes Unauthenticated RCE</title><link>https://groundy.com/articles/flowises-cve-2026-41264-turns-an-llm-written-import-statement-into/</link><guid isPermaLink="true">https://groundy.com/articles/flowises-cve-2026-41264-turns-an-llm-written-import-statement-into/</guid><description>CVE-2026-41264 (CVSS 9.8) shows how Flowise&apos;s CSV Agent regex allowlist fails when the LLM writes the code: aliasing os as pandas bypasses the filter for unauthenticated RCE.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-26T00:00:00.000Z</atom:updated><category>prompt-injection</category><category>agent-security</category><category>rce</category><category>flowise</category><category>llm-code-execution</category><category>sandbox-bypass</category><author>Groundy Editorial</author></item><item><title>Citizen Lab&apos;s &apos;Bad Connection&apos; Names Three Telecom Entry Points, Shows Diameter Silently Falls Back to SS7</title><link>https://groundy.com/articles/citizen-labs-bad-connection-report-names-three-telecom-entry-points-including/</link><guid isPermaLink="true">https://groundy.com/articles/citizen-labs-bad-connection-report-names-three-telecom-entry-points-including/</guid><description>Citizen Lab names 019Mobile and two carriers as surveillance transit points and shows roaming-forced SS7 fallback undermines Diameter protections even on upgraded networks.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-18T00:00:00.000Z</atom:updated><category>telecom-security</category><category>ss7-diameter</category><category>surveillance</category><category>roaming-security</category><category>gt-leasing</category><category>signaling-firewall</category><category>citizen-lab</category><author>Groundy Editorial</author></item><item><title>SGLang&apos;s CVE-2026-5760 Turns a GGUF Download Into RCE, Shifting the Trust Boundary to Hugging Face</title><link>https://groundy.com/articles/sglangs-cve-2026-5760-turns-a-gguf-download-into-rce-and-shifts-the-trust/</link><guid isPermaLink="true">https://groundy.com/articles/sglangs-cve-2026-5760-turns-a-gguf-download-into-rce-and-shifts-the-trust/</guid><description>CVE-2026-5760 lets poisoned GGUF files trigger Jinja2 SSTI through SGLang&apos;s unsandboxed template rendering, forcing teams to treat hub downloads as executable code.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-24T00:00:00.000Z</atom:updated><category>sglang</category><category>cve-2026-5760</category><category>jinja2-ssti</category><category>gguf-security</category><category>model-hub-trust</category><category>inference-security</category><category>remote-code-execution</category><author>Groundy Editorial</author></item><item><title>March-April MCP CVEs Expose the Local-Host Trust Model in AI Agent Frameworks</title><link>https://groundy.com/articles/marchapril-mcp-cves-expose-the-local-host-trust-model-in-ai-agent-frameworks/</link><guid isPermaLink="true">https://groundy.com/articles/marchapril-mcp-cves-expose-the-local-host-trust-model-in-ai-agent-frameworks/</guid><description>Three CVEs scoring up to 9.8 reveal a structural flaw: MCP&apos;s local-host trust model lacks authentication primitives for networked multi-tenant deployments.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-04-24T00:00:00.000Z</atom:updated><category>mcp-security</category><category>cve</category><category>authentication</category><category>ai-agents</category><category>protocol-design</category><category>vulnerability</category><category>supply-chain</category><author>Groundy Editorial</author></item><item><title>How Researchers Hacked McKinsey&apos;s AI Platform: What It Reveals</title><link>https://groundy.com/articles/mckinsey-ai-platform-hacked/</link><guid isPermaLink="true">https://groundy.com/articles/mckinsey-ai-platform-hacked/</guid><description>CodeWall&apos;s autonomous agent breached McKinsey&apos;s Lilli platform in two hours via SQL injection, exposing 46.5M messages and writable system prompts through a decades-old vulnerability.</description><pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-24T00:00:00.000Z</atom:updated><category>security</category><category>enterprise-ai</category><category>vulnerability</category><category>sql-injection</category><category>ai-security</category><author>Groundy Editorial</author></item><item><title>The Mysterious Case of Chinese Bot Traffic in 2026: How AI-Powered Bots Are Rewriting the Rules of Detection</title><link>https://groundy.com/articles/mysterious-chinese-bot-traffic-2026/</link><guid isPermaLink="true">https://groundy.com/articles/mysterious-chinese-bot-traffic-2026/</guid><description>Chinese bot traffic patterns have shifted dramatically in 2026, with AI-driven bots now accounting for 80% of AI bot activity and record-breaking 31.4 Tbps DDoS attacks. These new behaviors evade traditional detection through residential proxy networks, behavioral mimicry, and sophisticated infrastructure.</description><pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate><dc:creator>Groundy Editorial</dc:creator><atom:updated>2026-05-18T00:00:00.000Z</atom:updated><category>security</category><category>bots</category><category>traffic-analysis</category><category>china</category><author>Groundy Editorial</author></item></channel></rss>