Search
Find merged stories by title or summary.
[tl;dr sec] #340 - Anthropic and Meta Agents be Hackin', Agentic Incident Response Notebooks, Figma's AI Code Scanning
Hey there, I hope you’ve been doing well! 🫠 Vegas Like Icarus, I too have flouted common sense and the laws of nature by attending Hacker Summer Camp from Monday through Sunday. So far I have (mostly) survived the heat, and it’s been great catching up with friends. It’s somehow been busier than usual, will share more reflections next week. And potentially a story of one of the most memorable, funniest things I’ve observed in person for quite some time. It’s been strange not attending Hacker Summer Camp under Semgrep’s banner, for the first time in ~6 years. And kind of strange representing OpenAI, even though I’ve been working there for a few months now. I guess my identity/mental model is still updating, even though #LabLyfe is my day to day.
Critical Vulnerabilities Patched With Chrome 151 Update
The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek .
Flaws in Google APK for Python Unlock Agent-to-Agent Attack
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes
Patch faster isn’t the answer. Patch smarter is.
The 30-day patch cycle is dead. Most security teams already know this. What they haven’t fully reckoned with is why it died, and what has to replace it. SC Media recently gathered a range of security leaders on exactly this shift, and the picture they described is stark. AI didn’t just add more vulnerabilities to the pile. It collapsed the time between disclosure and exploitation from weeks to hours. Microsoft’s July release patched more than 600 bugs in a single Patch Tuesday, on the heels of a record 206 flaws the month before. In the same week, CISA pushed emergency patch orders for Oracle E-Business and Microsoft SharePoint, and researchers documented a full ransomware operation executed start to finish in under 24 hours. Recent Cloud Security Alliance research puts a number on the danger. Only 9% of organizations remediate critical vulnerabilities within 24 hours.
AWS Security Hub Adds Socket for Supply Chain Security
Amazon Web Services (AWS) customers can now adopt Socket directly through the AWS Security Hub Extended plan, apply committed AWS spend, and start with the first month free. Socket covers supply chain security in the program, with deep behavioral analysis that catches malicious packages signature-based tools miss. Supply chain security in the Extended plan # The AWS Security Hub Extended plan brings curated third-party security tools into AWS across 10 security categories, with pay-as-you-go pricing and no required upfront commitment. Socket adds supply chain security to that lineup, with a focus on catching malicious open source packages. Open source is where most modern applications get built, and it is also where attackers now go first.
Mini Shai-Hulud Hits keyv: Trojanized Release Exfiltrates CI Secrets via GitHub
On August 4, 2026, a malicious version of keyv was published to npm as keyv@6. 0. 0 , one of a number of npm packages affected across the Keyv and Cacheable ecosystem. The release follows the Mini Shai-Hulud pattern: a trojanized version of a heavily depended-on package, with an install-time hook that reaches cloud and CI credentials. It leaves the compiled library untouched and instead adds a preinstall hook and two files. The second of those files carries names and endpoints for AWS, HashiCorp Vault, Kubernetes, Google Cloud, Azure, npm, and GitHub Actions credentials, batched collection, and repository creation through GitHub’s own API. Technical analysis npm install └─ preinstall hook in package. json └─ setup. mjs └─ Math_Symbol. js, run under a downloaded Bun runtime Figure 1: The entry path, from a dependency install to the bundled file. What changed keyv@6. 0.
AI widely used to exploit critical flaws, disrupt supply chains
A report confirms the growing use of AI across a broad spectrum of threat groups.
Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated
OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier labs? Can victims sue them? We spoke to lawyers who specialize in computer hacking laws to find out.
Extend Amazon Inspector SBOM Generator with Plugins
Amazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities. The vulnerability management capabilities of Amazon Inspector are powered by an asset inventory engine known as the Amazon Inspector SBOM Generator (inspector-sbomgen), a standalone command-line tool that produces a software bill of materials (SBOM) from container images, directories, archives, local systems, compiled binaries, and more. Over the past two years, we’ve expanded inspector-sbomgen’s coverage across dozens of programming language ecosystems, operating systems, and widely deployed applications.
AWS KMS or AWS CloudHSM: Choose the right key management solution
Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM . Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is a fully managed service that integrates with all AWS services and all AWS Regions, making it the right choice for most key management workloads. AWS CloudHSM is a specialized option for use cases where you have strict requirements for dedicated HSM instances or must support legacy applications built around traditional HSM interfaces. Quick comparison The following table shows the pricing, AWS Region availability, algorithms, and AWS service integrations as of July 2026.
2026 Phase 1a IRAP report is now available on AWS Artifact for Australian customers
Amazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact . An independent Australian Signals Directorate (ASD) certified IRAP assessor completed the IRAP assessment of AWS in June 2026. The new IRAP report includes four additional AWS services that are now assessed at the PROTECTED level under IRAP. This brings the total number of services assessed at the PROTECTED level to 167. The four newly assessed services are: • Amazon Bedrock AgentCore • AWS Parallel Computing Service • AWS Resilience Hub • AWS Security Incident Response For the full list of services, see the IRAP tab on the AWS Services in Scope by Compliance Program page.
AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare
July 29, 2026 : We’ve updated this post to clarify the AWS Firewall Manager migration path. Application-layer distributed denial of service (DDoS) attacks are difficult to detect because they closely resemble legitimate traffic. HTTP request floods are now among the most common vectors targeting web applications, using valid-looking requests that blend in with normal user activity. In June 2025, AWS launched the AWS WAF Anti-DDoS managed rule group , built specifically for application-layer (L7) DDoS protection. AWS Shield Advanced is adopting it as the default application-layer protection, and in time as the only one. On July 27, AWS Shield Advanced begins adding the Anti-DDoS managed rule group to eligible web access control lists (ACLs) in Count mode. It will not cause any interruption to your traffic alongside your existing L7 automatic mitigation and WAF rules.
Announcing the Cloud Security Alliance on AWS Compliance Guide
AWS Security Assurance Services is announcing the release of the Cloud Security Alliance (CSA) Compliance Guide on Amazon Web Service (AWS) , a new resource that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4. 1 (CCM) to AWS services and recommended implementation practices. The guide is intended to help organizations using AWS plan, implement, and evidence the controls relevant to their CCM scope, including those pursuing or maintaining CSA STAR certification. What is the Cloud Controls Matrix? The Cloud Security Alliance is a not-for-profit organization dedicated to defining and raising awareness of best practices for cloud security. AWS maintains CSA STAR Level 2 certification , which couples the requirements of ISO/IEC 27001:2022 with the CCM.
Accelerating AWS Network Firewall troubleshooting with AWS DevOps Agent
When an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing to the firewall endpoint inside your Amazon Virtual Private Cloud (Amazon VPC) . A network drop looks the same from the workload no matter where it started. Isolating the cause means correlating the alert and flow logs with the firewall configuration, route tables, and recent API calls in AWS CloudTrail that might have changed them. That manual correlation is exactly where AWS DevOps Agent helps, accelerating root cause analysis so you can restore connectivity in minutes instead of hours. AWS DevOps Agent does that correlation for you.
Enterprise security at machine speed: AWS Black Hat 2026 preview
Black Hat 2026 (Aug 1-6, 2026) brings together over 22,000 security practitioners, researchers, and CISOs who build, break, and defend enterprise infrastructure. They’re security professionals who push the limits of offensive and defensive security and demand proof over promises. As frontier security models like Mythos reshape the enterprise landscape, they need security that operates at the same speed as the events they face. This August, Amazon Web Services (AWS) returns to Las Vegas to meet with our customers and partners to show how we’re delivering enterprise security at machine speed. At Black Hat USA 2026 , connect with AWS through live demos, a practitioner session on autonomous security operations, and an executive roundtable on building durable AI security architectures, plus networking receptions with customers and partners. Here’s where to find us and what you’ll take away.
Top 13 AI security testing solutions for dev pipelines in 2026
TL;DR: AI security testing solutions find vulnerabilities in code, dependencies, and AI components across the dev pipeline. What are AI security testing solutions? AI security testing solutions protect CI/CD pipelines from two critical angles: securing the AI-generated code your developers write using LLM assistants, and vulnerability testing the AI applications/models you deploy. Modern tools integrate directly into pipelines to scan source code, evaluate prompts, track pipeline dependencies, and auto-remediate issues before they hit production. Pipeline core testing categories: AI-assisted AppSec (for all codebases): Traditional SAST/DAST tools struggle with the velocity and style of AI-written code. AI-native tools catch risks standard rules engines miss: • Business logic flaws: Spotting logical bypasses created by loosely defined AI generation.
199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ran
Mend. io’s research team caught this campaign before most of the open source community ever saw it. Continuous monitoring of RubyGems flagged a batch of gems that looked, at a glance, like an ordinary cryptomining squat, and Mend. io reported the full batch to RubyGems for takedown. Every gem was pulled within hours. Mend. io’s team also pulled two of the samples apart in full, because knowing a campaign exists isn’t the same as knowing how it works. What that deeper look found: real tradecraft wrapped around code that, in both samples examined, doesn’t run at all. The short version: 199 gems, two accounts, one shared name pool. 181 names are machine-generated nonsense that nobody would ever type into a Gemfile . The other 19 are typosquats of a fully resolved dependency tree, including aws-sdk-core and all four of its direct dependencies.
Do more with AWS WAF labels using dynamic label interpolation
AWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label can record that a request came from a known bot category or that it matched a credential-stuffing pattern. You can forward that metadata to your origin as request headers, which gives your backend visibility into the decisions AWS WAF made at the edge. You can also use labels to build tiered policies: a low-confidence bot signal might trigger a CAPTCHA challenge, whereas a high-confidence signal blocks the request outright.
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.
Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond
Datadog Security Research investigates a June 2026 adversary-in-the-middle phishing campaign that cloned the AWS console login page to harvest victim credentials and multi-factor authentication codes.
[tl;dr sec] #332 - I've Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security
Hey there, I hope you’ve been doing well! 🤔 New Job, Who Dis? TL;DR : I’ve joined OpenAI to lead their Cyber efforts. I’m joined by Mike Aiello , an awesome security executive and human. Mike was previously CTO at Secureworks, led product for Google Cloud Security from 0 → $B’s in revenue, and CISO at Goldman Sachs. I was going to write a post describing all the details about joining, my thought process, etc. but it turns out there’s a lot to do at OpenAI and I’ve gotten very busy 😅 The post is started but not finished, will share when I can. So here’s the short version. Why
[tl;dr sec] #330 - AWS Pathfinding Labs, Running Codex Safely at OpenAI, Glasswing Updates
Hey there, I hope you’ve been doing well! ⛰️ Ain’t No Mountain High Enough To keep me from sending to you bae. Literally as I was starting to write this intro, my home Internet went out. After a moment I realized I had gotten a text a few days ago- scheduled maintenance with my Internet provider 😅 So now I’m finishing this issue via hot spotting with my phone. I’ve wondered sometimes what I’d do if there was some sort of force majeure world or personal event that put my ability to finish the newsletter in jeopardy. We cut to- *Movie trailer voice* In a world, where there’s too much security news…
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
Introducing Pathfinding Labs, a collection of intentionally vulnerable AWS environments for red teamers and blue teamers to deploy, exploit, and use for detection validation.
DFIR + AI Primer: Using AI in AWS Bedrock For Better Data Protection
For organizations concerned with where their investigation data goes, using LLMs inside their cloud environment (such as AWS or Azure) is a better-performing option than having local LLMs. When you use models in your cloud provider, then no data is seen by the GenAI vendors. We already talked about using Anthropic’s servers and local LLMs. In this post, we’ll cover how to configure your AWS account to run models and how to connect your MCP server, such as Autopsy or Cyber Triage, to them. This process should work with GovCloud , but we have not tested it. Using AI Models in AWS, Azure, or Google All cloud providers offer frameworks that can run various AI models, including Claude and ChatGPT. These frameworks have names like: • AWS Bedrock • Azure Foundry • Google Vertex ( Gemini Enterprise Agent Platform) When using these, none of your data ever goes to the GenAI vendor.
Cross-Agent Privilege Escalation: When Agents Free Each Other
During the Month of AI Bugs , I described an emerging vulnerability pattern that shows how commonly agentic systems have a design flaw that allows an agent to overwrite its own configuration and security settings. This allows the agent to break out of its sandbox and escape by executing arbitrary code. My research with GitHub Copilot , AWS Kiro and a few others demonstrated how this can be exploited by an adversary with an indirect prompt injection.
Ghosts in the Machine: The Fight for Privacy After Death
Ghosts in the Machine: The Fight for Privacy After Death Photo: Panyawat Auitpol / Unsplash In the early hours of 6 June 2020, Nicole Smallman and her sister Bibaa Henry had just finished celebrating Bibaa's birthday with friends in a park in London. Alone and in the dark, they were both fatally and repeatedly stabbed 36 times. Guest Contributor Please welcome Peter Marsden as a first-time guest contributor! Privacy Guides does not publish guest posts in exchange for compensation, and this tutorial was independently reviewed by our editorial team prior to publication. But the police didn’t just fail them in life—they failed them in death too. PC Deniz Jaffer and PC Jamie Lewis, both of the Metropolitan Police, took selfies with the dead bodies of the victims, posting them on a WhatsApp group. And no privacy laws prevented them from doing so.
AgentHopper: An AI Virus
As part of the Month of AI Bugs, serious vulnerabilities that allow remote code execution via indirect prompt injection were discovered. There was a period of a few weeks where multiple arbitrary code execution vulnerabilities existed in popular agents, like GitHub Copilot, Amazon Q, AWS Kiro,… During that time I was wondering if it would be possible to write an AI virus. Hence the idea of AgentHopper was born.
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
On the day AWS Kiro was released, I couldn’t resist putting it through some of my Month of AI Bugs security tests for coding agents. AWS Kiro was vulnerable to arbitrary command execution via indirect prompt injection. This means that a remote attacker, who controls data that Kiro processes, could hijack it to run arbitrary operating system commands or write and run custom code. In particular two attack paths that enabled this with AWS Kiro were identified:
Amazon Q Developer: Remote Code Execution with Prompt Injection
The Amazon Q Developer VS Code Extension (Amazon Q) is a popular coding agent, with over 1 million downloads . The extension is vulnerable to indirect prompt injection, and in this post we discuss a vulnerability that allowed an adversary (or also the AI for that matter) to run arbitrary commands on the host without the developer’s consent. The resulting impact of the vulnerability is the same as CVE-2025-53773 that Microsoft fixed in GitHub Copilot, however AWS did not issue a CVE when patching the vulnerabili
Issue 275: API hackers strike gold, Malicious API drift at CoinMarketCap, Survey reveals major API security gaps
This week, our theme is “ how secure is your API security?” . We highlight two recent attacks targeting major financial platforms, along with a new industry survey that exposes significant gaps in API security practices. We also explore technical deep-dives into vulnerabilities such as JWT flaws and host header injection attacks . Plus, we share details on an upcoming API security unconference happening this October in Stockholm. Breach: Popular Indian Gold Trading Platform Hacked A well-known digital platform for buying and selling gold in India has suffered a significant security breach, enabling attackers to gain unauthorized access to sell customers’ digital gold holdings. According to multiple Indian news outlets , this breach at Aditya Birla Capital Digital Limited (ABCD) was traced to vulnerabilities in the company’s APIs.
Issue 272: Volkswagen API hacked, API flaws in Instagram & Tiktok, ELi attacks, Radware & Cisco API vulnerabilities
This week, we’re sharing five API vulnerability incidents that provide valuable insights into how APIs are commonly hacked and how to prevent these same vulnerabilities in your APIs. These incidents include the exposure of vehicle owner data from Volkswagen’s mobile app, enumeration vulnerabilities in Instagram and Tiktok APIs, an in-depth look at expression language injection attacks, and cases of API vulnerabilities in Radware and Cisco platforms. Vulnerability: Volkswagen Authentication API Exposes OTP A security researcher successfully hacked Volkswagen’s mobile app by launching a brute-force attack on an API used to validate a one-time password (OTP).
Issue 270: AI double agents, securing API access, OpenAPI-driven MCP, APIs expose 33,000 employees
This week, the theme is AI, with articles on securing APIs against agentic misuse and preventing unintended behaviors. We cover two critical vulnerabilities in AI platforms Langflow and Dify, both caused by API security flaws, and highlight a major data leak due to unauthenticated internal APIs. Finally, we look at an engaging conversation around using OpenAPI to auto-generate MCP servers. Article: AI Agents prompted to attack APIs First up this week, an article by Facundo Fernandez on security vulnerabilities in autonomous AI agents highlights a growing concern for securing APIs from AI agents. The article provides examples of how an AI agent might be abused to launch common API authorization attacks, such as BOLA and BFLA from the OWASP Top 10 API security vulnerabilities list. Autonomous agents aren’t inherently malicious, but they don’t need to be.
Issue 269: API Security Guidelines, Mastering OpenAPI, Security Flaws in Shopware and Zabbix APIs
This week, the UK’s NCSC released detailed API security guidelines. Lorna Mitchell offers practical strategies for managing large OpenAPI files. Pieter Danhieux advocates for developer-focused security training in Australia. We also share best practices to secure your Postman collections and cover recent API vulnerability incidents at Zabbix and Shopware. Article: UKs NCSC promotes secure API development The UK’s National Cyber Security Centre (NCSC) has published a detailed set of guidelines for the secure development of HTTP-based APIs. The guidance covers key areas including API design and threat modeling, documentation and asset management, and also secure development and testing practices. A key recommendation is the use of standardized API specifications, notably OpenAPI, to fully document and describe APIs.
Issue 268: Cloudflare disables HTTP, Moodle and Flowise API flaws, DevSecOps & API secure design
This week, we focus on secure API design and best practices. We examine Cloudflare’s latest measures to prevent API token exposure, analyze three recent API vulnerabilities affecting an AI platform, a WordPress plugin, and a popular LMS solution, and highlight key articles on DevSecOps and API security best practices. Article: How HTTPS redirects can expose API data In a March blog post , Cloudflare announced it will block all API requests made over unsecured HTTP at the network level, ensuring that all client connections use encrypted HTTPS. Some API servers enforce HTTPS by redirecting HTTP requests to secure endpoints, this method still exposes sensitive data such as API keys or access tokens to potential man-in-the-middle attacks during the initial unencrypted request.
Issue 264: Pwn2Own Automotive 2025, Subaru APIs hacked, DevSecOps for the connected vehicle
This week, we focus on automotive cybersecurity. Guest contributor Ling Cheng of VicOne shares the security benefits of the Pwn2Own Automotive event. We explore Sam Curry’s success uncovering API flaws at Subaru; car hacking as a career choice; and CISA director Jen Easterly’s case for secure design, inspired by automotive safety. In February, I’ll chat with automotive cybersecurity expert Darren Shelcusky for his insights about API security and DevSecOps for the connected vehicle ecosystem. Industry News: Pwn2Own contest enhances automotive security By guest contributor Ling Cheng , Sr. Product Marketing Manager at VicOne Inc. As software-defined vehicles (SDVs) become more prevalent, concerns over vulnerabilities and the risks of cyberattacks are increasing.
Issue 261: API Security in 2025, OWASP insecure design, path traversal flaws for Mitel and Sailpoint
This week, we explore the opportunities and challenges in API security as we look ahead to the new year. We also include several newly discovered vulnerabilities and exploits of the embarrassingly common path traversal attack, and a look at OWASP insecure design. Before we dive into this week’s newsletter, the entire team at APISecurity. io extends our warmest wishes for a successful and fulfilling new year in 2025, both personally and professionally. To those of you taking some well-deserved time off this holiday season, we hope you enjoy a peaceful and restful break, free from API security incidents! Happy New Year! Article: Why API Security is a top priority for 2025 A recent article on TechTarget explores potential trends shaping the API ecosystem in 2025. Will we see a transformative shift in API development powered by AI-driven services and integrations?
Issue 241: Two critical flaws in FortiSIEM product, making public APIs private, API security strategy
This week, we have news of two critical vulnerabilities in the Fortinet FortiSIEM product. We also have articles on making public APIs private and building an API security strategy. Dana Epp offers his thoughts on the difference between endpoints and routes, and we have two developer-focused tutorials, one on securing gRPC and the other on Django API security best practices. Vulnerability: Two critical flaws in Fortinet FortiSIEM product This week’s main news is the further coverage of the two critical issues reported in the Fortinet FortiSIEM product courtesy of The Register. The two vulnerabilities (tracked as CVE-2024-23108 and CVE-2024-23109 ) were rated as critical with a CVSS score of 10, indicating that the exploits can be carried out remotely by unauthenticated attackers and are low in complexity.
Fancy Bear group exploits Outlook and WinRAR flaws in mass credential collection...
Threat actor leveraging patched vulnerabilities to send high-volume campaigns to targets in Europe and North America
Issue 233: Flaws in OAuth social sign-in, securing API gateways, scalable SaaS security
This week, we have important news of a vulnerability in the OAuth social sign-in feature of many popular platforms, potentially impacting billions of users. We have two articles from The NewStack, the first a guide on securing your API gateway and the second how to design scalable SaaS API security. We also have news of a significant partnership between Microsoft and 42Crunch designed to deliver end-to-end API security for enterprises. We finish with two guides, the first on preventing API breaches and the second from Dana Epp on using Burp Collaborator to prove API exploitability. Vulnerability: Flaws in OAuth social sign-in put billions at risk The most important item this week (and in the last few months) is the vulnerability discovered by Salt Labs in implementing the OAuth protocol in several popular websites.
