<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — New Resources</title>
  <link>https://appsec.fyi</link>
  <description>Curated application security resources — XSS, SQLi, SSRF, IDOR, RCE, and more.</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feed.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Sun, 12 Jul 2026 16:04:24 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <webMaster>carl@chs.us (Carl Sampson)</webMaster>
  <item>
    <title>Software Supply Chain Attack Highlights Growing Demand for Preemptive Package Security</title>
    <link>https://www.tipranks.com/news/private-companies/software-supply-chain-attack-highlights-growing-demand-for-preemptive-package-security</link>
    <guid isPermaLink="true">https://www.tipranks.com/news/private-companies/software-supply-chain-attack-highlights-growing-demand-for-preemptive-package-security</guid>
    <description>A recent software supply chain attack has underscored the increasing need for preemptive security in package management. These attacks target the dependencies that software relies on, introducing malicious code into legitimate applications. This incident highlights the vulnerabilities inherent in interconnected development environments and emphasizes the growing demand for robust solutions that can identify and mitigate risks *before* they impact end-users. Organizations are realizing the critical importance of securing their software supply chains to prevent widespread compromise.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Sun, 12 Jul 2026 12:35:39 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>Critical CVE-2026-2699 and CVE-2026-2701 Vulnerabilities Force Immediate Shutdown of Progress ShareFile Storage Zone Controller v5.x</title>
    <link>https://www.rescana.com/post/critical-cve-2026-2699-and-cve-2026-2701-vulnerabilities-force-immediate-shutdown-of-progress-sharefile-storage-zone-con</link>
    <guid isPermaLink="true">https://www.rescana.com/post/critical-cve-2026-2699-and-cve-2026-2701-vulnerabilities-force-immediate-shutdown-of-progress-sharefile-storage-zone-con</guid>
    <description>Progress ShareFile Storage Zone Controller v5.x has been forced into an immediate shutdown due to critical vulnerabilities, CVE-2026-2699 and CVE-2026-2701. These security flaws necessitate this urgent action to protect affected systems. Further details are available via the provided link.</description>
    <category>RCE</category>
    <category domain="difficulty">news</category>
    <pubDate>Sun, 12 Jul 2026 11:34:28 +0000</pubDate>
    <source url="https://appsec.fyi/rce.html">RCE — appsec.fyi</source>
  </item>
  <item>
    <title>Ghostcommit: Multimodal Prompt Injection Attack Exposes AI Code Review Tools to Supply Chain Risks</title>
    <link>https://www.rescana.com/post/ghostcommit-multimodal-prompt-injection-attack-exposes-ai-code-review-tools-to-supply-chain-risks</link>
    <guid isPermaLink="true">https://www.rescana.com/post/ghostcommit-multimodal-prompt-injection-attack-exposes-ai-code-review-tools-to-supply-chain-risks</guid>
    <description>A new multimodal prompt injection attack, dubbed &quot;Ghostcommit,&quot; targets AI code review tools, posing significant supply chain risks. This attack leverages the AI&#x27;s ability to process both text and image inputs. By embedding malicious prompts within images, attackers can trick AI code reviewers into accepting vulnerable code or even executing arbitrary commands. This bypasses traditional security checks and injects compromised code into development pipelines, potentially leading to widespread system compromise. The research highlights a critical vulnerability in how AI models handle mixed-media inputs, demanding urgent attention from developers of AI-powered security solutions.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">advanced</category>
    <pubDate>Sun, 12 Jul 2026 11:30:37 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>Compromised jscrambler 8.14.0 npm Release Runs Hidden Platform-Specific Binary During Install</title>
    <link>https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html</guid>
    <description>The jscrambler npm package version 8.14.0 was found to be compromised. During installation, it secretly executed a platform-specific binary. This binary&#x27;s purpose and potential impact are currently unclear. Users who have installed this version are advised to uninstall it immediately and review their systems for any suspicious activity. Further investigation is ongoing to determine the full extent of the compromise and its implications.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Sun, 12 Jul 2026 10:25:29 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)</title>
    <link>https://discounttimu.substack.com/p/scanning-malicious-websites-with-cfe</link>
    <guid isPermaLink="true">https://discounttimu.substack.com/p/scanning-malicious-websites-with-cfe</guid>
    <description>This document, Part 2 of &quot;Scanning malicious websites with arbitrary number of VPN tunnels,&quot; likely details advanced techniques for identifying malicious websites by leveraging multiple VPN tunnels. It probably explores methods to bypass security measures and gather intelligence on threats, potentially by obfuscating the origin of scanning activity. The focus is on a technical approach to enhance the detection and analysis of harmful online content through sophisticated network routing.</description>
    <category>Recon</category>
    <category domain="difficulty">advanced</category>
    <pubDate>Sun, 12 Jul 2026 06:15:20 +0000</pubDate>
    <source url="https://appsec.fyi/recon.html">Recon — appsec.fyi</source>
  </item>
  <item>
    <title>Global CMS Attack Wave: Attackers Distribute Web Shells via Known WordPress Joomla and Craft Vulnerabilities</title>
    <link>https://www.igorslab.de/en/global-cms-attack-wave-webshells-known-vulnerabilities/</link>
    <guid isPermaLink="true">https://www.igorslab.de/en/global-cms-attack-wave-webshells-known-vulnerabilities/</guid>
    <description>Attackers are exploiting known vulnerabilities in WordPress, Joomla, and Craft CMS to distribute web shells globally. This widespread attack wave targets these popular content management systems, indicating a coordinated effort to gain unauthorized access to websites. The specific vulnerabilities being leveraged allow attackers to upload and execute malicious code, potentially leading to data breaches, website defacement, and further compromise of server resources. Users of these CMS platforms are strongly advised to update their software immediately and ensure all plugins and themes are also current to mitigate the risk of infection.</description>
    <category>RCE</category>
    <category domain="difficulty">news</category>
    <pubDate>Sun, 12 Jul 2026 04:04:04 +0000</pubDate>
    <source url="https://appsec.fyi/rce.html">RCE — appsec.fyi</source>
  </item>
  <item>
    <title>Ghost Accounts Abuse GitHub API in Mass Recon Campaign</title>
    <link>https://www.securityweek.com/ghost-accounts-abuse-github-api-in-mass-recon-campaign/</link>
    <guid isPermaLink="true">https://www.securityweek.com/ghost-accounts-abuse-github-api-in-mass-recon-campaign/</guid>
    <description>Analysis of ghost account abuse of the GitHub API reveals mass reconnaissance campaigns leveraging dormant accounts and leaked credentials. Threat actors exploit unauthenticated API endpoints, including REST and GraphQL, to enumerate organizations, repositories, and users. While primarily focused on reconnaissance, some campaigns escalated to cloning repositories and exfiltrating data, sometimes using inadvertently exposed tokens. Detection strategies involve monitoring for data exfiltration from private repositories, anomalous user agent behavior, and establishing baselines for normal GitHub activity.</description>
    <category>GraphQL</category>
    <category domain="difficulty">news</category>
    <pubDate>Sun, 12 Jul 2026 01:19:28 +0000</pubDate>
    <source url="https://appsec.fyi/graphql.html">GraphQL — appsec.fyi</source>
  </item>
  <item>
    <title>HalluSquatting Turns AI Hallucinations Into Botnet Delivery Mechanism</title>
    <link>https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/</link>
    <guid isPermaLink="true">https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/</guid>
    <description>Technique detailing HalluSquatting, an attack that leverages AI hallucinations to deliver botnets at scale. This untargeted promptware method exploits AI applications by pre-registering fake repository or package names that LLMs commonly invent. When users ask AI tools like Cursor, GitHub Copilot, or Gemini CLI to fetch resources, the AI may hallucinate a squatted name, download malicious instructions, and execute them via the built-in terminal, leading to the deployment of malware and the creation of agentic botnets.</description>
    <category>AI Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 18:45:28 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>Researchers hid a prompt injection inside a PNG and AI fell for it</title>
    <link>https://www.digitaltrends.com/cool-tech/researchers-hid-a-prompt-injection-inside-a-png-and-ai-fell-for-it/</link>
    <guid isPermaLink="true">https://www.digitaltrends.com/cool-tech/researchers-hid-a-prompt-injection-inside-a-png-and-ai-fell-for-it/</guid>
    <description>Technique for prompt injection via image files that targets AI coding assistants like Claude. Researchers demonstrated hiding malicious instructions within a PNG image, which AI review tools often overlook. These hidden commands can later trigger AI assistants to access sensitive project files and exfiltrate data, disguised as legitimate code. The vulnerability&#x27;s manifestation varies depending on the specific coding assistant used, emphasizing the need for multimodal AI review that scrutinizes all asset types.</description>
    <category>AI Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 18:10:19 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>&#x27;Ghostcommit&#x27; hides prompt injection in images to fool AI agents steal secrets</title>
    <link>https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/</guid>
    <description>Writeup on Ghostcommit, an attack technique that hides prompt injection within PNG images to bypass AI code reviewers and steal repository secrets. Researchers demonstrated how a malicious instruction embedded in an image file referenced by an AGENTS.md document could trick AI agents like Cursor with Claude Sonnet into exfiltrating sensitive data from .env files. This exploit leverages the current blind spot where AI code reviewers often skip image analysis, unlike proposed multimodal defenders.</description>
    <category>AI Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 18:10:18 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>Shadow AI is Your New Attack Surface</title>
    <link>https://www.infosecurity-magazine.com/opinions/shadow-ai-is-your-new-attack/</link>
    <guid isPermaLink="true">https://www.infosecurity-magazine.com/opinions/shadow-ai-is-your-new-attack/</guid>
    <description>Analysis of &quot;Shadow AI&quot; highlights how unmanaged AI systems, adopted by employees for efficiency, create significant security risks. These &quot;Shadow AI&quot; deployments bypass traditional security controls and introduce new attack vectors such as data poisoning, prompt injection, third-party AI supply chain risk, and credential exposure, exemplified by the Samsung incident in March 2024. Addressing this emergent threat requires integrating AI governance and cybersecurity functions, focusing on visibility, accountability, AI-specific controls, and expertise investment.</description>
    <category>AI Security</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Sat, 11 Jul 2026 18:10:17 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>How to Use AI Browsers Without Getting Hacked</title>
    <link>https://lifehacker.com/tech/how-to-use-ai-browsers-without-getting-hacked</link>
    <guid isPermaLink="true">https://lifehacker.com/tech/how-to-use-ai-browsers-without-getting-hacked</guid>
    <description>Guide to using AI browsers like Perplexity Comet, ChatGPT Atlas, and Dia securely, highlighting risks such as prompt injection, unauthorized account access, and data leakage. It details vulnerabilities including CometJacking and Cross-Site Request Forgery (CSRF) affecting Atlas, and advises disabling data sharing for model training, restricting agent access to logged-in sessions, and utilizing incognito mode for sensitive tasks to mitigate these threats.</description>
    <category>AI Security</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Sat, 11 Jul 2026 18:10:16 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>New hack exploits AI hallucinations to trick agents into running malicious code &#x27;HalluSquatting&#x27; attack exploits a fundamental weakness in every available model</title>
    <link>https://www.tomshardware.com/tech-industry/cyber-security/hallusquatting-is-the-latest-agentic-ai-exploit-where-models-dream-up-potentially-malicious-urls-in-tool-calls-attack-exploits-a-fundamental-weakness-in-every-available-model</link>
    <guid isPermaLink="true">https://www.tomshardware.com/tech-industry/cyber-security/hallusquatting-is-the-latest-agentic-ai-exploit-where-models-dream-up-potentially-malicious-urls-in-tool-calls-attack-exploits-a-fundamental-weakness-in-every-available-model</guid>
    <description>Writeup of the HalluSquatting attack, an exploit leveraging AI hallucinations to trick agentic AI models like Claude into executing malicious code from fake GitHub repositories. This technique exploits the non-deterministic nature of LLMs, causing them to generate plausible but nonexistent repository names, which attackers then register. Successful exploitation can lead to reverse shells, data exfiltration, and further system compromise, affecting models such as Claude Opus 4.5 and applications like Cursor and Copilot.</description>
    <category>AI Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 18:10:15 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>Designing for the inevitable: System prompt leakage and mitigations in generative AI applications</title>
    <link>https://aws.amazon.com/blogs/security/designing-for-the-inevitable-system-prompt-leakage-and-mitigations-in-generative-ai-applications/</link>
    <guid isPermaLink="true">https://aws.amazon.com/blogs/security/designing-for-the-inevitable-system-prompt-leakage-and-mitigations-in-generative-ai-applications/</guid>
    <description>Library for defending against system prompt leakage in generative AI applications. This resource addresses LLM07, a top vulnerability where attackers use prompt injection to extract an application&#x27;s system prompt, potentially revealing proprietary information and tool definitions. It emphasizes that full remediation is not currently possible, advocating for design principles that assume leaks will occur and implementing mitigation controls like Amazon Bedrock Guardrails&#x27; prompt attack filters to reduce exposure and increase extraction difficulty.</description>
    <category>AI Security</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Sat, 11 Jul 2026 18:10:14 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>AI agents fall for indirect prompt injection traps</title>
    <link>https://www.infoworld.com/article/4193403/ai-agents-fall-for-indirect-prompt-injection-traps-2.html</link>
    <guid isPermaLink="true">https://www.infoworld.com/article/4193403/ai-agents-fall-for-indirect-prompt-injection-traps-2.html</guid>
    <description>Analysis of indirect prompt injection (IPI) traps reveals vulnerabilities in AI agents, with specific models like Llama3-3-70b-instruct, Llama3-2-90b-instruct, Gemini-3-flash, and Gemini-2.5-pro exhibiting susceptibility. This research highlights how hidden instructions embedded in websites can manipulate AI behavior, leading to scams that human users would typically avoid. The attack surface is expanding as AI agents interact more with the web, necessitating architectural rather than purely behavioral defenses, as traditional enterprise security models struggle to address these novel threats.</description>
    <category>AI Security</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Sat, 11 Jul 2026 18:10:13 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>When AI Agents Attack: Autonomous Cyber Operations and Europes Governance Gap</title>
    <link>https://carnegieendowment.org/europe/research/2026/07/when-ai-agents-attack-autonomous-cyber-operations-and-europes-governance-gap</link>
    <guid isPermaLink="true">https://carnegieendowment.org/europe/research/2026/07/when-ai-agents-attack-autonomous-cyber-operations-and-europes-governance-gap</guid>
    <description>Analysis of autonomous AI agent operations reveals evolving cybersecurity threats and governance gaps. The emergence of platforms like Moltbook, where millions of AI agents interact, highlights risks from data leaks (API authentication tokens) and the difficulty of tracing accountability. Major AI models like Anthropic&#x27;s Claude, capable of identifying and exploiting zero-day vulnerabilities across operating systems and browsers, demonstrate the blurring line between AI-assisted operations and autonomous cyber capabilities. The EU faces challenges adapting its governance frameworks to address these rapidly evolving, agentic AI risks, particularly given its dependence on U.S. AI infrastructure.</description>
    <category>AI Security</category>
    <category domain="difficulty">advanced</category>
    <pubDate>Sat, 11 Jul 2026 18:10:13 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>ZOWEH: XXE LAB SOLVED: Exploiting XXE to perform SSRF attacks Goal: Use XXE to access AWS metadata endpoint Method: External entity pointing to #XXE #SSRF</title>
    <link>https://x.com/ZOWEHZEE/status/2075936951429923278</link>
    <guid isPermaLink="true">https://x.com/ZOWEHZEE/status/2075936951429923278</guid>
    <description>This content details the successful exploitation of an XML External Entity (XXE) vulnerability to perform a Server-Side Request Forgery (SSRF) attack. The objective was to access the AWS metadata endpoint. The method involved utilizing an external entity to achieve this. The provided link points to further information on this XXE and SSRF exploit. No bug bounty payout amount is mentioned.</description>
    <category>SSRF</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Sat, 11 Jul 2026 13:48:22 +0000</pubDate>
    <source url="https://appsec.fyi/ssrf.html">SSRF — appsec.fyi</source>
  </item>
  <item>
    <title>Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions</title>
    <link>https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html</guid>
    <description>Library update addressing stored XSS in Zimbra Classic Web Client. Exploitation of this vulnerability allows attackers to inject and execute malicious JavaScript within user sessions via crafted emails, potentially leading to mailbox access, session data compromise, and account setting manipulation. This flaw, though unassigned a CVE, follows a history of XSS vulnerabilities in Zimbra, including CVE-2025-27915, CVE-2023-37580, and CVE-2024-27443. Users are advised to update to Zimbra Collaboration Suite version 10.1.19.</description>
    <category>XSS</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 12:56:34 +0000</pubDate>
    <source url="https://appsec.fyi/xss.html">XSS — appsec.fyi</source>
  </item>
  <item>
    <title>Zimbra 10.1.19 Fixes Stored XSS Flaw Triggered by Crafted Emails</title>
    <link>https://cyberpress.org/zimbra-10-1-19-fixes-stored-xss-flaw/</link>
    <guid isPermaLink="true">https://cyberpress.org/zimbra-10-1-19-fixes-stored-xss-flaw/</guid>
    <description>Zimbra 10.1.19 addresses a stored cross-site scripting (XSS) vulnerability that could be exploited by sending specially crafted emails. This flaw allowed attackers to inject malicious scripts into the Zimbra web client, potentially leading to unauthorized actions or data theft by users who viewed the compromised email. The update rectifies this security weakness, enhancing the platform&#x27;s safety.</description>
    <category>XSS</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 07:41:19 +0000</pubDate>
    <source url="https://appsec.fyi/xss.html">XSS — appsec.fyi</source>
  </item>
  <item>
    <title>Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)</title>
    <link>https://arxiv.org/pdf/2606.07158</link>
    <guid isPermaLink="true">https://arxiv.org/pdf/2606.07158</guid>
    <description>This research explores whether AI-generated adversaries can evade TTP-based attribution methods. The study, &quot;Can AI-generated adversaries break TTP-based attribution? (arXiv 2026),&quot; investigates the effectiveness of current attribution techniques against sophisticated, AI-driven attackers. It analyzes how advanced AI might mimic or alter Tactics, Techniques, and Procedures (TTPs) to mislead security systems and prevent the identification of the true attacker. The paper aims to understand the potential vulnerabilities in attribution models when faced with AI-powered threats and suggests future directions for developing more robust attribution systems.</description>
    <category>AI Security</category>
    <category domain="difficulty">advanced</category>
    <pubDate>Sat, 11 Jul 2026 06:15:40 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>Anonymous GitHub account mass-dropping undisclosed 0-days</title>
    <link>https://github.com/bikini/exploitarium</link>
    <guid isPermaLink="true">https://github.com/bikini/exploitarium</guid>
    <description>Archive of public proof-of-concept and vulnerability research writeups, including specific findings for c-ares-tcp-uaf-calc-poc, curl-smtp-expn-recipient-crlf-injection, discourse-scoped-api-key-preauth-bypass, and rustdesk-session-permission-pocs. The repository preserves original READMEs and tracked files from former standalone repositories, ensuring byte-for-byte identical content as verified by Git tree data. This collection aims to foster interest in cybersecurity vulnerability research and encourage ethical disclosure.</description>
    <category>Bug Bounty</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 06:15:34 +0000</pubDate>
    <source url="https://appsec.fyi/bugbounty.html">Bug Bounty — appsec.fyi</source>
  </item>
  <item>
    <title>Show HN: Osint tool that finds exposed files on domains</title>
    <link>https://search.cerast-intelligence.com/</link>
    <guid isPermaLink="true">https://search.cerast-intelligence.com/</guid>
    <description>This &quot;Show HN&quot; post introduces an OSINT tool designed to discover exposed files on various domains. The tool aids in identifying potentially sensitive information that might be unintentionally accessible via websites. No bug bounty payout amount is mentioned in the provided content.</description>
    <category>OSINT</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Sat, 11 Jul 2026 06:15:34 +0000</pubDate>
    <source url="https://appsec.fyi/osint.html">OSINT — appsec.fyi</source>
  </item>
  <item>
    <title>Show HN: Bramble – Local-first password manager</title>
    <link>https://github.com/flythenimbus/bramble</link>
    <guid isPermaLink="true">https://github.com/flythenimbus/bramble</guid>
    <description>Library for local-first password management, Bramble offers Chromium browser extensions, and iOS/Android apps that sync vaults peer-to-peer. It uses a Rust crypto core for Argon2id key derivation and AES-256-GCM encryption, with secrets wiped from memory post-use. Bramble supports passkeys, smart autofill, TOTP codes, and encrypted backups to local files or future cloud storage providers. It contrasts with cloud-based managers by ensuring vaults remain on user devices, eliminating a central breach target. Unlock options include master password, hardware keys, biometrics, or a recovery code.</description>
    <category>Secrets &amp; Credential Leaks</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Sat, 11 Jul 2026 06:15:33 +0000</pubDate>
    <source url="https://appsec.fyi/secrets.html">Secrets &amp; Credential Leaks — appsec.fyi</source>
  </item>
  <item>
    <title>A way to exclude sensitive files issue still open for OpenAI Codex</title>
    <link>https://github.com/openai/codex/issues/2847</link>
    <guid isPermaLink="true">https://github.com/openai/codex/issues/2847</guid>
    <description>Library of proposed features for OpenAI Codex, addressing the exclusion of sensitive files and paths from model analysis. This includes a mechanism for both repository-local and global ignore files, akin to `.codexignore`, to prevent the exposure of sensitive data such as `.env` files, `.pem` certificates, and `.ssh` directories, while still allowing analysis of others like `node_modules/`. The goal is deterministic and shareable configurations for team-wide consistency, building on prior discussions and aiming to rectify a gap in the current `codex-rs` implementation.</description>
    <category>AI Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 06:15:33 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>How to keep an HTTP connection alive for 9 hours</title>
    <link>https://snyk.io/blog/how-to-keep-http-connection-alive-9-hours</link>
    <guid isPermaLink="true">https://snyk.io/blog/how-to-keep-http-connection-alive-9-hours</guid>
    <description>Tool for managing CTF user accounts and notifications, built with Spring Boot, Spring Security, and WebFlux. It integrates with the CTFd API to create users, assign unique aliases, and manage email notifications, including handling API rate limits with robust retry mechanisms and supporting long-running bulk email processes using Server-Sent Events (SSE) for status updates.</description>
    <category>API Security</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Sat, 11 Jul 2026 06:00:35 +0000</pubDate>
    <source url="https://appsec.fyi/apisec.html">API Security — appsec.fyi</source>
  </item>
  <item>
    <title>PUMA live hacking event revisited: leHACK’s biggest Bug Bounty yet</title>
    <link>https://yeswehack.com/en/blog/puma-live-hacking-event</link>
    <guid isPermaLink="true">https://yeswehack.com/en/blog/puma-live-hacking-event</guid>
    <description>leHACK&#x27;s biggest Bug Bounty event, focused on PUMA, saw participants uncover numerous vulnerabilities. The event, which brought together ethical hackers and security researchers, aimed to identify and fix security flaws within PUMA&#x27;s digital systems. The detailed analysis of the event highlights the significant findings and contributions made by the hacking community to enhance PUMA&#x27;s cybersecurity posture.</description>
    <category>Bug Bounty</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 06:00:29 +0000</pubDate>
    <source url="https://appsec.fyi/bugbounty.html">Bug Bounty — appsec.fyi</source>
  </item>
  <item>
    <title>New Trojan Turns Visual Studio Projects Into a Software Supply Chain Attack Vector</title>
    <link>https://cyberpress.org/trojan-visual-studio-supply-chain-attack/</link>
    <guid isPermaLink="true">https://cyberpress.org/trojan-visual-studio-supply-chain-attack/</guid>
    <description>A new Trojan has been discovered that exploits Visual Studio projects, turning them into a potent software supply chain attack vector. This malicious code can infiltrate development environments, allowing attackers to compromise legitimate software builds. The ultimate impact is the potential for widespread distribution of malware through trusted software updates.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Sat, 11 Jul 2026 05:55:45 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>Zero Day Initiative CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys</title>
    <link>https://www.thezdi.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys</link>
    <guid isPermaLink="true">https://www.thezdi.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys</guid>
    <description>Writeup detailing CVE-2026-47291, a kernel-mode remote code execution vulnerability in Windows HTTP.sys. Exploitation involves an attacker sending crafted HTTP/1.x requests over TLS, triggering a heap buffer overflow during header parsing due to insufficient bounds checking when growing a buffer reference array. This can lead to denial-of-service or code execution with kernel privileges. The vulnerability is mitigated by configuring `MaxRequestBytes` to 65,535 or lower, and detection requires monitoring TLS-encrypted traffic for an unusually high number of HTTP header lines per request.</description>
    <category>RCE</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 23:34:17 +0000</pubDate>
    <source url="https://appsec.fyi/rce.html">RCE — appsec.fyi</source>
  </item>
  <item>
    <title>Roundcube Webmail Security Update Patches Critical Zero-Click XSS and SSRF Bypass Flaws</title>
    <link>https://gbhackers.com/roundcube-webmail-security-update-patches-critical-zero-click-xss/</link>
    <guid isPermaLink="true">https://gbhackers.com/roundcube-webmail-security-update-patches-critical-zero-click-xss/</guid>
    <description>Roundcube Webmail has released a security update addressing critical zero-click vulnerabilities. These flaws allowed for Cross-Site Scripting (XSS) and Server-Side Request Forgery (SSRF) bypasses, potentially enabling attackers to execute malicious code or access internal resources without user interaction. Users are strongly advised to update their Roundcube installations immediately to mitigate these risks. The update is crucial for protecting against potential exploitation of these severe security weaknesses.</description>
    <category>XSS</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 22:16:32 +0000</pubDate>
    <source url="https://appsec.fyi/xss.html">XSS — appsec.fyi</source>
  </item>
  <item>
    <title>Injective Labs SDK npm package compromised to steal cryptocurrency keys</title>
    <link>https://www.scworld.com/brief/injective-labs-sdk-npm-package-compromised-to-steal-cryptocurrency-keys</link>
    <guid isPermaLink="true">https://www.scworld.com/brief/injective-labs-sdk-npm-package-compromised-to-steal-cryptocurrency-keys</guid>
    <description>Library for detecting supply-chain attacks like the compromise of the @injectivelabs/sdk-ts npm package. Hackers injected malicious code into version 1.20.21 of the package, which was downloaded 310 times, to steal cryptocurrency private keys and mnemonic seed phrases. The malware targeted functions for generating or importing wallet keys, exfiltrating captured data via HTTP POST requests. This incident highlights the risk to applications built with cryptocurrency wallets, trading bots, decentralized exchanges, and DeFi applications.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 21:25:43 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>Sudarshana: Cornered a headless PDF export that fetched user URLs. Pointed it at 169.254.169.254/latest/meta-data/iam/security-credentials/ and it echoed a role&#x27;s temp keys. IMDSv2 blocks this: no PUT token no answer. Allowlist the hosts you call denylists miss the IP. #SSRF #IMDSv2</title>
    <link>https://x.com/Sudarshana_io/status/2075682976583602648</link>
    <guid isPermaLink="true">https://x.com/Sudarshana_io/status/2075682976583602648</guid>
    <description>A security researcher, Sudarshana, discovered a Server-Side Request Forgery (SSRF) vulnerability in a headless PDF export. By directing the export to a specific AWS IMDSv2 endpoint (169.254.169.254/latest/meta-data/iam/security-credentials/), they successfully retrieved temporary AWS credentials. The researcher notes that IMDSv2&#x27;s default configuration, which requires a PUT token, prevents this exploitation. They recommend using host allowlists rather than denylists to mitigate such vulnerabilities, as denylists may miss specific IPs.</description>
    <category>SSRF</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Fri, 10 Jul 2026 21:03:37 +0000</pubDate>
    <source url="https://appsec.fyi/ssrf.html">SSRF — appsec.fyi</source>
  </item>
  <item>
    <title>OpenClaw Vulnerabilities Let Attackers Turn WhatsApp Messages Into Host-Level Code Execution</title>
    <link>https://cyberpress.org/openclaw-remote-access-tool/</link>
    <guid isPermaLink="true">https://cyberpress.org/openclaw-remote-access-tool/</guid>
    <description>Researchers have discovered critical vulnerabilities in OpenClaw, a messaging application. These flaws could allow attackers to execute arbitrary code on a user&#x27;s host system simply by sending a specially crafted WhatsApp message. This means a malicious message could potentially compromise a user&#x27;s entire device, going beyond just the messaging application itself. Further details are available at the provided link.</description>
    <category>RCE</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 20:49:20 +0000</pubDate>
    <source url="https://appsec.fyi/rce.html">RCE — appsec.fyi</source>
  </item>
  <item>
    <title>Developers face RCE via Claude Code &#x27;auto-mode&#x27; exploit</title>
    <link>https://www.developer-tech.com/news/developers-face-rce-via-claude-code-auto-mode-exploit/</link>
    <guid isPermaLink="true">https://www.developer-tech.com/news/developers-face-rce-via-claude-code-auto-mode-exploit/</guid>
    <description>A vulnerability in Claude Code&#x27;s &quot;auto-mode&quot; allows for Remote Code Execution (RCE), posing a significant security risk to developers. This exploit enables malicious actors to potentially run arbitrary code on a developer&#x27;s system through the AI assistant. Further details are available via the provided link. The summary does not include a payout amount as none was stated in the content.</description>
    <category>RCE</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 20:09:18 +0000</pubDate>
    <source url="https://appsec.fyi/rce.html">RCE — appsec.fyi</source>
  </item>
  <item>
    <title>Hackers can use 9 of the most popular AI tools to assemble massive botnets</title>
    <link>https://arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/</link>
    <guid isPermaLink="true">https://arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/</guid>
    <description>Library for mitigating prompt injection vulnerabilities in AI assistants. HalluSquatting, a novel pull-based attack, exploits LLMs&#x27; tendency to hallucinate resource identifiers, enabling the assembly of massive botnets and large-scale device infections. This technique targets AI coding assistants like Cursor, Gemini CLI, GitHub Copilot, and others by registering predicted hallucinated identifiers and seeding them with malicious payloads.</description>
    <category>AI Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 18:45:37 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>Hackers tried to backdoor Injective npm package to steal wallet keys</title>
    <link>https://cryptonews.net/news/security/33128062/</link>
    <guid isPermaLink="true">https://cryptonews.net/news/security/33128062/</guid>
    <description>Malicious actors attempted to compromise the Injective npm package, a crucial component for developers building on the Injective blockchain. The attackers aimed to inject malicious code into the package to steal users&#x27; private wallet keys. This incident highlights the ongoing threats to the cryptocurrency ecosystem and the importance of robust security measures for open-source software. Further details on the specifics of the attack and its prevention are likely to be found in the linked article.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 18:45:34 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>CrowdStrike identifies five new prompt injection threats to AI</title>
    <link>https://www.csoonline.com/article/4195670/crowdstrike-identifies-five-new-prompt-injection-threats-to-ai.html</link>
    <guid isPermaLink="true">https://www.csoonline.com/article/4195670/crowdstrike-identifies-five-new-prompt-injection-threats-to-ai.html</guid>
    <description>Analysis of five new prompt injection threats identified by CrowdStrike against AI systems. These techniques include Trigger-Activated Rule Addition, Cognitive Token Suppression, Algorithmic Payload Decomposition, Special Token Injection, and Unwitting User Context-Data Injection, which exploit LLMs by tricking them into accepting dubious instructions disguised as benign input. Security teams can counter these attacks through threat modeling, expanded testing, and detection engineering for composite attacks.</description>
    <category>AI Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 16:05:33 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>Injective software package hit by malicious supply chain attack</title>
    <link>https://ambcrypto.com/injective-software-package-hit-by-malicious-supply-chain-attack-details/</link>
    <guid isPermaLink="true">https://ambcrypto.com/injective-software-package-hit-by-malicious-supply-chain-attack-details/</guid>
    <description>Library for building Injective applications, compromised via a malicious supply chain attack on the `@injectivelabs/sdk-ts` package (v1.20.21) published to npm. Attackers gained access to a contributor&#x27;s GitHub account to push malicious commits and, under the guise of telemetry, uploaded a backdoor that stole developers&#x27; private keys and mnemonic seed phrases when using `fromMnemonic` or `fromHex` wallet generation functions. The attack spread through transitive dependencies in 17 additional Injective packages.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 15:35:39 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws</title>
    <link>https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html</guid>
    <description>Writeup detailing a WhatsApp-to-host attack chain leveraging three OpenClaw vulnerabilities: GHSA-hjr6-g723-hmfm and GHSA-9969-8g9h-rxwm, both involving OS command injection and incomplete input validation in the host execution environment filtering; and GHSA-575v-8hfq-m3mc, a path traversal flaw enabling sandbox bind mount bypass. These flaws allow for credential theft, privilege escalation, and arbitrary code execution without prior host compromise, as demonstrated by accessing sensitive user files or the Docker socket.</description>
    <category>RCE</category>
    <category domain="difficulty">advanced</category>
    <pubDate>Fri, 10 Jul 2026 14:34:29 +0000</pubDate>
    <source url="https://appsec.fyi/rce.html">RCE — appsec.fyi</source>
  </item>
  <item>
    <title>Daily CyberSecurity: Four Apache Camel vulnerabilities allow header injection server-side request forgery secret disclosure and an authentication bypass. Patch to 4.21.0 now. #ApacheCamel #HeaderInjection #SSRF #CyberSecurity #Vulnerability #InfoSec</title>
    <link>https://x.com/Daily_CyberSec/status/2075581115335614844</link>
    <guid isPermaLink="true">https://x.com/Daily_CyberSec/status/2075581115335614844</guid>
    <description>Four critical vulnerabilities have been discovered in Apache Camel, affecting versions prior to 4.21.0. These vulnerabilities enable header injection, server-side request forgery (SSRF), secret disclosure, and authentication bypass. Users are strongly advised to update to version 4.21.0 immediately to patch these security flaws and protect their systems.</description>
    <category>SSRF</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 14:08:23 +0000</pubDate>
    <source url="https://appsec.fyi/ssrf.html">SSRF — appsec.fyi</source>
  </item>
  <item>
    <title>Your next insider threat doesnt have a badge. It has an API token</title>
    <link>https://www.cio.com/article/4195152/your-next-insider-threat-doesnt-have-a-badge-it-has-an-api-token.html</link>
    <guid isPermaLink="true">https://www.cio.com/article/4195152/your-next-insider-threat-doesnt-have-a-badge-it-has-an-api-token.html</guid>
    <description>Library for securing AI agents, this resource addresses the evolving threat landscape where authorized AI agents, acting within their granted permissions, can cause breaches through sequences of seemingly benign actions. It details failure modes like tool-chain abuse, delegation-chain exploitation, and approval evasion, arguing that traditional security models focused on &quot;who is allowed in&quot; and &quot;what data is allowed out&quot; are insufficient for agentic systems. The library advocates for a runtime policy engine to govern agent actions at the moment they occur, ensuring authority shrinks during delegation and that audit logs serve as immutable evidence.</description>
    <category>API Security</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Fri, 10 Jul 2026 10:11:08 +0000</pubDate>
    <source url="https://appsec.fyi/apisec.html">API Security — appsec.fyi</source>
  </item>
  <item>
    <title>Django SQL Injection Vulnerability Actively Exploited in the Wild</title>
    <link>https://cybersecuritynews.com/django-sql-injection-vulnerability-exploited/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/django-sql-injection-vulnerability-exploited/</guid>
    <description>A critical SQL injection vulnerability in Django is currently being exploited in the wild. This vulnerability affects Django versions 3.2.x prior to 3.2.18, 4.0.x prior to 4.0.7, and 4.1.x prior to 4.1.1. The exploit targets specific database queries that can be manipulated to gain unauthorized access or execute malicious commands. Users are strongly advised to update to the patched versions immediately to mitigate this risk. No specific bounty payout amount was mentioned in the provided content.</description>
    <category>SQLi</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 09:06:31 +0000</pubDate>
    <source url="https://appsec.fyi/sqli.html">SQLi — appsec.fyi</source>
  </item>
  <item>
    <title>Turning software supply chain security into a daily habit</title>
    <link>https://www.helpnetsecurity.com/2026/07/10/software-supply-chain-security-video/</link>
    <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/07/10/software-supply-chain-security-video/</guid>
    <description>Guide on operationalizing software supply chain risk, arguing for daily use of SBOMs beyond compliance for vulnerability triage, vendor access reviews, identity monitoring, and incident response. It draws on Group-IB’s High-Tech Crime Trend Report 2026 to illustrate how supply chain attacks link phishing, ransomware, and data breaches through inherited trust. The guide details prioritizing exposed systems, defining compromise windows, containing stolen credentials, and vendor risk scoring, highlighting AI&#x27;s acceleration of attack timelines.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Fri, 10 Jul 2026 06:45:25 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>Roundcube Webmail 1.7.2 Fixes Zero-Click XSS SSRF Bypass and DoS Flaws</title>
    <link>https://cyberpress.org/roundcube-webmail-1-7-2-fixes-zero-click-xss-dos/</link>
    <guid isPermaLink="true">https://cyberpress.org/roundcube-webmail-1-7-2-fixes-zero-click-xss-dos/</guid>
    <description>Roundcube Webmail 1.7.2 addresses critical security vulnerabilities, including a zero-click Cross-Site Scripting (XSS) flaw, a Server-Side Request Forgery (SSRF) bypass, and Denial of Service (DoS) issues. The update provides essential patches to protect users from these threats.</description>
    <category>SSRF</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 06:16:31 +0000</pubDate>
    <source url="https://appsec.fyi/ssrf.html">SSRF — appsec.fyi</source>
  </item>
  <item>
    <title>Inside an AI coal mine security camera network powered by plaintext passwords</title>
    <link>https://eaton-works.com/2026/07/08/coal-india-camera-hack</link>
    <guid isPermaLink="true">https://eaton-works.com/2026/07/08/coal-india-camera-hack</guid>
    <description>Writeup of plaintext password vulnerability in Coal India&#x27;s AI security camera network, exposing the &quot;RPI Dashboard&quot; developed by DeepSight AI Labs. The analysis details how an unauthenticated API call to `get_users` revealed an entire user list with weak, duplicated passwords, and how local storage manipulation could bypass authentication to access the alert dashboard across seven coal mines, a flaw later confirmed fixed by CERT-IN.</description>
    <category>Secrets &amp; Credential Leaks</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Fri, 10 Jul 2026 06:15:37 +0000</pubDate>
    <source url="https://appsec.fyi/secrets.html">Secrets &amp; Credential Leaks — appsec.fyi</source>
  </item>
  <item>
    <title>Claude Code is steganographically marking requests</title>
    <link>https://thereallo.dev/blog/claude-code-prompt-steganography</link>
    <guid isPermaLink="true">https://thereallo.dev/blog/claude-code-prompt-steganography</guid>
    <description>Analysis of Claude Code reveals prompt steganography used to mark requests. The application locally alters the system prompt by subtly changing date separators or apostrophes, embedding classification data about API base URLs and system timezones. This technique, triggered by the `ANTHROPIC_BASE_URL` environment variable and specific geographical timezones, aims to detect API resellers and unauthorized gateways. While not malicious, the hidden implementation of this classification mechanism undermines trust in a tool with extensive filesystem and shell access.</description>
    <category>AI Security</category>
    <category domain="difficulty">advanced</category>
    <pubDate>Fri, 10 Jul 2026 06:15:31 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>Xsnow &quot;protestware&quot; in Debian</title>
    <link>https://lwn.net/SubscriberLink/1079385/3d7a57da58b41aa9</link>
    <guid isPermaLink="true">https://lwn.net/SubscriberLink/1079385/3d7a57da58b41aa9</guid>
    <description>Writeup detailing the &quot;protestware&quot; controversy surrounding the Xsnow application in Debian. The entry discusses how Xsnow&#x27;s maintainer included a feature that displayed Ukrainian flags when the application&#x27;s language was set to Russian. This triggered a debate on the Debian development list regarding potential violations of the Debian Free Software Guidelines (DFSG), specifically concerning discrimination. While Xsnow itself was deemed DFSG-compliant, the discussion highlighted concerns about software exhibiting deceptive behavior based on user settings.</description>
    <category>Supply Chain Security</category>
    <category domain="difficulty">news</category>
    <pubDate>Fri, 10 Jul 2026 06:15:30 +0000</pubDate>
    <source url="https://appsec.fyi/supplychain.html">Supply Chain Security — appsec.fyi</source>
  </item>
  <item>
    <title>Symlinks Are Still Scary (And Yes, You Can Commit Them to Git)</title>
    <link>https://snyk.io/blog/symlinks-are-still-scary</link>
    <guid isPermaLink="true">https://snyk.io/blog/symlinks-are-still-scary</guid>
    <description>Library detailing symlink attacks, a decades-old vulnerability vector enabling arbitrary file access and RCE. These attacks leverage symbolic links, small files containing paths that, when opened by a program, redirect to another location. Git&#x27;s support for committing symlinks allows attackers to ship them in repositories, posing risks to build scripts, editors, and AI agents that process files without proper path resolution. The library highlights historical examples like CVE-2021-32803, Zip Slip, CVE-2024-21626, and CVE-2024-32002, alongside modern instances in Incus, emphasizing the need to resolve paths atomically before operation.</description>
    <category>AI Security</category>
    <category domain="difficulty">intermediate</category>
    <pubDate>Fri, 10 Jul 2026 06:00:41 +0000</pubDate>
    <source url="https://appsec.fyi/ai.html">AI Security — appsec.fyi</source>
  </item>
  <item>
    <title>Why offensive security and exposure management can&#x27;t stay siloed in the AI era</title>
    <link>https://yeswehack.com/en/blog/offensive-security-exposure-management-siloed</link>
    <guid isPermaLink="true">https://yeswehack.com/en/blog/offensive-security-exposure-management-siloed</guid>
    <description>In the AI era, offensive security and exposure management must integrate. Traditional silos hinder proactive threat identification and mitigation. AI-powered tools can enhance both, offering deeper insights into vulnerabilities and potential attack vectors. Integrating these disciplines allows organizations to move beyond reactive security measures and build a more resilient defense against evolving cyber threats. This unified approach is crucial for effective risk management in a rapidly changing landscape.</description>
    <category>Bug Bounty</category>
    <category domain="difficulty">beginner</category>
    <pubDate>Fri, 10 Jul 2026 06:00:32 +0000</pubDate>
    <source url="https://appsec.fyi/bugbounty.html">Bug Bounty — appsec.fyi</source>
  </item>
</channel>
</rss>