Trust Me, I'm an Artifact: I'll Just Borrow Your Shell
Latest August 26, 2026

Trust Me, I'm an Artifact: I'll Just Borrow Your Shell

Originally published on Bloom Security.

Critical Claude Desktop — Artifacts / Cowork

Research

Deep dives into real-world security research, IoT hacking, and attack chain analysis.

Trust Me, I'm an Artifact: I'll Just Borrow Your Shell
Aug 26, 2026 Claude Artifacts Critical

Trust Me, I'm an Artifact: I'll Just Borrow Your Shell

Originally published on Bloom Security.

Shai Hulud Returns: Keyv and the Caching Ecosystem Hit in a Self-Replicating NPM Attack
Aug 04, 2026 keyv Critical

Shai Hulud Returns: Keyv and the Caching Ecosystem Hit in a Self-Replicating NPM Attack

Originally published on Bloom Security.

Poisoned Coworker: Hijacking Claude Cowork
Jun 23, 2026

Poisoned Coworker: Hijacking Claude Cowork

Claude Cowork is sold as a safe place to do dangerous things: an AI coworker that lives inside a real Linux VM...

Securing the Core, Ignoring the Door: The Repo Trust Trap
Feb 23, 2026

Securing the Core, Ignoring the Door: The Repo Trust Trap

TL;DR I found OS Command Injection (CWE-78) in the developer tooling of two widely-used open-source projects: Envoy (CNCF graduated, powers Istio) and...

View all 5 research posts →

Recent Advisories

The six newest disclosures. The full index is filterable by severity, vendor and year.

Tab Hijacking in Todoist for Chrome: One postMessage to Anywhere
May 03, 2026 Todoist CVE Reserved High

Tab Hijacking in Todoist for Chrome: One postMessage to Anywhere

Todoist for Chrome is the official browser extension from Doist for the Todoist task manager, with over 3 million users on the...

Prototype Pollution via .proto: When Your Schema Poisons the Runtime
Apr 12, 2026 protocol-buffers-schema CVE-2026-5758 Critical

Prototype Pollution via .proto: When Your Schema Poisons the Runtime

protocol-buffers-schema is an npm package for parsing Protocol Buffer schema definitions. It is the schema parser behind protocol-buffers, one of the original...

Replican't: When Deserialization Starts Writing Your Script
Mar 31, 2026 Replicator CVE-2026-2265 Critical

Replican't: When Deserialization Starts Writing Your Script

replicator is an npm package for advanced JavaScript serialization and deserialization. It extends regular JSON behavior and lets applications encode and restore...

LiquidOverflow — How a Template Engine Exposed 86,000 Repositories to Arbitrary File Read
Mar 11, 2026 LiquidJS CVE-2026-30952 High

LiquidOverflow — How a Template Engine Exposed 86,000 Repositories to Arbitrary File Read

Templating engines are the silent workhorses of the web. They sit between your data and your users, quietly rendering pages, emails, and...

i0Regret: Breaking the Chain — How a Missing Slash Led to Arbitrary Code Execution
Feb 03, 2026 OpenTelemetry CVE-2026-24051 High

i0Regret: Breaking the Chain — How a Missing Slash Led to Arbitrary Code Execution

In the cloud-native ecosystem, we rely on SDKs as the “truth” for telemetry and observability. We assume these libraries are passive observers,...

CVE-2025-46389: Emby MediaBrowser - Unverified Password Change
Jul 20, 2025 Emby CVE-2025-46389 Medium

Unverified Password Change

Emby is a popular self-hosted media server platform used to organize, stream, and share personal media libraries across devices. It handles user...

View all 50 advisories →