Research
Trust Me, I'm an Artifact: I'll Just Borrow Your Shell
Originally published on Bloom Security.
Shai Hulud Returns: Keyv and the Caching Ecosystem Hit in a Self-Replicating NPM Attack
Originally published on Bloom Security.
Poisoned Coworker: Hijacking Claude Cowork
Claude Cowork is sold as a safe place to do dangerous things: an AI coworker that lives inside a real Linux VM...
Securing the Core, Ignoring the Door: The Repo Trust Trap
TL;DR I found OS Command Injection (CWE-78) in the developer tooling of two widely-used open-source projects: Envoy (CNCF graduated, powers Istio) and...
From Gate Opener to Full Control: Hacking a Smart Parking Device
When I moved into my new apartment, I was excited. A fresh start, a great location, and — best of all —...
No research posts match these filters.