This week's articles
One does not simply defend agentically
Defenders face organisational/political constraints that prevent agentic AI use analogous to attackers. NCSC proposes a risk framework across potency, scope, criticality, rollout confidence, and recoverability dimensions to safely identify and expand automatable defensive actions.
Detection fidelity in the age of AI agents living off the land
AI agents using standard Linux tools (curl, tcpdump, Python scripts) erode tripwire detection fidelity by flooding systems with legitimate-looking noise. Detection must shift to probabilistic correlation of co-occurring signals across the kill chain, not isolated indicators.
Send GitLab an email, push to main
GitLab gives you a private email address to create issues. If leaked, anyone who has it can push code, execute CI/CD jobs, and bypass IP restrictions across all of your public and private projects.
Exploring the new AWS Sign Up experience
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.
Containers Are No Longer a Security Boundary
AI-accelerated kernel vuln discovery (5,976 CVEs in 2026) has made container escapes trivial. CVE-2026-80521, a Linux AF_UNIX use-after-free, demonstrates a full container escape.
Mapping Scaleway IAM, An Attacker's View of the Trust Boundaries
An attacker-focused analysis of Scaleway IAM trust boundaries, showing how a stolen user API key equals full account takeover, how policy-less keys still enable reconnaissance, and offering defender mitigations including preferring application keys and treating org metadata as public.
Hacking OpenAI
Researchers chained a libheif heap buffer overflow (via Discourse/ImageMagick image upload) with an OpenAI SSO misconfiguration to achieve RCE on community.openai.com, take over employee ChatGPT/Codex accounts, and access OpenAI's internal GitHub monorepo.
|