Posts

CRLF-Powered Desync Attacks: Beheading HTTP Streams

This PortSwigger research by Tom Stacey and Tobia Righi, presented at Black Hat and DEF CON 2026, demonstrates how a simple HTTP header injection primitive using CRLF sequences can be escalated into full-blown desync attacks, including request smuggling, response queue poisoning, browser-powered desync, and even self-propagating desync worms. The technique exploits common misconfigurations in Nginx, OpenResty, and Tengine reverse proxies that decode CRLF characters, allowing attackers to inject their own headers or split requests. The attacks can be triggered through the victim's browser using JavaScript fetch or simple page navigation, bypassing IP and connection-locked protections to steal HTTPOnly cookies and achieve account takeover. The research included real-world case studies across CDN, telecom, payments, retail, streaming, and social media platforms, with a companion Burp extension released for detection.  https://portswigger.net/research/crlf-powered-desync-attacks

Containers Are No Longer a Security Boundary

DepthFirst argues that traditional Linux containers should no longer be treated as a strong security isolation boundary because they share the host kernel. The research demonstrates a container escape using CVE-2026-80521, a Linux kernel use-after-free vulnerability in the AF_UNIX subsystem, and argues that AI-assisted vulnerability discovery and exploit generation are lowering the barrier to kernel exploitation. The recommended mitigation is to use stronger isolation mechanisms such as microVMs, including Firecracker or Kata Containers, especially for untrusted and multi-tenant workloads.  https://depthfirst.com/research/containers-are-no-longer-safe

How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign

This Wiz blog post presents a practical investigation playbook drawn from the Wiz Customer Incident Response Team's response to a coordinated campaign targeting GitHub Personal Access Tokens (PATs) across multiple organizations between May and June 2026. The attack followed three phases: reconnaissance via the GitHub API from an AWS IP address using a Chrome user agent, low-volume validation cloning from HostPapa infrastructure to confirm token validity, and finally a mass parallelized repository cloning operation using 102 AWS IP addresses in the ca-central-1 region with a git/2.43.0 user agent. The investigation methodology includes reviewing GitHub audit logs and personal security logs to establish baselines and identify anomalies, pivoting on indicators of compromise, and engaging GitHub Support for additional logs. The initial access vector—how the attacker obtained valid PATs across multiple unrelated organizations—remained unidentified in the investigation. The post recommen...

Measuring the Quality of AI-Powered Threat Models

LLM-based and increasingly agentic threat-modeling tools can now augment significant portions of threat modeling from analyzing architectures and identifying assets to generating Data Flow Diagrams (DFDs), threats, attack scenarios, attack trees, adversarial tests, and mitigations. As these capabilities become more sophisticated and autonomous, an equally important challenge emerges: how do we objectively measure the quality of the threat models they produce? The number of threats generated is not, by itself, an indication of quality. Nor is the percentage that results in remediation, because threat validity, risk acceptance, and remediation are different decisions. More importantly, these measures tell us little about relevant threats the AI failed to identify.  I approach this challenge through scope and input validation, expert-established ground truth, True Positive/False Positive/False Negative classification, precision, recall, F1, and Human-in-the-Loop validation. The object...

Finding and Fixing Software Vulnerabilities Using AI: A Guide for Developers

This is a guide from the OpenSSF Best Practices Working Group and the OpenSSF AI/ML Working Group, authored by David A. Wheeler and contributors, aimed at software developers and vulnerability researchers. It covers how to use artificial intelligence to find and fix software vulnerabilities, and the material is intended to serve as the basis for a course.  https://best.openssf.org/Finding-and-Fixing-Vulnerabilities-Using-AI/

Agentic Vulnerability Enumeration (AVE) — Behavioral Classification Standard for Agentic AI

AVE is an open standard for classifying and scoring behavioral vulnerabilities in agentic AI components, including skill files, MCP servers, and agent plugins. It provides stable vulnerability IDs, behavioral fingerprints, AIVSS-based severity scores, detection guidance, and mappings to frameworks such as OWASP MCP Top 10, OWASP Agentic AI Top 10, and MITRE ATLAS. The standard is designed to make findings interoperable and comparable across different security scanners and implementations. https://aveproject.org/

IAM for AI Agents: A Practical Enterprise Framework

This article outlines an identity and access management framework for AI agents, treating each agent as a non-human identity with a human owner, defined purpose, scoped authorization, an expiration, and continuous monitoring. It explains why traditional IAM systems fall short, since they describe access as configured rather than what an autonomous agent actually executed, creating an intent-to-execution gap the article calls identity dark matter. Recurring lifecycle failure modes include absent ownership, long-lived secrets, unbounded delegation, invisible instantiation, and no expiration. Essential components cover distinct agent identity and short-lived federated credentials, fine-grained authorization such as task-scoped grants, tool allowlisting, data boundaries, and action thresholds, plus behavioral auditability and revocation. The article recommends extending existing governance platforms for lifecycle, building in-application enforcement where agent frameworks are proprietary, ...