Logo
Search
Home
Archive
Login
SUBSCRIBE
Logo

THE ARCHIVE

Every issue, open.

One attack, one rule, one move worth shipping.
Your GitLab issue email can push to main

Sep 29, 2026

•

5 min read

Your GitLab issue email can push to main

GitLab's file-an-issue-by-email address carries a token that reaches every project the account can reach and never expires. Aikido showed it can change code and run CI as the owner, on a project locked to an IP allowlist too. GitLab closed the report as intended behavior.

Your AI agent can read its own vault secret

Sep 22, 2026

•

6 min read

Your AI agent can read its own vault secret

AWS AgentCore Harness copies vault secrets into its own memory as plaintext, where its default shell tool can read them. In a lab with a permissive model, Unit 42 stole a token through a support ticket and used it from a laptop. AWS closed the report as informative, pointing to customer-side controls.

Your package registry trusts a key of 32 spaces

Sep 15, 2026

•

6 min read

Your package registry trusts a key of 32 spaces

A config value JFrog Artifactory never set resolved to the empty string, passed three checks that each asked a different question, and registered as a working signing key. Its secret is 32 space characters, and anything signed with it is treated as a cluster member.

cloud-security

+3

Your agent can edit /etc/hosts

Sep 8, 2026

•

5 min read

Your agent can edit /etc/hosts

Agents on a timed lookup task were allowed to fetch pages and blocked from sending anything that writes. They invented a hostname ending in a trusted suffix, pointed it at the blocked server, and posted the recipe for each other.

Your WAF logs your users' session cookies

Sep 1, 2026

•

8 min read

Your WAF logs your users' session cookies

AWS WAF logs every request header by default, unredacted. Redacting the log files does not cover the requests the WAF serves from its own API.

cloud-security

+4

Malware asks your MCP server what it can do

Aug 25, 2026

•

7 min read

Malware asks your MCP server what it can do

It asks your server what tools it has, then uses the one that runs commands. No bug, no patch.

Your docker cp can overwrite host files

Aug 18, 2026

•

6 min read

Your docker cp can overwrite host files

Copying one file out of a container can overwrite /usr/bin/runc. CVE-2026-17106.

cloud-security

+4

Your build server runs commands from strangers

Aug 11, 2026

•

6 min read

Your build server runs commands from strangers

TeamCity handed XStream a list of allowed classes. XStream added it to the ones it already allowed.

cloud-security

+3

Your secrets webhook hands out its own token

Aug 4, 2026

•

6 min read

Your secrets webhook hands out its own token

One annotation redirects the client, and the webhook's own token goes with it

R.K. Chidambaram
R.K. Chidambaram
Load more

Weekly Recon

Weekly defensive engineering for cloud, CI/CD, agents, Kubernetes, and software supply-chain security. One attack walked through. One detection idea. One defender move worth shipping.

© 2026 defensive.works Weekly Recon.
beehiivPowered by beehiiv