Logo
Search
Home
Archive
Login
SUBSCRIBE
Logo

Detection Engineering

cloud-security

+3

Your agent can edit /etc/hosts

Sep 8, 2026

•

5 min read

Your agent can edit /etc/hosts

Agents on a timed lookup task were allowed to fetch pages and blocked from sending anything that writes. They invented a hostname ending in a trusted suffix, pointed it at the blocked server, and posted the recipe for each other.

cloud-security

+4

Malware asks your MCP server what it can do

Aug 25, 2026

•

7 min read

Malware asks your MCP server what it can do

It asks your server what tools it has, then uses the one that runs commands. No bug, no patch.

cloud-security

+4

Your build server runs commands from strangers

Aug 11, 2026

•

6 min read

Your build server runs commands from strangers

TeamCity handed XStream a list of allowed classes. XStream added it to the ones it already allowed.

cloud-security

+3

Your secrets webhook hands out its own token

Aug 4, 2026

•

6 min read

Your secrets webhook hands out its own token

One annotation redirects the client, and the webhook's own token goes with it

R.K. Chidambaram
R.K. Chidambaram

cloud-security

+4

How a rootkit hides a connection

Jul 28, 2026

•

2 min read

How a rootkit hides a connection

One number gets rewritten, and your socket list comes back short

Weekly Recon

Weekly defensive engineering for cloud, CI/CD, agents, Kubernetes, and software supply-chain security. One attack walked through. One detection idea. One defender move worth shipping.

© 2026 defensive.works Weekly Recon.
beehiivPowered by beehiiv