Dark Reading·1d agoAI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment#access-control#agent-security#ai-agents
GBHackers·1d ago highGitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs#gitlab#email-token#ci-cd 6 sources 4 min
BleepingComputer·1d agoWith the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance#soc2#ai-agents#identity 8 min
CSO Online·1d agoFixing Flock: The controls needed now that misuse patterns are clear#flock-safety#alpr#surveillance 14 min
oss-security·2d agoCVE-2026-95811: Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it#lemonldap-ng#perl#cve-2026-95811CVE-2026-95811 3 sources
oss-security·2d agoCVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key#apache-airflow#hashicorp#vaultCVE-2026-97636
oss-security·2d agoCVE-2026-57590: Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations#apache#dolphinscheduler#cve-2026-57590CVE-2026-57590
CERT/CC Vulnerability Notes·2d agoVU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability#rfid#nfc#access-controlCVE-2026-75907 2 min
arXiv cs.CR·2d agoBeyond Centralized Policy Decision Points: Decentralized Sticky Policy Authorization through Evidence Quorums#sticky-policy#authorization#decentralizedResearch
arXiv cs.CR·3d agoPhysalia: Redistribution-Resistant Content Protection for Decentralized Storage#physalia#decentralized-storage#secret-sharingResearch
Dark Reading·3d agoRelays Are Masking Chinese Access to Frontier AI Models in the US#china#frontier-models#llm 2 sources
TechCrunch · AI·3d agoMeta’s AI agent has been blocked from using Amazon.com#meta#amazon#muse 6 sources
Full Disclosure·4d agoTeams meeting audio and roster data remain accessible via ACS Call Automation connectCall after a participant is removed from the meeting#microsoft#teams#azure-communication-servicesVulnerability
arXiv cs.CR·4d agoFrom Alignment to Access Control: A Framework for GenAI Policy Enforcement#genai#policy-enforcement#access-controlAI safety & security
oss-security·5d agoCVE-2026-93710: Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks#cve-2026-93710#dancer2#perlCVE-2026-93710 4 sources1
arXiv cs.CR·6d agoLeaseGuard: Incumbent-Preserving Admission Control for Privileged LLM Agents#access-control#admission-control#ai-safetyResearch
arXiv cs.CR·6d agoStructured Decomposition for Reliable LLM-Generated Access Control Policies#access-control#llm#opaResearch
oss-security·9d agoCVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)#access-control#apache-airflow#authorizationCVE-2026-75157
The Register · Security·9d agoTest environment let anyone access live customer data#access-control#data-exposure#misconfiguration 2 min
arXiv cs.CR·10d agoA Policy Profile for Croissant: Refusal as a Property of the Dataset#access-control#croissant#data-governanceResearch
Simon Willison·10d agodatasette 0.65.5#access-control#datasette#permission-bypassVulnerability 2 sources1
oss-security·10d agoCVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods#access-control#apache#authorization-bypassCVE-2026-82561 5 sources1
oss-security·11d agoCVE-2026-86465: Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key#access-control#akeyless#apache-airflowCVE-2026-86465
oss-security·11d agoCVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access#access-control#account-deactivation#apache-airflowCVE-2026-82310