ai-security
Safeguard articles tagged "ai-security" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Authorization Belongs in the Tool, Not in the Prompt
Your support chatbot can now issue refunds and look up orders, because someone connected it to real tools. Every one of those actions sits behind a customer-facing text box, protected however carefully the prompt was worded.
A Poisoned Memory Outlives the Conversation That Created It
Prompt injection in a single turn affects one response, then the next request starts clean. A persistent memory feature breaks that boundary by design, so a single successful injection becomes durable, recalled and trusted in every future session.
Writing an MCP Server That Holds No Credentials
Give a model a tool that writes and you have added a route into whatever sits behind it. The design that keeps it a new shape rather than a new privilege, and the four things that were not obvious.
postmark-mcp: The First Confirmed Malicious MCP Server Found in the Wild
A single added line of code in a compromised npm package silently BCC'd every outgoing email to an attacker. Snyk's disclosure marks the first real, deployed malicious MCP server, not a proof of concept.
How a GitHub Actions Flaw Turned a 61-Million-Download Python Package Into a Cryptominer Delivery Vector
The Ultralytics YOLO compromise in December 2024 didn't touch a single line of reviewed code. It exploited the CI/CD pipeline that builds and publishes the package instead.
EchoLeak: The First Real-World Zero-Click Prompt Injection in a Production LLM
A single email, never opened or clicked, was enough to exfiltrate data from Microsoft 365 Copilot. CVE-2025-32711 shows why zero-click prompt injection is a categorically different threat than phishing-style attacks.
Langflow and Marimo: When the AI Platform's Core Feature Is the Vulnerability
Three confirmed-exploited CVEs across Langflow and Marimo show what happens when a code-execution-by-design platform ships an authentication gap on the endpoint meant to guard it.
Langflow, MLflow, Ray, LiteLLM and Kestra: AI Orchestration Platforms Enter CISA's KEV Catalogue
Five AI and ML orchestration platforms had vulnerabilities confirmed as exploited in the wild between July and September 2026 — Langflow twice, then MLflow, Ray, and Kestra. Five different root causes, one shared category.
Indirect Prompt Injection Stopped Being a Demo. Google Is Measuring It at Web Scale.
Malicious injected instructions are now tracked across billions of crawled pages a month, every AI browser tested at Black Hat proved vulnerable, and one framework bug turned a prompt into RCE.
66,000 CVEs: The Year Enumeration Stopped Being a Strategy
2026 is forecast to close near 66,000 CVEs, driven partly by AI-assisted discovery. At that volume reading the list is not a job anyone can do — and most programmes are still built around reading it.
CVE-2026-9198: Two Endpoints, No Password, Full Remote Code Execution
Langflow's auto-login endpoint mints a superuser token for anyone who asks. Its code-validation endpoint runs Python through exec(). Chained, that is unauthenticated RCE at CVSS 9.8.
You Cannot Defend an MCP Server You Do Not Know You Are Running
Tool poisoning is the most impactful client-side MCP vulnerability, and the defensive research is solid. All of it assumes you know which MCP servers you connect to. Almost nobody does.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.