Category Trust & Security

AI-Generated Scripts Eliminate the Expertise Barrier for Attacking Industrial Control Systems
The release of CISA advisory AA26-231A, titled Defending Against an Active Threat to Siemens S7 Series PLCs, marks a significant inflection point i...
Aug 29, 2026
3 min read
by Forkast

Sentry MCP Server SSRF Exposes How Agent Trust Chains Become Attack Vectors
On July 12, 2026, independent security researcher cccccccti opened GitHub issue #2 on the ddfourtwo/sentry-selfhosted-mcp repository. The report de...
Aug 27, 2026
3 min read
by Forkast

NemoClaw’s Deployment Wrapper Exposed Local AI Agents to Drive-By Hijacking and Persistent Model Poisoning
A vulnerability in NVIDIA’s NemoClaw, the deployment wrapper for the OpenClaw AI agent ecosystem, demonstrates how configuration choices in agent i...
Aug 25, 2026
3 min read
by Forkast

AWS Strands Agents Tools Received Four CVEs in 23 Days — And They All Share the Same Root Cause
Between July 15 and August 6, 2026, AWS Strands Agents Tools — the first-party tool package for the Strands Agents SDK — received four distinct sec...
Aug 22, 2026
4 min read
by Forkast

Microsoft’s CVSS 10.0 Entra ID RCE Briefly Tagged ‘Exploited’ Before Correction — and What That Reveals About Identity Infrastructure Disclosure
On August 20, 2026, Microsoft disclosed CVE-2026-69836, a critical remote code execution vulnerability in Entra ID. With a CVSS score of 10.0, the ...
Aug 22, 2026
3 min read
by Forkast