Fetching from the wire…
Security2026-08-27 · source-backed
The CNCF Sandbox project shipped fixes on August 26 for command injection in the Kubernetes toolset plus slab, kubevela, inspektor_gadget and aks follow-ups, SSRF in fetch_webpage and connectivity_check, and hardening of kubectl-run to execute without a host shell (GitHub). The bash toolset now validates command arguments and redirections rather than just the prefix, and session-approval prefixes are cryptographically signed to prevent forgery. Prefix-only validation is the same class of mistake as Chainlit's executable-name allowlist, appearing in two unrelated projects on the same day.
Each link below shares sources, entities, or timing with this story.
Founding signatories include AWS, Anthropic, Google, OpenAI, NVIDIA, Microsoft and GitHub, IBM, Red Hat, Cisco, JPMorganChase, Citi, the Rust Foundation, Zscaler, and Sonatype, with OpenSSF, CNCF, and OpenInfra participating. The open letter drew 455 points on HN. (Akrites / L...
chaterm/Chaterm merged PR #2484 today fixing its database-ai read-only guard, which failed to parse parenthesized and UNION set queries and accepted DML before an EXPLAIN SELECT (GitHub). The fix also bounds unwrap iterations and handles VALUES CTEs. That guard is the only thi...
Frontier labs publish demos. This one published the thing they actually page. Anthropic's August 18 writeup describes Claude Tag running as the first responder for CI failures inside the company. Dedicated service account. MCP connectors to Datadog, Grafana, PagerDuty, GitHub...
gemini-cli's August 27 nightly prevents SSRF in MCP OAuth metadata discovery and authentication (PR #29081), google/adk-python v1.39.1 added a Host header check on its CLI server plus artifact reference scoping, and pydantic-ai v2.35.3 scopes safe_download cookies to their ori...
Hudson Rock got hold of the archive and counted it. 433,909 files. 118,829 CI runner dumps traced to 2,488 corporate domains. AWS keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys belonging to NVIDIA, Volkswagen, Micr...
A community radar repo scans GitHub every six hours and dynamically tests plugins on a Kubernetes cluster. Its August 16 snapshot indexes 2,855 candidates, confirms 2,560, has tested 1,305, and rates only 860 as runtime-usable against 394 outright incompatible (GitHub). The cu...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.