๐ต๏ธ RESEARCH & DEEP DIVES
-
Security Assessment Reveals Multiple Vulnerabilities in Internet-Facing MCP Servers
A dynamic security assessment found numerous vulnerabilities in internet-facing MCP servers.- Applies to over 21,000 internet-facing Model Context Protocol (MCP) servers launched since Nov 2024
- Assessment audited 414 production MCP servers, uncovering 68 vulnerabilities including SQL injection and SSRF
- Attacks exploit cloud metadata services, prompt template injection, and path traversal via cursor manipulation
- 91.8% of audited servers lack OAuth authentication and many expose shell execution without access controls
- 41.6% of servers disappear within three days, indicating rapid deployment cycles without security review
๐ Coverage: arxiv.org ยท ๐ Original: arxiv.org ยท ๐ via arXiv cs.CR
-
Researchers demonstrate stealthy backdoor evading diffusion model semantic watermarks
A stealthy backdoor method enables evasion of semantic watermarks in latent diffusion models.- Applies to Latent Diffusion Models (LDMs) using semantic watermarking for image protection
- Targets watermark detection pipelines relying on neural networks, specifically VAE encoders
- Uses GhostVAE to implant a backdoor with a universal trigger via power spectrum regularization
- Achieves high evasion success (~94.6%) while preserving watermark detection on benign images (~94.4%)
- Backdoor remains stealthy against 17 defenses across input, parameter, and latent spaces
๐ Coverage: arxiv.org ยท ๐ Original: arxiv.org ยท ๐ via arXiv cs.CR
-
Domain Decoupling Attack exploits DNS validation gap in CDN and shared hosting
Researchers discovered a Domain Decoupling Attack exploiting DNS-based authorization gaps in shared hosting.- Applies to CDN and non-CDN shared hosting environments with shared edge IP addresses
- Vulnerability arises from DNS-based authorization where allowed domain permissions apply to shared IPs
- Attack resolves an allowed domain to gain permission for a shared IP, then connects using a hidden domain
- Uses consistent TLS SNI and HTTP Host headers to evade detection and access other tenants
- Measurements show high exposure rates: 95.8% overall, 99.26% for CDN domains, 92.75% for non-CDN domains
๐ Coverage: arxiv.org ยท ๐ Original: arxiv.org ยท ๐ via arXiv cs.CR
๐ CVEs & KEV
- CVE-2026-56846 โ CVSS 7.5 โ A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks eva...
- CVE-2026-6837 โ CVSS 7.2 โ A post-authentication command injection vulnerability in the "export-cgi" CGI...
- CVE-2026-8508 โ CVSS 6.5 โ An improper authentication vulnerability in the "social_login.cgi" CGI progra...
- CVE-2026-18719 โ CVSS 6.3 โ cemtan sar2html Search sar2html.py sql injectionA vulnerability was detected ...
- CVE-2026-58045 โ CVSS 6.2 โ A flaw in Node.js allows a spoofed
TypedArraybyteLengthto trigger a rea... - CVE-2026-58042 โ CVSS 5.9 โ A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When ...
- CVE-2026-18720 โ CVSS 5.3 โ kalcaddle kodbox msgWarning Plugin action improper authorizationA flaw has be...
- CVE-2026-58041 โ CVSS 5.3 โ A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created th...
- CVE-2026-17614 โ CVSS 4.4 โ Wildfly-core: path traversal on wildfly domain controllerA path traversal fla...
- CVE-2026-58044 โ CVSS 3.7 โ A flaw in Node.js HTTP client can cause a request desynchronization for Node....
- CVE-2026-56845 โ CVSS โ โ An unauthenticated path traversal (LFI) vulnerability exists under /custom-so...