Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

47 articles
138 topics
RSS Feed
CVE-2026-69240: Sequelize Oracle Dialect Allows SQL Injection via TO_TIMESTAMP Escape Bypass (CVSS 9.8)
cvesecurityvulnerability

CVE-2026-69240: Sequelize Oracle Dialect Allows SQL Injection via TO_TIMESTAMP Escape Bypass (CVSS 9.8)

Sequelize versions before 6.37.4 fail to escape single quotes for string values starting with TO_TIMESTAMP or TO_DATE when using the Oracle dialect. An attacker can inject arbitrary SQL through any application value that reaches this escape path.

HOL GuardAug 4, 2026
cvesecurity

CVE-2026-69240: Sequelize Oracle Dialect SQL Injection (CVSS 9.8)

SQL injection in Sequelize Oracle dialect via TO_TIMESTAMP escape bypass. Fixed in 6.37.4.

HOL Guard
Aug 4, 2026
cvesecurity

CVE-2026-38447: osTicket Generates Predictable API Keys via MD5 Hashing (CVSS 9.8)

osTicket 1.18.3 generates API keys using MD5 with predictable inputs (timestamp and client IP). An attacker can approximate the key generation time and brute-force the key space. Affects 5 million+ users and 15,000+ businesses worldwide.

HOL Guard
Aug 4, 2026
cvesecurity

CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)

Net::SAML2 before 0.86 accepts decrypted SAML assertions that carry no XML signature. Any party can encrypt an unsigned assertion to an SP's published certificate and authenticate as an arbitrary user. Affects Azure AD, Okta, Google, ADFS, and all other IdPs.

HOL Guard
Aug 4, 2026
cvesecurity

CVE-2026-53609: ApostropheCMS Prototype Pollution Leads to Authorization Bypass (CVSS 9.1)

ApostropheCMS's apos.util.set() allows authenticated editors to pollute Object.prototype via patch operators, bypassing authorization on all REST API endpoints for subsequent unauthenticated requests. CVSS 9.1. Fixed in version 4.31.0.

HOL Guard
Aug 3, 2026
cvesecurity

CVE-2026-52855: Pterodactyl Wings Leaks Daemon Configuration Secrets via Egg Templates (CVSS 9.9)

Pterodactyl Wings exposes its entire daemon configuration through egg configuration-file templating, leaking API keys, SFTP credentials, and database connection strings. CVSS 9.9. Fixed in version 1.12.3.

HOL Guard
Aug 3, 2026
pluginsplori

Introducing plori

A maintainer's guide to the plori plugin: what it does, who it helps, and how it pairs with Guard.

liu170045
Jul 29, 2026
AI AgentsDeveloper Tools

CIGAR: A Governed Context Runtime for AI Agents

CIGAR Honey is an open-source runtime for compiling governed, policy-aware context for AI agents. It creates bounded context bundles with provenance, authorization, replayable evidence, scoped handoffs, and intent-first external actions.

patches
Jul 28, 2026
HOL GuardAI security

HOL Guard 2.1: 51,000 Test Cases, HMAC-Backed Reconnect, and a New Command Classification Engine

HOL Guard 2.1 ships a 51,000-case command classification corpus, HMAC-backed dashboard reconnect, signed Codex hook manifests, DNS-pinned archive downloads, and a typed GitHub capability model — all open source, canary-tested on TestPyPI.

Michael Kantor
Jul 27, 2026
MCPAI security

MCP Tool Poisoning: How the AI Agent Protocol Became a Supply Chain Attack Surface

The MCP protocol connects AI agents to over 10,000 tools. It also creates a new supply chain attack surface: poisoned tool descriptions that silently hijack agent behavior. Here's the data, the CVEs, and what to do.

HOL
Jul 21, 2026
prompt injectionAI security

Prompt Injection Defense in 2026: What Actually Works When Detection Is Impossible

OpenAI says perfect prompt injection detection is still unsolved. Three academic proofs show why it may never be possible. This is the defense-in-depth architecture that actually works in 2026.

HOL
Jul 21, 2026
slopsquattingsupply chain

Slopsquatting: When AI Hallucinations Become Supply Chain Attacks

AI coding assistants hallucinate package names 19.7% of the time. Attackers register those names on npm and PyPI before real packages can claim them. Tens of thousands of developers have already installed malicious packages their AI suggested. Here is how the attack works, what the research shows, and how to stop your team from becoming the next victim.

HOL
Jul 21, 2026
skills registryregistry broker

Skill Release: registry-broker 1.0.0

New registry-broker 1.0.0 release in the HOL Skills Registry. Search, resolve, register, and communicate with 76,000+ AI agents across 15 registries via the Hashgraph Online Registry Broker API, with cross-registry disco

HOL Registry
Jun 14, 2026
1 / 4