Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

117 articles
325 topics
RSS Feed
F5 BIG-IP APM OAuth RCE hits CISA KEV
cvef5big ip

F5 BIG-IP APM OAuth RCE hits CISA KEV

How to fix CVE-2026-94127: install F5 Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, 17.5.1.9.0.160.12-ENG, or 17.1.3.5.0.41.14-ENG for your train

HOL GuardSep 22, 2026
ghsacve

BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)

How to fix CVE-2026-94545: upgrade next to 16.3.6 (15.5.26 hardening if you stay on 15.x)

HOL Guard
Sep 22, 2026
cveerlang

Your Erlang TLS 1.3 client can trust a server with no certificate

How to fix CVE-2026-89422: upgrade Erlang/OTP to 29.1.1, 28.5.0.7, or 27.3.4.18

HOL Guard
Sep 22, 2026
cvetemporal

Temporal write access can run shell on your Worker Service host

How to fix CVE-2026-89139: upgrade Temporal Server to 1.31.3 or 1.30.7

HOL Guard
Sep 21, 2026
cveopenshift

BREAKING: OpenShift console Devfile API lets anyone SSRF your cluster

How to fix CVE-2026-75885: upgrade OpenShift console when Red Hat ships the errata

HOL Guard
Sep 18, 2026
cvewordpress

BREAKING: WordPress comment XSS lets strangers plant script (7.1.1)

How to fix CVE-2026-93485: upgrade WordPress to 7.1.1

HOL Guard
Sep 18, 2026
cvemulter

Aborted multer uploads still fill the disk after the 5038 fix

How to fix CVE-2026-88932: upgrade multer to 2.4.0

HOL Guard
Sep 16, 2026
cveunbound

BREAKING: Unbound DNSKEY digest overflow can RCE your resolver (1.26.1)

How to fix CVE-2026-81642: upgrade Unbound to 1.26.1

HOL Guard
Sep 16, 2026
hol guardguard extensions

Hidden command in Claude Code: base64 piped to sh

Chat looked short. Claude Code packed a hidden command in base64 and piped decode to sh. HOL Guard froze it. Inbox: Allow just this once or Keep blocked.

HOL Guard
Sep 15, 2026

Keep a Codex Task on Track Through Compaction with Context Guard

A practical Context Guard walkthrough: define requirements, compact a Codex task, recover the checklist, and verify the finished document.

lgr5945
Sep 12, 2026
cvescreenconnect

ScreenConnect client file runs hit CISA KEV

How to fix CVE-2026-84869: upgrade ScreenConnect to 26.6.5 or later, then reinstall host clients and update access agents

HOL Guard
Sep 11, 2026
cvegitlab

Self-managed GitLab: unauth commits API file read hits CISA KEV

How to fix CVE-2026-85706: upgrade GitLab to 19.1.8 / 19.2.6 / 19.3.2

HOL Guard
Sep 11, 2026
hol guardguard extensions

Your agent tried to ship your AWS keys

You left Claude Code running. It tried to send your AWS keys to a website you never opened. Guard froze it: Allow just this once, or Keep blocked.

HOL Guard
Sep 11, 2026
1 / 10

HOL Guard research desk

Security research for the AI agent era

Threat guides and evidence dossiers on prompt injection, MCP tool poisoning, slopsquatting, and the attacks shaping how teams ship code with agents.

Explore the security hub