Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

124 articles
348 topics
RSS Feed
Apple CoreGraphics file OOB write hits CISA KEV
cveappleios

Apple CoreGraphics file OOB write hits CISA KEV

How to fix CVE-2026-86950: update to iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1

HOL GuardSep 29, 2026
hol guardguard extensions

Claude Code approved itself: Guard paused the self-click

Claude Code hit a warning, then ran hol-guard approvals approve on itself. HOL Guard froze it. Inbox: Allow just this once or Keep blocked.

HOL Guard
Sep 29, 2026
cveunsloth

Unsloth RCE: malicious Hugging Face model config.json injects code

How to fix CVE-2026-93348: upgrade unsloth-zoo to 2026.8.14+ and unsloth to 2026.8.20+

HOL Guard
Sep 28, 2026
cvenetscaler

BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)

How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23

HOL Guard
Sep 27, 2026
cvewordpress

WordPress page template include hits CISA KEV

How to fix CVE-2026-87902: upgrade WordPress to 7.1.2 (or your branch patch).

HOL Guard
Sep 25, 2026
cvesharepoint

SharePoint code injection hits CISA KEV

How to fix CVE-2026-65660: upgrade SharePoint Server to the August 2026 fixed builds (SE 16.0.19725.20522 / 2019 16.0.10417.20198 / 2016 16.0.5565.1001)

HOL Guard
Sep 25, 2026
cveadobe commerce

Magento incorrect authorization hits CISA KEV

How to fix CVE-2026-71362: upgrade Adobe Commerce and Magento Open Source to the matching *-2026-aug security train (or APSB26-92 Isolated patch)

HOL Guard
Sep 24, 2026
cvef5

F5 BIG-IP APM OAuth RCE hits CISA KEV

How to fix CVE-2026-94127: install F5 Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, 17.5.1.9.0.160.12-ENG, or 17.1.3.5.0.41.14-ENG for your train

HOL Guard
Sep 22, 2026
ghsacve

BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)

How to fix CVE-2026-94545: upgrade next to 16.3.6 (15.5.26 hardening if you stay on 15.x)

HOL Guard
Sep 22, 2026
cveerlang

Your Erlang TLS 1.3 client can trust a server with no certificate

How to fix CVE-2026-89422: upgrade Erlang/OTP to 29.1.1, 28.5.0.7, or 27.3.4.18

HOL Guard
Sep 22, 2026
cvetemporal

Temporal write access can run shell on your Worker Service host

How to fix CVE-2026-89139: upgrade Temporal Server to 1.31.3 or 1.30.7

HOL Guard
Sep 21, 2026
cveopenshift

BREAKING: OpenShift console Devfile API lets anyone SSRF your cluster

How to fix CVE-2026-75885: upgrade OpenShift console when Red Hat ships the errata

HOL Guard
Sep 18, 2026
cvewordpress

BREAKING: WordPress comment XSS lets strangers plant script (7.1.1)

How to fix CVE-2026-93485: upgrade WordPress to 7.1.1

HOL Guard
Sep 18, 2026
1 / 11

HOL Guard research desk

Security research for the AI agent era

Threat guides and evidence dossiers on prompt injection, MCP tool poisoning, slopsquatting, and the attacks shaping how teams ship code with agents.

Explore the security hub