Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

107 articles
302 topics
RSS Feed
ScreenConnect client file runs hit CISA KEV
cvescreenconnectconnectwise

ScreenConnect client file runs hit CISA KEV

How to fix CVE-2026-84869: upgrade ScreenConnect to 26.6.5 or later, then reinstall host clients and update access agents

HOL GuardSep 11, 2026
cvegitlab

Self-managed GitLab: unauth commits API file read hits CISA KEV

How to fix CVE-2026-85706: upgrade GitLab to 19.1.8 / 19.2.6 / 19.3.2

HOL Guard
Sep 11, 2026
hol guardguard extensions

Your agent tried to ship your AWS keys

When an agent posts cloud keys with curl, Guard's command.data-protection Extension pauses it. Inbox shows Allow just this once or Keep blocked. Rehearse with hol-guard command test on a dummy path.

HOL Guard
Sep 11, 2026
cvejfrog

Artifactory anonymous token chain hits CISA KEV

How to fix CVE-2026-42018 / CVE-2026-42016: upgrade self-hosted Artifactory past the anonymous-JWT and token-scope floors (prefer 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20)

Hashgraph Online
Sep 11, 2026
cveheadroom

CVE-2026-71416: Headroom WebSocket proxy spends your OpenAI key for any reachable browser

How to fix CVE-2026-71416: upgrade headroom-ai to 0.35.0

HOL Guard
Sep 11, 2026
cvecompression

CVE-2026-87776: Express compression leaks native memory until the process dies

How to fix CVE-2026-87776: upgrade compression to 1.8.2

HOL Guard
Sep 11, 2026
cveapache artemis

CVE-2026-57967: unauth Artemis CORE session steal and OpenWire queue delete

How to fix CVE-2026-57967: upgrade Apache Artemis / ActiveMQ Artemis to 2.57.0. Unauth CORE SESSION_REATTACH can steal a live session; OpenWire RemoveSubscriptionInfo can delete queues before auth.

HOL Guard
Sep 10, 2026
cvepan os

BREAKING: CVE-2026-0310 PAN-OS XML overflow gives unauth root on PA-Series

How to fix CVE-2026-0310: upgrade PAN-OS to the fixed hotfix for your train (for example 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, 10.2.18-h10). Unauth XML to management web or dataplane can root PA-Series firewalls.

HOL Guard
Sep 10, 2026
cveadobe commerce

CVE-2026-77774: Magento still needs APSB26-138 after the StyleSmuggler hotfix

How to fix CVE-2026-77774: apply Adobe APSB26-138 September Isolated patches (or *-2026-sep builds) after the StyleSmuggler hotfix, then verify with php vendor/bin/patch-status

HOL Guard
Sep 8, 2026
cvefastify cli

CVE-2026-75021: fastify-cli debug-host bind can expose Inspector RCE

How to fix CVE-2026-75021: upgrade fastify-cli to 8.0.1

HOL Guard
Sep 8, 2026
cveadobe commerce

BREAKING: CVE-2026-75650 lets unauth callers run code on Adobe Commerce and Magento

How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 from repo.magento.com, then rotate the Commerce encryption key and every credential it protected

HOL
Sep 7, 2026
cveadobe commerce

BREAKING: CVE-2026-75650 is unauthenticated RCE in Adobe Commerce and Magento, already exploited

How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 for Adobe Commerce / Magento Open Source, then rotate the encryption key and all protected credentials

HOL
Sep 7, 2026
hol guardguard 3

HOL Guard 3.0: Rust authority, extension-first controls, honest harness contracts

HOL Guard 3.0 puts PreToolUse on a version-matched Rust path with no Python semantic fallback, makes Local Extensions the capability vocabulary for managed-restrictive Control Sets, and keeps sync paused from meaning unprotected. Pin tip 3.0.113; do not pin yanked 3.0.0.

HOL Guard
Sep 7, 2026
1 / 9

HOL Guard research desk

Security research for the AI agent era

Threat guides and evidence dossiers on prompt injection, MCP tool poisoning, slopsquatting, and the attacks shaping how teams ship code with agents.

Explore the security hub