Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

113 articles
311 topics
RSS Feed
BREAKING: OpenShift console Devfile API lets anyone SSRF your cluster
cveopenshiftssrf

BREAKING: OpenShift console Devfile API lets anyone SSRF your cluster

How to fix CVE-2026-75885: upgrade OpenShift console when Red Hat ships the errata

HOL GuardSep 18, 2026
cvewordpress

BREAKING: WordPress comment XSS lets strangers plant script (7.1.1)

How to fix CVE-2026-93485: upgrade WordPress to 7.1.1

HOL Guard
Sep 18, 2026
cvemulter

Aborted multer uploads still fill the disk after the 5038 fix

How to fix CVE-2026-88932: upgrade multer to 2.4.0

HOL Guard
Sep 16, 2026
cveunbound

BREAKING: Unbound DNSKEY digest overflow can RCE your resolver (1.26.1)

How to fix CVE-2026-81642: upgrade Unbound to 1.26.1

HOL Guard
Sep 16, 2026
hol guardguard extensions

Hidden command in Claude Code: base64 piped to sh

Chat looked short. Claude Code packed a hidden command in base64 and piped decode to sh. HOL Guard froze it. Inbox: Allow just this once or Keep blocked.

HOL Guard
Sep 15, 2026

Keep a Codex Task on Track Through Compaction with Context Guard

A practical Context Guard walkthrough: define requirements, compact a Codex task, recover the checklist, and verify the finished document.

lgr5945
Sep 12, 2026
cvescreenconnect

ScreenConnect client file runs hit CISA KEV

How to fix CVE-2026-84869: upgrade ScreenConnect to 26.6.5 or later, then reinstall host clients and update access agents

HOL Guard
Sep 11, 2026
cvegitlab

Self-managed GitLab: unauth commits API file read hits CISA KEV

How to fix CVE-2026-85706: upgrade GitLab to 19.1.8 / 19.2.6 / 19.3.2

HOL Guard
Sep 11, 2026
hol guardguard extensions

Your agent tried to ship your AWS keys

You left Claude Code running. It tried to send your AWS keys to a website you never opened. Guard froze it: Allow just this once, or Keep blocked.

HOL Guard
Sep 11, 2026
cvejfrog

Artifactory anonymous token chain hits CISA KEV

How to fix CVE-2026-42018 / CVE-2026-42016: upgrade self-hosted Artifactory past the anonymous-JWT and token-scope floors (prefer 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20)

Hashgraph Online
Sep 11, 2026
cveheadroom

CVE-2026-71416: Headroom WebSocket proxy spends your OpenAI key for any reachable browser

How to fix CVE-2026-71416: upgrade headroom-ai to 0.35.0

HOL Guard
Sep 11, 2026
cvecompression

CVE-2026-87776: Express compression leaks native memory until the process dies

How to fix CVE-2026-87776: upgrade compression to 1.8.2

HOL Guard
Sep 11, 2026
cveapache artemis

CVE-2026-57967: unauth Artemis CORE session steal and OpenWire queue delete

How to fix CVE-2026-57967: upgrade Apache Artemis / ActiveMQ Artemis to 2.57.0. Unauth CORE SESSION_REATTACH can steal a live session; OpenWire RemoveSubscriptionInfo can delete queues before auth.

HOL Guard
Sep 10, 2026
1 / 10

HOL Guard research desk

Security research for the AI agent era

Threat guides and evidence dossiers on prompt injection, MCP tool poisoning, slopsquatting, and the attacks shaping how teams ship code with agents.

Explore the security hub