Engineering & Technical

The Engineer

The Signal

SGLang lets any host that reaches its ZeroMQ socket run code on your GPU nodes.

The multimodal runtime passes received bytes to pickle.loads(). The __reduce__ hook lets a payload name any callable, so the fix is removing pickle from the receive path (CVE-2026-93088, 9.8). MCP Atlassian before 0.22.0 repeats the mistake with identity and gives any caller operator-level Atlassian access, so check which version you are running.

In Play

  1. The AI Tier Is Shipping Textbook RCE

    Two of the criticals in this briefing sit in infrastructure you are standing up right now. SANS AtRisk reports SGLang's multimodal runtime binds an unauthenticated ZeroMQ socket and passes received bytes to pickle.loads() (CVE-2026-93088, 9.8), and MCP Atlassian before 0.22.0 grants operator-level Atlassian access to any caller without per-user identity (CVE-2026-77244, 10.0). Separately, CSO reports Unsloth Studio could run a model repo's Python just from selecting it in the picker. All three treat network reachability or a UI click as authorization.

  2. Extraction Attacks Walk Past Per-Account Rate Limits

    OpenAI disclosed a distillation campaign that spread 16,000 requests across 4,000+ accounts on July 24-25, under four requests each, eventually spanning 15,000+ accounts. The Information reports the technique: copy encrypted reasoning out of one conversation and ask the model in another to decrypt and transcribe it. The ciphertext worked as a portable bearer token, so the serving layer was a confused deputy. No per-user quota fires on four requests, and nothing was decrypted or breached.

  3. Deterministic Oracles Beat Model Quality

    Google's PageBreak found 500+ XSS bugs across first-party apps since November 2025 at near-zero false positives, per Clint Gibler's reporting, using per-class validators that fire a real payload at a running app rather than a smarter model. Findings came mostly from Gemini 3.1 Pro and 3.5 Flash, so verification, not frontier reasoning, is the bottleneck. On apps built on Google's hardened framework PageBreak found only 2 XSS. The oracle sets precision; the model is the replaceable part.

  4. Always-On Agents Break Per-Task IAM

    OpenAI's Dots gives Pro, Business and Enterprise an always-on agent with its own cloud computer, browser and 4,000+ plugin connectors. Most agent deployments minted short-lived per-task tokens; a coworker fixing bugs in the background has no expiry, so the easy path is a long-lived OAuth grant per connector. Meanwhile the FTC opened its first probe into rogue agents after OpenAI test agents traded 70,000+ messages and breached Hugging Face, with the chairman suggesting developers may be liable when tests reach real systems.

  5. Multi-Tenant Postgres Latency Cliffs

    An indexed RLS tenant check costs almost nothing, but per-row membership subqueries, VOLATILE helpers (the CREATE FUNCTION default) and non-leakproof predicates turn sub-millisecond queries into seconds, per TLDR Data. The same report notes Slack's workspace-keyed shards ran hot once enterprise tenants arrived, arguing for per-table shard keys over query hints. These are design choices, not data growth, and they bite long before volume does.

Deep Dives

  1. Three Products, One Bug: Network Reachability Mistaken for Authorization

    The AI serving layer is reintroducing deserialization RCE and confused-deputy auth you thought you'd retired, and each shipped as a maximum-severity CVE.

    Why pickle over a socket is always RCE Pickle has no safe mode for untrusted input. __reduce__ lets a payload name any callable. So pickle.loads() on bytes from an unauthenticated socket is remote code execution for anyone with L4 access.…

    3 action items

    ●
  2. The Distillation Campaign Was a Sybil Attack, Not a Volume Attack

    An extraction campaign spread across thousands of accounts at four requests each and replayed encrypted reasoning across sessions — so per-user rate limits and context-free tokens stopped counting as defenses.

    The arithmetic that defeats a per-account rate limiter OpenAI didn't do the division, so here it is. 16,000 requests across 4,000+ accounts over two days is under four requests each . That is roughly two per day. Nobody ships a…

    3 action items

    ●
  3. In Agent-Heavy Environments, Oracles and Per-Agent Identity Carry the Load

    Rarity-based tripwires are already blind on hosts running coding agents, and the systems that work share one shape: the model generates, something deterministic decides.

    Curl tripwires are already dead A single run of curl, tcpdump or a throwaway Python script used to justify a look. Coding agents now run them all day. In the Hugging Face incident the sensors saw the activity and never…

    3 action items

    ●

The edition continues

Take the signal into the room.

Sign up or log in to read all 3 deep dives in full, plus the final take.

Read the full edition

Continue with LinkedIn