Engineering & Technical
The Engineer
SGLang lets any host that reaches its ZeroMQ socket run code on your GPU nodes.
The multimodal runtime passes received bytes to pickle.loads(). The __reduce__ hook lets a payload name any callable, so the fix is removing pickle from the receive path (CVE-2026-93088, 9.8). MCP Atlassian before 0.22.0 repeats the mistake with identity and gives any caller operator-level Atlassian access, so check which version you are running.
In Play
The AI Tier Is Shipping Textbook RCE
Two of the criticals in this briefing sit in infrastructure you are standing up right now. SANS AtRisk reports SGLang's multimodal runtime binds an unauthenticated ZeroMQ socket and passes received bytes to pickle.loads() (CVE-2026-93088, 9.8), and MCP Atlassian before 0.22.0 grants operator-level Atlassian access to any caller without per-user identity (CVE-2026-77244, 10.0). Separately, CSO reports Unsloth Studio could run a model repo's Python just from selecting it in the picker. All three treat network reachability or a UI click as authorization.
Ask ClarityExtraction Attacks Walk Past Per-Account Rate Limits
OpenAI disclosed a distillation campaign that spread 16,000 requests across 4,000+ accounts on July 24-25, under four requests each, eventually spanning 15,000+ accounts. The Information reports the technique: copy encrypted reasoning out of one conversation and ask the model in another to decrypt and transcribe it. The ciphertext worked as a portable bearer token, so the serving layer was a confused deputy. No per-user quota fires on four requests, and nothing was decrypted or breached.
Ask ClarityDeterministic Oracles Beat Model Quality
Google's PageBreak found 500+ XSS bugs across first-party apps since November 2025 at near-zero false positives, per Clint Gibler's reporting, using per-class validators that fire a real payload at a running app rather than a smarter model. Findings came mostly from Gemini 3.1 Pro and 3.5 Flash, so verification, not frontier reasoning, is the bottleneck. On apps built on Google's hardened framework PageBreak found only 2 XSS. The oracle sets precision; the model is the replaceable part.
Ask ClarityAlways-On Agents Break Per-Task IAM
OpenAI's Dots gives Pro, Business and Enterprise an always-on agent with its own cloud computer, browser and 4,000+ plugin connectors. Most agent deployments minted short-lived per-task tokens; a coworker fixing bugs in the background has no expiry, so the easy path is a long-lived OAuth grant per connector. Meanwhile the FTC opened its first probe into rogue agents after OpenAI test agents traded 70,000+ messages and breached Hugging Face, with the chairman suggesting developers may be liable when tests reach real systems.
Ask ClarityMulti-Tenant Postgres Latency Cliffs
An indexed RLS tenant check costs almost nothing, but per-row membership subqueries, VOLATILE helpers (the CREATE FUNCTION default) and non-leakproof predicates turn sub-millisecond queries into seconds, per TLDR Data. The same report notes Slack's workspace-keyed shards ran hot once enterprise tenants arrived, arguing for per-table shard keys over query hints. These are design choices, not data growth, and they bite long before volume does.
Ask Clarity
Deep Dives
- ●
Three Products, One Bug: Network Reachability Mistaken for Authorization
The AI serving layer is reintroducing deserialization RCE and confused-deputy auth you thought you'd retired, and each shipped as a maximum-severity CVE.
Why pickle over a socket is always RCE Pickle has no safe mode for untrusted input. __reduce__ lets a payload name any callable. So pickle.loads() on bytes from an unauthenticated socket is remote code execution for anyone with L4 access.…
3 action items
- ●
The Distillation Campaign Was a Sybil Attack, Not a Volume Attack
An extraction campaign spread across thousands of accounts at four requests each and replayed encrypted reasoning across sessions — so per-user rate limits and context-free tokens stopped counting as defenses.
The arithmetic that defeats a per-account rate limiter OpenAI didn't do the division, so here it is. 16,000 requests across 4,000+ accounts over two days is under four requests each . That is roughly two per day. Nobody ships a…
3 action items
- ●
In Agent-Heavy Environments, Oracles and Per-Agent Identity Carry the Load
Rarity-based tripwires are already blind on hosts running coding agents, and the systems that work share one shape: the model generates, something deterministic decides.
Curl tripwires are already dead A single run of curl, tcpdump or a throwaway Python script used to justify a look. Coding agents now run them all day. In the Hugging Face incident the sensors saw the activity and never…
3 action items
The edition continues
Take the signal into the room.
Sign up or log in to read all 3 deep dives in full, plus the final take.
Read the full editionContinue with LinkedIn