50개 이상의 MCP 서버 분석을 통한 고위험 보안 취약점 식별 및 AIVSS 기반 정량 분석
We scanned 50+ MCP servers and found HIGH-severity bugs in Atlassian, GitHub, Cloudflare, and Microsoft — here's what we learned
We scanned 50+ MCP servers and found HIGH-severity bugs in Atlassian, GitHub, Cloudflare, and Microsoft — here's what we learned
React 및 Next.js 내 12건의 보안 취약점 발견 및 즉시 패치 권고
Stop Pre-Generating Image Thumbnails in Laravel — Do It On-The-Fly Instead
Your AI Assistant is Gullible: Building a "Semantic Airgap" for Gmail Connectors
From a Single IP to Exfiltrated Passwords in a PNG: My First Freelance Pentest Engagement
GHSA-C4QG-J8JG-42Q5: GHSA-C4QG-J8JG-42Q5: Server-Side Request Forgery in OpenClaw QQBot Extension
Most webhook security guides protect the wrong side. The scary part is delivery.
I Spent a Week Securing Webhook Ingestion. The Real Attack Surface Was Delivery.
Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now
Hardening an Express API: URL Validation, Error Handling, and Tests in One Session
MCP Security Vulnerabilities in 2026: Command Injection, SSRF & Mitigation Strategies
I Built This Tool With Three AIs at Once — Claude, Gemini, and Copilot
7 MCP Server Vulnerabilities That Can Compromise Your Claude Code Session
7 Full-Stack Security Audit Challenges: Can You Find All the Bugs?
CVE-2026-32279: CVE-2026-32279: Server-Side Request Forgery in Connect-CMS External Page Migration