Do you plan to display your LED dodecahedron again sometime? Let me know, would love to see it live! :-)
right here, right now.
Posts
The team did some data analysis on CVE-2026-48710 on a sample of 50.000 scanned hosts on the Internet. Spoiler: Lots of API keys are prone to be leaked!
Analysis: https://www.persistent-security.net/post/cve-2026-48710-bad-hosts-in-the-wild
PSA: we had to pause the month of bypasses (http://github.com/persistent-security/month-of-bypasses
) because of the #badhost situation, it will be continued as soon as things calm down!
Important! Using a reverse proxy might not fully protect you from BadHost / CVE-2026-48710 **also this does not only affect AI related infrastructure because FastAPI is also affected and used for various applications!**
While everyone was on Holiday we scanned a few thousand hosts for #BadHost (CVE-2026-48710): zero auth required and we found clinical trial databases, email mailboxes, MCP server for SSH industrial IoT via bastion servers, and live PII APIs wide open. The FastAPI/MCP ecosystem is sitting exposed - patch to Starlette 1.0.1 now and check your exposure at https://badhost.org
Patch Starlette now! If you're run it via uvicorn or other common ASGI servers then a host header parsing issue can lead to vulnerabilities leading from auth bypass up until RCE! Examples for affected packages are liteLLM, vllm, etc... Here is the X41 Advisory:
If AI is taking jobs everywhere and especially in security, why is everyone I currently deal with swamped with work?
26b74a3148a790a887f7e59a93905eea2fa126a917aae28f4a428e8494cdf4d6
Iteration 3: Inject shellcode into winlogon.exe and leak secrets via DNS: https://github.com/persistent-security/month-of-bypasses/blob/main/mob-3-poc-winlogon-clr-injection-dns-exfil.ps1 #mob
POC collection of AI found bypasses / technique variations (updated regularly over the coming weeks): https://github.com/persistent-security/month-of-bypasses