The Lab · 2026-03-31 08:27:09 · GitHub Issues
A critical security verification gap has been identified in the `verify-mcp.ts` tool used to audit Model Context Protocol (MCP) servers. The tool currently probes for unauthenticated access to the `resources/list` endpoint across all transport paths—SSE, Streamable HTTP, and stdio—and flags it as a high-severity findin...
The Lab · 2026-04-11 16:22:32 · GitHub Issues
A critical security flaw in the popular software composition analysis tool cdxgen has been exposed, revealing a pathway for attackers to exfiltrate sensitive keys and data. The vulnerability, which centers on the tool's handling of YAML and JSON configuration files, allows maliciously crafted scripts to leverage the `s...
The Lab · 2026-05-13 11:48:23 · The Hacker News Echo RSS
Cybersecurity researchers have identified a targeted campaign dubbed GemStuffer that has weaponized the RubyGems package registry as a covert data exfiltration channel, compromising more than 150 gems in an operation distinct from typical software supply chain attacks. The campaign's objective is not mass developer com...