Discussion about this post

User's avatar
ToxSec's avatar

“There are no sanitization warnings or roadblocks. An attacker can pass a malicious command, receive a connection error, and walk away with full control of the server.”

great and approachable way to describe this. awesome to see you cover this story!

jaycee's avatar

This is what I was saying long ago. A2A, Zapier, pickle, huggingface, github. All of them are threat vectors. Zero-trust is the way.

4 more comments...

No posts

Ready for more?