First reported · updated · 2 reports arxiv.org
Research · latest
First reported equixly.com
How an AI agent talked itself into an XXE — and was right
Equixly describes how its autonomous AI agent, starting only from an OpenAPI specification and low-privileged credentials, identified an XML External Entity (XXE) injection in the chat layer of a collaboration platform, flagged an ordinary-looking JSON message-forward field as an XML sink, and confirmed it out-of-band. The agent then chained the flaw to local file reads and server-side request forgery to exfiltrate a cleartext database credential during a grey-box assessment. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector