TECH.
FOR.
HUMANS.
Your AI Gateway Is Holding All the Keys
The LiteLLM vulnerability chain is not just another proxy bug. AI gateways sit between users, models, provider keys, stored credentials, and prompt logs. Treat them like production security infrastructure.
I write about security, privacy, and AI — the stuff that matters but rarely gets explained well. Practical, opinionated, honest.
No fear-mongering. No affiliate tax. Just the plain-English version.
LATEST
78 articles and counting. Newest first.
Section 702 Expired. Do Not Trade It Back for Nothing.
EFF says Section 702 expired on June 12 after Congress failed to renew it. The next fight is whether warrantless backdoor searches come back under a different deadline.
Your AI Report Needs a Receipt Drawer
KPMG pulled an AI usage report after apparent hallucinations. EFF keeps finding fake staff quoted by AI slop sites. The fix is boring: citations, owners, and a human who checks the receipts.
Your AUR Helper Is Not a Trust Boundary
The Arch User Repository hijack is a reminder that developer package feeds are not harmless convenience. Build scripts run code, and abandoned packages inherit trust too easily.
The AI Act Is Being Weakened Before It Starts
EDRi says the EU AI Omnibus would delay high-risk AI safeguards and reduce public transparency. That is not boring Brussels plumbing. It is where accountability disappears.
AI Builders Are Production Servers Now
Langflow exploitation is a reminder that low-code AI builders, agent frameworks, and model gateways are not experiments once they touch the internet. They are production attack surface.
The Schema Was Not Supposed to Run Code
Six protobuf.js bugs are a useful warning for Node teams: parsers, schemas, and generated code are now part of your execution boundary. Treat them that way.
- highCisco Patches Actively Exploited Catalyst SD-WAN Manager File-Write FlawThe Hacker News / Cisco / CISAJun 16
- highCISA Flags Exploited LiteSpeed cPanel Plugin Root EscalationThe Hacker News / CISAJun 16
- mediumEU Cybersecurity Act 2.0 Debate Raises Geopolitics-versus-Evidence RiskHelp Net SecurityJun 16
- criticalLiteLLM Chain Lets Low-Privilege Users Take Over AI Gateway ServersThe Hacker News / Obsidian SecurityJun 15