<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Elmoz Research</title>
  <link>https://elmoz.de/blog/</link>
  <atom:link href="https://elmoz.de/feed.xml" rel="self" type="application/rss+xml"/>
  <description>Teardowns and guides on AI agent and non-human identity security.</description>
  <language>en</language>
  <item><title>The Vercel breach was an attack path, not a vulnerability.</title><link>https://elmoz.de/blog/vercel-breach-ai-oauth-attack-path</link><guid>https://elmoz.de/blog/vercel-breach-ai-oauth-attack-path</guid><pubDate>Sun, 27 Sep 2026 08:00:00 +0000</pubDate><description>The 2026 Vercel breach started with an AI tool&#x27;s OAuth token. We trace the attack path step by step and show where it could have been broken.</description></item>
  <item><title>Autonomous AI agents breached online retailers for about $25 a company.</title><link>https://elmoz.de/blog/autonomous-ai-agents-25-per-company</link><guid>https://elmoz.de/blog/autonomous-ai-agents-25-per-company</guid><pubDate>Sat, 26 Sep 2026 08:00:00 +0000</pubDate><description>Gambit recovered the staging server of an AI-run campaign against online retailers. At least 27 companies, 600,000 card records, about 25 dollars a target.</description></item>
  <item><title>Coding agent sandbox escapes: a checklist after the Codex research.</title><link>https://elmoz.de/blog/coding-agent-sandbox-escape-checklist</link><guid>https://elmoz.de/blog/coding-agent-sandbox-escape-checklist</guid><pubDate>Thu, 24 Sep 2026 08:00:00 +0000</pubDate><description>Accomplish escaped the OpenAI Codex sandbox twice, once out of read-only mode. Use this checklist to review what your coding agents can reach.</description></item>
  <item><title>Spain logged the first breach notification where the attacker was an AI agent.</title><link>https://elmoz.de/blog/first-ai-agent-breach-notification-aepd</link><guid>https://elmoz.de/blog/first-ai-agent-breach-notification-aepd</guid><pubDate>Mon, 21 Sep 2026 08:00:00 +0000</pubDate><description>Spain's AEPD logged its first breach notification naming an autonomous AI agent. The agent logged in before it found the flaw. Trace the path and what to check.</description></item>
  <item><title>Three of OpenAI’s six new incidents are access problems, not alignment problems.</title><link>https://elmoz.de/blog/openai-agent-incidents-access-not-alignment</link><guid>https://elmoz.de/blog/openai-agent-incidents-access-not-alignment</guid><pubDate>Fri, 18 Sep 2026 08:00:00 +0000</pubDate><description>OpenAI disclosed six new model incidents. Three are access findings: leaked API keys, an internal artifact store, public file hosts. Trace the reach.</description></item>
  <item><title>AI agents breached 395 organisations. A service account opened the domain.</title><link>https://elmoz.de/blog/papercut-ai-agents-service-account-domain-admin</link><guid>https://elmoz.de/blog/papercut-ai-agents-service-account-domain-admin</guid><pubDate>Thu, 17 Sep 2026 08:00:00 +0000</pubDate><description>GreyNoise and Blackpoint traced an AI-run campaign against PaperCut servers. Follow the path from one unauthenticated request to Domain Admins.</description></item>
  <item><title>Infostealer logs are full of AI session tokens that replay past MFA.</title><link>https://elmoz.de/blog/ai-session-tokens-replay-past-mfa</link><guid>https://elmoz.de/blog/ai-session-tokens-replay-past-mfa</guid><pubDate>Wed, 16 Sep 2026 08:00:00 +0000</pubDate><description>Okta found replayable AI session tokens and working API keys in a free infostealer dump. Trace the path from an infected laptop to your AI accounts.</description></item>
  <item><title>GitSpawn: one line in .git/config runs code in seven AI coding agents.</title><link>https://elmoz.de/blog/gitspawn-git-config-ai-coding-agents</link><guid>https://elmoz.de/blog/gitspawn-git-config-ai-coding-agents</guid><pubDate>Fri, 11 Sep 2026 08:00:00 +0000</pubDate><description>GitSpawn lets a repository’s .git/config run code in Claude Code, Codex, Cursor and four other AI coding agents. The attack path, patch status and checks.</description></item>
  <item><title>AI agents in OT and KRITIS: a security checklist for operators.</title><link>https://elmoz.de/blog/ai-agents-in-kritis</link><guid>https://elmoz.de/blog/ai-agents-in-kritis</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>Deploy AI agents in critical infrastructure with clear ownership, scoped access, logging and human oversight. Six security measures for OT and KRITIS operators.</description></item>
  <item><title>MCP security: risks and a 12-point hardening checklist.</title><link>https://elmoz.de/blog/mcp-security-guide</link><guid>https://elmoz.de/blog/mcp-security-guide</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>Secure Model Context Protocol servers against prompt injection, tool poisoning and credential misuse. A practical 12-point MCP security checklist.</description></item>
  <item><title>NIS2 reporting for AI agent incidents: when the 24-hour deadline applies.</title><link>https://elmoz.de/blog/nis2-reporting-ai-agent-incidents</link><guid>https://elmoz.de/blog/nis2-reporting-ai-agent-incidents</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>When is an AI agent incident reportable under NIS2 in Germany? Review the significance threshold, 24-hour and 72-hour deadlines, and evidence to collect.</description></item>
  <item><title>AI-assisted attacks on critical infrastructure: evidence and security lessons.</title><link>https://elmoz.de/blog/ai-agents-critical-infrastructure-2026</link><guid>https://elmoz.de/blog/ai-agents-critical-infrastructure-2026</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>Separate documented AI-assisted OT attacks from claims of autonomous attacks. Review incident evidence, access risks and priorities for infrastructure operators.</description></item>
  <item><title>Non-human identity security: risks, controls and a practical plan.</title><link>https://elmoz.de/blog/non-human-identities-nhi-security-2026</link><guid>https://elmoz.de/blog/non-human-identities-nhi-security-2026</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>What are non-human identities? Learn how to secure service accounts, API keys and AI agents, evaluate NHI security tools, and reduce access to sensitive data.</description></item>
  <item><title>Cursor deleted the PocketOS database on Railway. How did it get access?</title><link>https://elmoz.de/blog/cursor-deleted-production-database-railway-pocketos</link><guid>https://elmoz.de/blog/cursor-deleted-production-database-railway-pocketos</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>How a Cursor agent reached the PocketOS production database through a Railway API token, what Railway changed, and the access controls to review.</description></item>
  <item><title>The Salesloft Drift breach: how stolen OAuth tokens exposed Salesforce data.</title><link>https://elmoz.de/blog/salesloft-drift-oauth-breach-700-companies</link><guid>https://elmoz.de/blog/salesloft-drift-oauth-breach-700-companies</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>How stolen Salesloft Drift OAuth tokens enabled Salesforce data theft. Trace the access path and review token scope, stored secrets and revocation.</description></item>
  <item><title>JADEPUFFER ransomware: tracing the agentic attack path.</title><link>https://elmoz.de/blog/jadepuffer-first-agentic-ransomware</link><guid>https://elmoz.de/blog/jadepuffer-first-agentic-ransomware</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>Examine Sysdig’s JADEPUFFER research: Langflow exploitation, credential theft and database extortion, with lessons for non-human identity security.</description></item>
  <item><title>The Nx s1ngularity attack: how malware targeted AI coding CLIs.</title><link>https://elmoz.de/blog/s1ngularity-nx-supply-chain-ai-cli-attack</link><guid>https://elmoz.de/blog/s1ngularity-nx-supply-chain-ai-cli-attack</guid><pubDate>Tue, 08 Sep 2026 08:00:00 +0000</pubDate><description>How the Nx s1ngularity supply-chain attack targeted AI coding CLIs and developer credentials. Review the access path and controls that limit exposure.</description></item>
</channel>
</rss>
