4 posts 2 posts

Explainer

[type] creeta 3-axis IA

Starlette BadHost: CVE-2026-48710 Auth Bypass in AI Agent Stacks

Starlette BadHost (CVE-2026-48710): a crafted Host header bypasses auth middleware. Unproxied AI agents at highest risk.

AI Marketing Claims and FTC Section 5: A Compliance Guide for 2026

The CMG Active Listening case sets the FTC's bar for AI capability and consent claims. What dev teams need to know.

The Real BadHost Risk: MCP Servers, vLLM, and the Proxy Gap

CVSS 6.5 misses the mark. Why MCP servers and proxy-less AI agent stacks face disproportionate exposure from BadHost.

Illinois SB 315 Explained: Who It Covers and What Devs Must Do by 2028

SB 315 passed 110-0. Who the $500M threshold covers, what five obligations apply, and when enforcement starts.

Starlette BadHost: AI 에이전트 스택의 CVE-2026-48710 인증 우회 취약점

Starlette BadHost (CVE-2026-48710): a crafted Host header bypasses auth middleware. Unproxied AI agents at highest risk.

일리노이 SB 315 해설: 적용 대상과 2028년까지 개발자가 해야 할 일

SB 315 passed 110-0. Who the $500M threshold covers, what five obligations apply, and when enforcement starts.