#mitre-d3fend
8 posts

RAG Pipeline Security: Preventing Data Leakage, Poisoning, and Injection in AI Knowledge Bases
A practical guide to securing Retrieval-Augmented Generation pipelines in production — covering knowledge base poisoning, indirect prompt injection, data leakage through vector stores, and access control patterns for SaaS teams.

Weekly AI Cybersecurity News Roundup — July 7–13, 2026
EU launches sweeping AI cybersecurity action plan with Grand Challenge, CISA adds Langflow as first-ever AI agent platform to KEV catalog, Ghostcommit attack hides prompt injection in PNG images to steal code secrets, Accenture confirms 35GB data breach, DHS HSIN network breached, and Anthropic sues Abnormal AI over slash-mark logo trademark dispute.

Malicious Web Bots, Real-World Hacks & Exploit Techniques — July 2026
Malicious bots now exceed 40% of internet traffic, driven by AI variants that mimic human behavior and defeat legacy defenses. This week’s incidents…

CVE-2026-29000: The CVSS 10.0 pac4j-jwt Authentication Bypass That Lets Anyone Become Admin
A critical authentication bypass in pac4j-jwt allows remote attackers to forge admin tokens using only the server's RSA public key. With a CVSS score of 10.0, this vulnerability affects Java applications using pac4j for JWT-based authentication. We examine the root cause, exploitation mechanics, detection strategy, and patch guidance.

API Security for AI-Powered Applications: A Practical Guide
A step-by-step guide to securing APIs in AI-powered applications — covering authentication, rate limiting, OWASP API Top 10 risks, gateway configuration, and monitoring with real-world breach data and config examples.

Secrets Management for AI Pipelines: A Practical Security Guide
A step-by-step guide to securing API keys, tokens, and credentials in AI-powered automation pipelines — covering detection, rotation, vaulting, and CI/CD hardening with real-world incident data.

The 9 Security Fixes Every SaaS Company Needs
Enterprise buyers check these 9 things before signing. Here's what they look for, why it matters, and how to fix each one in under 30 minutes.

Securing the AI Stack: A Practical Guide to Hardening Agent Pipelines
A hands-on guide to securing AI agent pipelines, from API key management to rate limiting and isolation zones — based on real production hardening of a 6-blog AI publishing empire.