Aggregator
Kong launches Context Mesh to turn enterprise APIs into agent-ready tools
Kong has announced Kong Context Mesh, a product that automatically discovers enterprise APIs, transforms them into agent-consumable tools, and deploys them with runtime governance. “Organisations have spent years building APIs as the nervous system of the enterprise. Context Mesh allows them to reuse that investment to power agents instead of starting from scratch,” said Marco Palladino, CTO of Kong. “The challenge is that agents are only as good as the enterprise context they can reach. … More →
The post Kong launches Context Mesh to turn enterprise APIs into agent-ready tools appeared first on Help Net Security.
Qilin
You must login to view this content
Запихнуть торнадо в процессор: мега-симуляция турбулентности объяснила, почему глохнут двигатели и откуда берутся торнадо
Top Cyber Industry Defenses Spike CO2 Emissions
UofTCTF 2026 部分wp
FDA 拒绝审核 Moderna 的 mRNA 流感疫苗
«Я не я, и база не моя» больше не работает. Верховный суд разъяснил: за данные отвечает тот, кто их собрал
美国西北大学 | PentestAgent:将LLM代理融入自动化渗透测试
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
GOP Congress moves to shape election law in Trump’s image
The MEGA Act and SAVE Act would dramatically transform U.S. election laws in a quest to curb election fraud. Audits and experts say improprieties are extremely rare.
The post GOP Congress moves to shape election law in Trump’s image appeared first on CyberScoop.
Adobe security advisory (AV26-115)
Google Chrome 145 重新加入对 JPEG-XL 图像的支持
GitGuardian Raises $50M Series C to Address Non-Human Identities Crisis and AI Agent Security Gap
Google сам ищет ваши нюдсы (чтобы их спрятать). Теперь выдача автоматически зачищается от слитых фото и паспортов
NetBSD 11.0 RC1 释出
Observing the Anatomy of Peak Traffic
Scary Agent Skills: Hidden Unicode Instructions in Skills ...And How To Catch Them
There is a lot of talk about Skills recently, both in terms of capabilities and security concerns. However, so far I haven’t seen anyone bring up hidden prompt injection. So, I figured to demo a Skills supply chain backdoor that survives human review.
Additionally, I also built a basic scanner, and had my agent propose updates to OpenClaw to catch such attacks.
Attack SurfaceSkills introduce common threats, like prompt injection, supply chain attacks, RCE, data exfiltration,… This post discusses some basics, highlights the most simple prompt injection avenue, and shows how one can backdoor a real Skill from OpenAI with invisible Unicode Tag codepoints that certain models, like Gemini, Claude, Grok are known to interpret as instructions.