Insights & Research

Vulnerability research, AI security, and field notes on compliance from the team that breaks systems so attackers can't.

Latest

CVE-2026-59822: MCP Authentication Bypass in LiteLLM

LiteLLM's MCP endpoint caught a rejected credential and continued with an anonymous session. The strict check still ran and still failed correctly. Its failure just stopped being terminal.

Andrew Roe·
Read the full story