⤷ Title: Critical Authentication Bypass Vulnerability Found in Milvus Proxy (CVE-2025-64513, CVSS 9.3)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 00:16:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Authentication Bypass #Critical Vulnerability #CVE_2025_64513 #Milvus #Vector Database
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 00:16:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Authentication Bypass #Critical Vulnerability #CVE_2025_64513 #Milvus #Vector Database
Daily CyberSecurity
Critical Authentication Bypass Vulnerability Found in Milvus Proxy (CVE-2025-64513, CVSS 9.3)
A Critical (CVSS 9.3) Auth Bypass flaw (CVE-2025-64513) in Milvus Proxy allows unauthenticated attackers to gain full administrative control over the vector database cluster. Update to v2.6.5.
⤷ Title: AWS S3 Unleashed: Native Vector Storage & 50 TB Max Object Size for AI/Big Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:06:41 +0000
════════════════════════
⌗ Tags: #Technology #50 TB Object #Amazon S3 Vectors #AWS re:Invent #AWS S3 #big data #Generative AI #Iceberg Tables #RAG #Vector Database
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:06:41 +0000
════════════════════════
⌗ Tags: #Technology #50 TB Object #Amazon S3 Vectors #AWS re:Invent #AWS S3 #big data #Generative AI #Iceberg Tables #RAG #Vector Database
Daily CyberSecurity
AWS S3 Unleashed: Native Vector Storage & 50 TB Max Object Size for AI/Big Data
⤷ Title: AI Data at Risk: Critical Milvus Flaw (CVSS 9.8) Exposes Database via Port 9091
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 00:06:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Critical Vulnerability #Data Breach #DevOps #machine_learning #Milvus #Patch Alert #Port 9091 #rce #Vector Database
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 00:06:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Critical Vulnerability #Data Breach #DevOps #machine_learning #Milvus #Patch Alert #Port 9091 #rce #Vector Database
Daily CyberSecurity
AI Data at Risk: Critical Milvus Flaw (CVSS 9.8) Exposes Database via Port 9091
Critical Milvus flaw (CVSS 9.8) exposes port 9091. Unauthenticated attackers can steal secrets & delete data. Update to v2.5.27 or v2.6.10 immediately.
⤷ Title: Injection Flaws (CVE-2026-40967 & 40978) Hit Spring AI Vector Stores
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 02:39:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CosmosDB #CVE_2026_40967 #CVE_2026_40978 #infosec #Java security #Patch Alert #RAG #Spring AI #sql injection #Vector Database
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 02:39:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CosmosDB #CVE_2026_40967 #CVE_2026_40978 #infosec #Java security #Patch Alert #RAG #Spring AI #sql injection #Vector Database
Daily CyberSecurity
Injection Flaws (CVE-2026-40967 & 40978) Hit Spring AI Vector Stores
Spring AI discloses two critical injection flaws (CVE-2026-40967 & 40978) in Vector Store implementations. Upgrade to v1.0.6 or v1.1.5 now to prevent data leaks.
⤷ Title: Prompt Injection Was Just the Beginning: Real AI Supply Chain Attacks Are Here in 2026
════════════════════════
𐀪 Author: Akansha Shukla
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:07:43 GMT
════════════════════════
⌗ Tags: #vector_database #indirect_prompt_injection #supply_chain_security #api_security #ai_security
════════════════════════
𐀪 Author: Akansha Shukla
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:07:43 GMT
════════════════════════
⌗ Tags: #vector_database #indirect_prompt_injection #supply_chain_security #api_security #ai_security
Medium
Prompt Injection Was Just the Beginning: Real AI Supply Chain Attacks Are Here in 2026
How indirect prompt injection, vector database poisoning, and agentic trust exploits are reshaping enterprise AI security.
⤷ Title: Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 01:45:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ChromaDB #CVE_2026_45829 #Cyber Security #FastAPI #HiddenLayer #Hugging Face #infosec #Machine Learning Security #Pre_Authentication RCE #trust_remote_code #Vector Database
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 01:45:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ChromaDB #CVE_2026_45829 #Cyber Security #FastAPI #HiddenLayer #Hugging Face #infosec #Machine Learning Security #Pre_Authentication RCE #trust_remote_code #Vector Database
Daily CyberSecurity
Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models
Unpatched CVSS 10 flaw (CVE-2026-45829) in ChromaDB allows unauthenticated remote code execution via Hugging Face models. Isolate your servers now!
⤷ Title: ChromaToast Exploit: Unpatched CVSS 10.0 Flaw Grants Pre-Auth RCE in ChromaDB Python Server
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 06:59:37 +0000
════════════════════════
⌗ Tags: #Vulnerability #ChromaDB CVE_2026_45829 #HiddenLayer ChromaToast Research #Hugging Face Model Hijacking #Pre_Authentication Code Injection #Python FastAPI Server Vulnerability #Rust Implementation Mitigation #Shodan Internet Exposure #trust_remote_code Parameter #Unpatched Remote Code Execution #Vector Database Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 06:59:37 +0000
════════════════════════
⌗ Tags: #Vulnerability #ChromaDB CVE_2026_45829 #HiddenLayer ChromaToast Research #Hugging Face Model Hijacking #Pre_Authentication Code Injection #Python FastAPI Server Vulnerability #Rust Implementation Mitigation #Shodan Internet Exposure #trust_remote_code Parameter #Unpatched Remote Code Execution #Vector Database Exploit
Penetration Testing Tools
ChromaToast Exploit: Unpatched CVSS 10.0 Flaw Grants Pre-Auth RCE in ChromaDB Python Server
A critical authentication bypass vulnerability facilitating unauthenticated remote code execution (RCE) has been isolated within the ChromaDB architecture.
⤷ Title: Your RAG Database Is a Backdoor: Replicating and Defending Against AgentPoison
════════════════════════
𐀪 Author: Cnadgir
════════════════════════
ⴵ Time: Thu, 28 May 2026 23:46:25 GMT
════════════════════════
⌗ Tags: #hacking #vector_database #ethical_ai #ai #rags
════════════════════════
𐀪 Author: Cnadgir
════════════════════════
ⴵ Time: Thu, 28 May 2026 23:46:25 GMT
════════════════════════
⌗ Tags: #hacking #vector_database #ethical_ai #ai #rags
Medium
Your RAG Database Is a Backdoor: Replicating and Defending Against AgentPoison
Chinmay N, Chinmay B, Hayden, and Suditi (UC San Diego, DSC 291 Spring 2026)