Skip to content

#Security/incidents

0 items today
10/6Tue
10/5Mon
10/4Sun
  1. Hacker News · MCP76

    RugSnare: hash-pinning MCP tool descriptions to catch silent changes after approval

    RugSnare is a runtime integrity tool for MCP tool descriptions. It computes a normalized hash pin over each approved tool's { name, description, inputSchema }, and any silent change afterward triggers an alert and fails CI (exit 1).

    Why it matters: RugSnare hash-pins MCP tool descriptions, keeps watching for silent changes after approval, and shares measured data from 66 official server versions.

10/3Sat
9/29Tue
7/17Fri
4/4Sat
  1. Hacker News · Prompt Injection52

    PIGuard:通过 MOF 策略缓解提示词注入防护的过度防御

    圣路易斯华盛顿大学与威斯康星大学麦迪逊分校的研究者提出 PIGuard,一个用于检测提示词注入的轻量防护模型,并配套发布 NotInject 评测数据集。NotInject 包含 339 条带触发词的良性样本,用于衡量防护模型的过度防御问题,结果显示现有 SOTA 模型准确率降至接近随机猜测的 60%。

    Awaiting translation

2/25Wed
  1. Lovable · Blog22

    Lovable 如何为非技术团队设计治理、权限与安全机制

    Lovable 将编辑、审批、发布拆分为独立权限,发布同时受显式权限与审批状态双重限制,未获授权的操作在系统中直接不可执行。平台采用基于角色的访问控制,审批在构建内容的同一系统内完成,源代码不离开客户安全边界,Lovable 不克隆客户 GitHub 仓库、不拉取应用代码、不要求访问内部 CI/CD。

    Awaiting translation