When "AI Infrastructure" Means "Remote Shell": Three Logic-Class RCEs, Reproduced
Three logic-class RCEs — LiteLLM, marimo, ActiveMQ — reproduced end-to-end. Two are in CISA KEV. Why injection beats memory corruption for reliability.
CVE research, AI red teaming, eBPF intrusion detection, and smart contract security — technical deep-dives from Singapore's APAC security research hub.
5-stage AI red teaming methodology: prompt injection, RAG poisoning, MCP abuse, agent escalation. OWASP ASI mapping, 33+ LLM benchmarks, Singapore MAS context.
Loading module "ai-red-teaming-framework-llm-security-testing-methodology"...
Analyzing dependencies...
Integrity check: PASSED
-- End of stream --
Three logic-class RCEs — LiteLLM, marimo, ActiveMQ — reproduced end-to-end. Two are in CISA KEV. Why injection beats memory corruption for reliability.
CVE-2025-41243 (CVSS 10.0) in Spring Cloud Gateway: with the actuator exposed, 'property modification' reaches arbitrary file read and SSRF to cloud metadata.
Singapore FinTech AI security: MAS TRM controls, PDPA for AI, fraud detection adversarial testing, LLM chatbot prompt injection defence, real-time monitoring.
AI security for Singapore's 11 CII sectors under CSA 2024: finance, healthcare, transport threats, eBPF runtime monitoring, MAS/MOH/LTA compliance evidence.
eBPF kernel-level security for AI workloads: data poisoning detection, model exfiltration prevention, inference protection. ~600k EPS ingest (rules disabled).
Four-pillar enterprise GenAI risk framework: People, Process, Policy, Platform for LLM deployments. Data leakage, hallucination, IP risk, audit trail controls.
QEMU-based IoT firmware audit: AI pipeline, ASAN verification, public CVE-2026-37555 in libsndfile 1.2.2. Singapore, CSA CLS, APAC embedded security.
MAS TRM compliance for AI/ML systems in Singapore: model validation, drift monitoring, adversarial testing, PDPA alignment, CISO 90-day remediation checklist.
Singapore AI security regulations 2026: MAS TRM, CSA Cybersecurity Act, AI Verify, PDPA mapped for enterprises deploying AI. Practical CISO compliance roadmap.
A pre-auth DoS in Vanetza V2X: one crafted 802.11p packet crashes the ITS-G5 stack via an uncaught off-curve ECC exception. CVSS 6.5, no fix available.
A CUDA BIP39 kernel bug: missing checksum-bit guard causes wrap-around negative shifts to silently corrupt entropy. Bug, PoC, and one-line fix.
Independent forensic analysis: 116,500 rsETH ($292M) stolen via forged LayerZero lzReceive. 9 attacker EOAs, $266M ETH motionless at hub.