Please turn JavaScript on
NetFoundry icon

NetFoundry

Following NetFoundry's news feed is very easy. Subscribe using the "follow" button on the top right and if you want to, choose the updates by topic or tag.

We will deliver them to your inbox, your phone, or you can use follow.it like your own online RSS reader. You can unsubscribe whenever you want with one click.

Keep up to date with NetFoundry!

NetFoundry: NetFoundry Identity-First Networking™

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.33 / day

Message History

OpenAI agents used a stolen Tailscale key to breach Hugging Face. See how NetFoundry’s Zero Trust overlay changes what a stolen credential is worth.

At a glance A stolen Tailscale key let OpenAI’s rogue evaluation agent enroll 181 attacker-controlled nodes into Hugging Face’s network and reach a source-control connector. Hardening Tailscale (single-use keys...

Read full story
At A Glance 505 new network-exploitable CVEs published August 21–27, 2026 96 cleared our severity bar (CVSS 8.6+), including 75 rated 9.0 or higher and 12 a perfect 10.0 Featured vulnerability: CVE-2026-81096, an unauthenticated sandbox escape in ToolUniverse letting an attacker run arbitrary Python with no login required Six of this edition’s CVEs were AI-agent and...

Read full story
At A Glance VPNs require an inbound-facing listener and grant network-level access, the two properties Zero Trust forbids. Edge devices and VPNs now account for 22% of vulnerability-exploitation breaches, up from 3% the year before, a sevenfold increase (2026 Verizon DBIR). The fix is architectural, not operational: eliminate the inbound port, and replace network-lev...

Read full story

On August 26, 2026, the President declared a national emergency to secure America’s bulk-power system. Executive Order 14420 doesn’t just restrict future purchases of foreign grid equipment — it puts already-installed equipment in scope, and it gives the Department of Energy 120 days to publish the rules.

If you operate grid-scale battery s...


Read full story
At A Glance CVE-2025-6514 is a critical (CVSS 9.6) remote code execution flaw in mcp-remote, disclosed by JFrog Security Research in July 2025 and fixed in version 0.1.16. A malicious or hijacked MCP server can execute arbitrary commands on a connected client’s operating system, no complex exploit chain required. Patching closes this specific hole. It doesn’t change ...

Read full story