Serious path traversal bug found in Microsoft's NLWeb "Agentic Web" tool
Aug 12 2025Vulnerability allowed reading of system files and theft of AI LLM API keys.
Vulnerability allowed reading of system files and theft of AI LLM API keys.
After 'data breach'.
Vulnerability finding program targets company's enterprise offerings.
Legitimate feature needs to be secured, but admins aren't sure how to do it.
Over 100 currently supported models at risk.
Identity Protection and Recovery Bill passes NSW parliament.
Block-busting bot or legitimate AI traffic?
IDORs and broken access controls at scale.
After large-scale run of the agent.
Uses soft power to shrink 'upstream patch gap'.