← All posts

Platform & Architecture

229 posts on platform & architecture.

CVE-2026-48710 "BadHost": The Starlette Host Header Bug Sitting Under Most AI Gateways

CVE-2026-48710, disclosed by X41 D-Sec during an OSTIF-sponsored audit and nicknamed BadHost, lets a single malformed character in an HTTP Host header bypass path-based authentication middleware in Starlette, the ASGI framework underneath FastAPI, vLLM, LiteLLM, and most MCP servers. CISA added it to the KEV catalog on September 2, 2026. The bug sits a layer below the AI gateway a team actually chose, which is the argument for enforcing authorization at the request boundary instead of trusting framework middleware.

llm-securityai-securityzero-trustarchitectureinline-enforcement
Read post →

CVE-2026-59822: What an MCP Authentication Bypass in LiteLLM Teaches About Session-Level Authorization

CVE-2026-59822 lets an attacker reach LiteLLM MCP tooling with a fabricated Authorization header, because a failed key check fell back to an empty UserAPIKeyAuth object instead of rejecting the request. CISA added it to the Known Exploited Vulnerabilities catalog on September 2, 2026, alongside six other flaws. The bug sits in the MCP session boundary, not the general proxy API, which is a different failure mode than LiteLLM'"'"'s earlier CVE-2026-12773.

llm-securityai-securityzero-trustinline-enforcementpolicy-enforcement
Read post →

Hugging Face Security: What Access Tokens and Endpoint Isolation Cover

Hugging Face secures the Hub and Inference API through three separate mechanisms: fine-grained access tokens with org-level roles, private or gated repositories, and network isolation options on Inference Endpoints. Each answers a different question about who can reach a model. None of the three evaluates the specific prompt a specific authenticated caller sends on a given request. This piece maps where each control ends.

ai-securityllm-securityidentity-and-authorizationarchitecturezero-trust
Read post →

Hugging Face Audit Logs at the AI Request Boundary

Hugging Face logs Inference API and Inference Endpoints traffic against an API token and an organization account. That record supports billing and rate-limit troubleshooting. A security review needs a different record, one that ties a specific hosted-model request to the actor who sent it. This article separates the two and lists what a review should retrieve.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

HubSpot Breeze Security: What Role-Based Permissions Miss

HubSpot scopes CRM permissions to what a user can open in the UI, one record at a time. Breeze agents assemble content from many records into a single prompt before that prompt reaches the underlying model, a step the permission model was never built to re-evaluate. This piece maps where the UI control stops and where request-level policy needs to pick up.

ai-securityllm-securityidentity-and-authorizationarchitecturezero-trust
Read post →

HubSpot Breeze Audit Logs Need a Request-Level Record

HubSpot logs record CRM activity such as field edits, logins, and permission changes inside the admin console. That evidence answers a different question than what a Breeze agent actually sent to a model. This article separates the two records and maps what a request-level audit trail needs.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

Grok Enterprise Security: What API Credentials Do Not Authorize

An enterprise call to the Grok API authenticates with a single API credential shared across an application or team. xAI documents credential management and enterprise data-handling terms, but neither answers which employee or agent originated a given request. This piece maps that request-level gap and what closes it.

ai-securityllm-securityidentity-and-authorizationarchitecturezero-trust
Read post →

Grok Enterprise Audit Logs: What the xAI API Console Shows

Grok reaches most enterprise deployments through xAI developer API, where a single API credential authenticates the calling application rather than the person using it. This article walks through what xAI usage console records at that request boundary, what it cannot show a security reviewer, and what independent evidence a compliance review actually needs.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

Grammarly Enterprise AI Security: What the API Call Actually Exposes

Grammarly Business runs as a browser extension, desktop app, or Office add-in, but every AI suggestion it generates depends on an HTTP call to Grammarly''s cloud API carrying the surrounding text. This piece separates that outbound request, and the admin controls Grammarly Business offers over it, from the local-integration questions that belong to endpoint and DLP tooling.

ai-securityllm-securityidentity-and-authorizationarchitecturezero-trust
Read post →

Gemini Enterprise Security: What VPC-SC, CMEK, and IAM Leave Open

VPC Service Controls, CMEK, and IAM cover three real but separate jobs inside Gemini Enterprise: network perimeter, encryption material control, and coarse role-based access. None of the three evaluates whether a specific authenticated caller, sending a specific prompt, should reach the model right now. This piece maps what each control secures and the request-level gap between them.

ai-securitycloud-securityllm-securityidentity-and-authorizationarchitecturezero-trust
Read post →

Google Gemini Enterprise Audit Logs at the AI Request Boundary

Gemini Enterprise routes a Workspace user prompt through Vertex AI-backed model endpoints, and Google records that activity in two places: Cloud Audit Logs and the Workspace Admin console. This article separates what those two systems capture from the identity-bound, per-request policy record a security review actually needs.

ai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

GitHub Copilot Security: What the Request Path to the Model Covers

GitHub Copilot completions, chat, and agent-mode requests leave the IDE as HTTP calls to GitHub Copilot API endpoints that route to OpenAI and Anthropic models. Org and enterprise policy, content exclusion, and telemetry settings shape what leaves the editor, but none of them evaluate a specific request against the developer sending it. This piece maps the controls and the gap between them.

ai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →