Featured · Vulnerability Research
How We Found Three Bugs in a Compiler Proven Correct
CompCert’s formal proof held. We found three bugs at the compiler’s edges.
Cantina 20 min read
Read article
Vulnerability Research, practical guides, and updates from the people building Cantina.
71 stories
37–48 of 71 articles
Category
Vulnerability Research
Clarion connects Dependabot alerts to code and production context, makes missing evidence visible, and carries assessments into remediation and reporting.
Cantina 5 min read
Product Updates
Prepare FHIR APIs for CMS-0057-F requirements due primarily January 1, 2027. See five Pathling findings and apply for a free vulnerability scan.
Cantina 3 min read
Company News
Cantina has signed OpenAI’s call for collective cyber defense, supporting wider access to advanced security capabilities for organizations of every size.
Cantina 2 min read
Guides
Build a web exposure analysis agent with Cloudflare Workers. Follow the scans, evidence and false positives that show why HTTP 200 is not proof of exposure.
Jimmy Vo 18 min read
Product Updates
Clarion adds Claude Code and MCP server visibility, human approvals and exposure sweeps. Apex gains Audit Setup, CLI updates and clear scan controls.
Cantina 5 min read
Vulnerability Research
Apex traced three Seagate openSeaChest memory bugs to an overflowing allocation, an inclusive loop, and an unchecked device index.
Cantina 4 min read
Vulnerability Research
CompCert is a formally verified C compiler for high-assurance software. Its proof held. The bugs lived at the edges.
Cantina 20 min read
Vulnerability Research
Two Node.js vulnerabilities can replay SQLite writes or crash workers through oversized DNS responses. See the affected paths, fixed releases, and mitigations.
Cantina 7 min read
Vulnerability Research
A single 4-byte emoji overflows a fixed stack buffer in Prism, Ruby's default parser since 3.4. What breaks, why the safety check causes it, and the fix.
Cantina 10 min read
Company News
Cantina launches Clarion alongside $8M in new funding led by Framework Ventures, bringing total funding to $16.5M.
Cantina 7 min read
Product Updates
SpaceXAI's Grok Build coding agent was uploading unnecessary repository data; the company's transparent response set industry standards.
Cantina 5 min read
Vulnerability Research
Analysis of four RabbitMQ security vulnerabilities affecting OAuth permissions, topic access, loopback enforcement, and Direct Reply-To bindings.
Cantina 7 min read
Vulnerability Research
Security researchers disclose three distinct vulnerabilities affecting Node.js hostname and TLS stack layers, each enabling authentication bypasses through trust boundary violations.
Cantina 13 min read
Company News
Cantina gains access to Anthropic's CVP to enhance AppSec agent capabilities for vulnerability verification and resolution.
Cantina 5 min read
Guides
A comprehensive analysis of deepfake fraud trends, detection methods, and defensive strategies as of 2026.
Cantina 7 min read
Vulnerability Research
Analysis of how TeamPCP compromised the Trivy security scanner and launched a multi-ecosystem supply chain attack affecting major software delivery infrastructure.
Cantina 12 min read
Company News
Cantina's CEO examines how AI model capabilities for finding vulnerabilities have shifted security from access control to remediation speed.
Cantina 4 min read
Vulnerability Research
A vulnerability in Pathling Server versions 1.2.0 and earlier allowed attackers to bypass security allowlists by reclassifying untrusted data as local after fetching it from attacker-controlled URLs.
Cantina 6 min read
Vulnerability Research
Four additional high-severity vulnerabilities discovered in Pathling FHIR analytics server beyond the TrustLaunder findings.
Cantina 10 min read
Vulnerability Research
A memory-safety vulnerability in Apple's swift-crypto library allows out-of-bounds reads when processing malformed X-Wing HPKE encapsulated keys.
Cantina 14 min read
Vulnerability Research
Cantina's Apex agent discovered CVE-2026-46727, a use-after-free race condition in Ruby 4.0.0-4.0.4's DNS resolver that can crash processes.
Cantina 7 min read
Vulnerability Research
AI-assisted development creates security triage bottlenecks that faster scanners cannot solve; routing findings to service owners with drafted fixes is the actual scaling lever.
Cantina 7 min read
Vulnerability Research
AI-generated code often contains authorization flaws that static analysis misses because the vulnerabilities exist across multiple functions rather than within individual code blocks.
Cantina 9 min read
Vulnerability Research
A poisoned VS Code extension compromised a GitHub employee device, exposing 3,800 internal repos in a broader supply chain attack campaign.
Cantina 12 min read
Guides
Governance requires mapping policy clauses to runtime checks and audit evidence, not just writing policies.
Cantina 4 min read
Guides
Analysis of Apple's May 2026 security patch cycle that closed 80+ vulnerabilities, including AI-credited findings from both Cantina and Anthropic.
Cantina 12 min read
Vulnerability Research
Four production-critical AI infrastructure vulnerabilities reveal systemic gaps in how organizations manage interconnected security risks across their AI stack.
Cantina 4 min read
Vulnerability Research
Analysis of Dirty Frag, a Linux privilege escalation vulnerability affecting major distributions through networking subsystem flaws.
Cantina 5 min read
Vulnerability Research
Cyber-enabled cargo theft reached $725M in losses during 2025, exploiting compromised dispatch workflows and freight software to orchestrate sophisticated theft schemes.
Cantina 5 min read
Vulnerability Research
Cantina's autonomous agent Apex discovered a memory safety vulnerability that persisted in WebKit for 13 years, along with two CSP bypasses, all patched in iOS 26.5.
Cantina 19 min read
Vulnerability Research
Governance of AI agents is shifting from policy frameworks to real-time runtime controls as regulatory bodies establish standards and minimum security requirements.
Cantina 5 min read
Vulnerability Research
Federal agencies warn of active exploitation of internet-connected PLC controllers across U.S. critical infrastructure, creating operational trust and safety concerns.
Cantina 3 min read
Vulnerability Research
Prompt injection becomes a critical security issue when AI agent frameworks allow model-controlled input to reach file operations or code execution.
Cantina 3 min read
Vulnerability Research
Spring Security 7.0.0–7.0.4 silently discards the servlet-path attribute in XML authorization rules, enabling unauthenticated access to protected endpoints.
Cantina 9 min read
Vulnerability Research
Current evidence enables faster incident response by making unusual execution paths queryable rather than requiring manual reconstruction.
Cantina 4 min read
Vulnerability Research
Analysis of how the Checkmarx supply-chain incident demonstrates security tools can become vectors for attack when given privileged access to CI/CD environments and developer workflows.
Cantina 7 min read
Vulnerability Research
A vulnerability in simple-git demonstrates how helper libraries in trusted automation workflows can become serious security exposures.
Cantina 6 min read
Company News
Cantina integrates endpoint detection and device management capabilities through partnerships with CrowdStrike and Swif.
Cantina 3 min read
Guides
Framework for managing AI security risks in healthtech before product launch, covering PHI handling, code review, vendor management, and regulatory compliance.
Cantina 7 min read
Vulnerability Research
Fragmented security stacks grow in tools but fail to improve coverage due to manual cross-system context assembly.
Cantina 4 min read
Vulnerability Research
Annual SOC 2 audits provide historical snapshots but fail to address current security postures that regulators and buyers increasingly demand.
Cantina 4 min read
Vulnerability Research
A critical RCE vulnerability in Apache ActiveMQ's management plane exposes how security gaps persist across organizational silos.
Cantina 4 min read
Vulnerability Research
Analysis of how a malicious Bitwarden CLI package bypassed source controls through npm registry compromise.
Cantina 6 min read
Vulnerability Research
A guide to evaluating agent accountability by examining whether security platforms can trace actions back to initiating users and their delegated authority.
Cantina 7 min read
Vulnerability Research
Healthcare systems face substantial security exposure at data handoff points between EHRs, APIs, payers, and connected platforms.
Cantina 7 min read
Vulnerability Research
Analysis of CVE-2025-64439 in LangGraph showing how unsafe deserialization combined with serializer fallback logic creates remote code execution vulnerabilities.
Cantina 6 min read
Vulnerability Research
Production deployment context helps security teams prioritize alerts based on actual operational risk rather than severity alone.
Cantina 4 min read
Vulnerability Research
Auto-approval settings for coding agents shift execution control boundaries and require careful policy definition before rollout.
Cantina 3 min read
Guides
GitHub's MCP server push protection now blocks secrets within agent sessions rather than at repository commit.
Cantina 3 min read
Vulnerability Research
Analysis of how untrusted input reaching MCP stdio configuration can enable local code execution attacks.
Cantina 6 min read
Vulnerability Research
Analysis of how Vercel's April 2026 security breach leveraged compromised third-party OAuth access through Google Workspace to reach deployment control-plane configuration.
Cantina 11 min read
Vulnerability Research
Security incidents in healthtech are now judged like operational failures, making continuity protection equally important as data protection.
Cantina 8 min read
Vulnerability Research
OpenSSH 10.3p1 fixes two vulnerabilities rooted in decades-old trust assumptions from Berkeley rcp.
Cantina 6 min read
Guides
Framework for assessing AI agent governance readiness across inventory, permissions, approvals, logging, and incident response.
Cantina 6 min read
Guides
Automated code analysis helps teams counter "vibe coding" risks from AI-assisted development by catching security flaws early and reducing alert fatigue.
Cantina 3 min read
Guides
SaaS teams must prepare now for EU AI Act transparency obligations taking effect August 2, 2026.
Cantina 5 min read
Guides
A security framework for governing Model Context Protocol access to prevent costly AI agent mistakes
Cantina 6 min read
Vulnerability Research
Analysis of the tj-actions/changed-files compromise that exposed secrets through mutable GitHub Action tags in 23,000+ repositories.
Cantina 4 min read
Product Updates
Manual compliance evidence collection creates operational friction; continuous automated compliance reduces audit timelines and engineering overhead.
Cantina 3 min read
Vulnerability Research
Spring AI's SimpleVectorStore is vulnerable to remote code execution through SpEL injection in filter expressions when keys are not properly sanitized.
Cantina 5 min read
Vulnerability Research
Enterprises managing 45-83 security tools face fragmentation, alert fatigue, and financial losses that agentic AI platforms can resolve.
Cantina 11 min read
Vulnerability Research
An AI-driven security tool discovered a 15-year-old buffer overflow vulnerability in XZ Utils before attackers could exploit it.
Cantina 3 min read
Vulnerability Research
A threat actor compromised an axios maintainer account and published malicious npm releases that delivered cross-platform malware to approximately 3% of affected installations.
Cantina 3 min read
Vulnerability Research
How agentic security platforms autonomously defend against CVE-2026-21643, a critical pre-authentication SQL injection vulnerability in FortiClient EMS.
Cantina 6 min read
Vulnerability Research
A high-severity vulnerability in Claude Code allowed privilege escalation through workspace trust dialog bypass.
Cantina 3 min read
Vulnerability Research
A high-severity Cypher injection vulnerability in Spring AI's Neo4j component was identified and autonomously remediated by Cantina's Apex security tool.
Cantina 3 min read
Vulnerability Research
Technical analysis of CVE-2026-22738, a critical Spring AI vulnerability enabling remote code execution through unvalidated SpEL injection in vector store filters.
Cantina 3 min read
Vulnerability Research
A supply chain compromise in LiteLLM versions 1.82.7 and 1.82.8 delivered malware through PyPI that executed at Python startup via .pth files.
Cantina 6 min read
Guides
A comprehensive guide addressing AI-powered defense tools and AI system security for SOC analysts, security engineers, and CISOs navigating 2026's threat landscape.
Cantina 18 min read
Vulnerability Research
Agentic AI transforms security operations by automating alert triage and investigation, freeing SOC analysts to focus on strategic work.
Cantina 6 min read
Guides
Five AI agent security engineering rules for permissions, prompt injection, execution controls, monitoring, and incident response.
Cantina 6 min read
Try another keyword or choose a different category.
Page 4 of 6