4 posts 2 posts

Explainer

Explainer articles that unpack AI concepts and tools.

A Crafted Host Header Bypasses Auth in Your AI Agent Stack

Starlette BadHost (CVE-2026-48710): a crafted Host header bypasses auth middleware. Unproxied AI agents at highest risk.

One FTC Case Now Sets the Bar for Every AI Marketing Claim

The CMG Active Listening case sets the FTC's bar for AI capability and consent claims. What dev teams need to know.

BadHost's CVSS 6.5 Understates the Real Risk for MCP Servers

CVSS 6.5 misses the mark. Why MCP servers and proxy-less AI agent stacks face disproportionate exposure from BadHost.

SB 315 Passed 110-0 — Five Developer Obligations Before 2028

SB 315 passed 110-0. Who the $500M threshold covers, what five obligations apply, and when enforcement starts.

Starlette BadHost, 프록시 없는 AI 에이전트 인증을 우회한다

Starlette BadHost (CVE-2026-48710): a crafted Host header bypasses auth middleware. Unproxied AI agents at highest risk.

일리노이 AI 법안, $5억 매출이면 적용 의무가 달라진다

SB 315 passed 110-0. Who the $500M threshold covers, what five obligations apply, and when enforcement starts.