Topic hub
AI Security
Protect AI systems from attacks, ensure data privacy, and implement secure AI practices.
All posts · 41

AI SECURITY01
AI Incident Reporting: Which Regulator Clock Starts FirstThe shortest EU incident deadline is four hours from classification, not 24 from awareness. NIS2 Article 4(1) switches itself off for financial entities.AI SECURITY02
MLflow authorizes by dictionary lookup: 120 entries at v3.15.2, and a miss is a pass rather than a denial. Ten advisories in five months say the same thing.
AI SECURITY03
Ray Cluster Authentication: RAY_AUTH_MODE and Five CVEsRay had no authentication before 2.52.0 and still defaults to disabled in 2.58.0. Five CVEs set the version floor. What vLLM copies to workers.
AI SECURITY04
Triton Inference Server Security: 22 of 31 CVEs Are DoSNVIDIA's 2026 index lists 31 Triton CVEs: 22 are denial of service only, 6 list code execution, and the 26.06 floor shipped 53 days before its bulletin.
AI SECURITY05
Text-to-SQL Agent Permissions: The Role Is the BoundaryCOPY (SELECT 1) TO PROGRAM runs to completion inside BEGIN TRANSACTION READ ONLY on PostgreSQL 18.6. Only the database role refused every payload.
AI SECURITY06
Picklescan Bypass File Extension Mismatch: 6 ControlsCVE-2025-10155 does not make picklescan report clean. It makes it exit 2 with Infected files 0, which most CI gates read as a pass.
AI SECURITY07
Can You Use GitHub Copilot With CUI Under CMMC Level 2?GitHub Enterprise Cloud holds a FedRAMP Tailored authorization from 2018 and Copilot has none of its own. Three postures, and what each proves at assessment.
AI SECURITY08
How to Secure an Ollama Server Exposed to the InternetA 293-day scan found 175,000 publicly reachable Ollama hosts in 130 countries. The default bind is safe. One systemd line undoes it.
AI SECURITY09
Presidio vs GLiNER for PII Redaction Before an LLM in 2026Presidio left Microsoft in June 2026, and only 3 of its 81 entity types come from a model. Which PII classes each detector misses, and where the hop belongs.