
GraphQL
Programming languageWikipedia
104
MENTIONS
47
EPISODES
38
PODCASTS
Search complete. 104 mentions across 47 episodes found for "GraphQL".
Sep 12, 2026
Cyber Mornings Daily - September 12th, 2026
S
4:34speaker_0HOST
My notes show GitLab also just patched two other critical flaws.
S
4:38speaker_0HOST
There's a GraphQL code injection flaw, CVE-2026-99478.
S
4:40speaker_0HOST
Right.
S
4:40speaker_0HOST
And the other is CVE-2026-8771-TIME.
S
4:46speaker_1HOST
Which is a CDSS 9.9, by the way.
S
4:49speaker_0HOST
Right, 9.9. And that one is described as an insecure deserialization bug in DuoChat access that bypasses serialization via crafted GraphQL subscription argument.
S
4:57speaker_1HOST
That's a mouthful.
S
4:58speaker_0HOST
It really is.
The Department of Know: Liquid drained, CISA urges change, agentic whistleblowers
R
10:06Rich StroffolinoHOST
Adobe says it's working on a fix, but hasn't offered a release time.
R
10:09Rich StroffolinoHOST
Sansa recommends disabling GraphQL and rotating Magento credentials if a compromise is suspected.
R
10:16Rich StroffolinoHOST
Um, you know, e-commerce zero day, uh, I can't think of a better way to kick off the weekend here.
R
10:21Rich StroffolinoHOST
Mark, anything here to, uh, uh, that, uh, you wanna know more about within this story? A lot of interesting technical details here, or Sansa has the mitigations out, a patch will be out, dot, dot, dot, someday.
Caching is a cop-out
H
7:22Hussein NasserHOST
So you see how precious these calls get.
H
7:25Hussein NasserHOST
So back to our life, how we do things is when we execute... a REST call or a GraphQL or any endpoint or a SQL statement, we just assume that, you know what, I'm not going to do that again.
H
7:41Hussein NasserHOST
That's slow.
H
7:42Hussein NasserHOST
Let's just cache it.
Ep. #42, When Forking Becomes a Feature with Will Cory
W
15:07Will CoryGUEST
I think for the most part, the default is exactly what you said, where I think we'll just collapse on the same standards we've been using all the time.
W
15:16Will CoryGUEST
OpenAPI, GraphQL, Nix, all these things are definitely no reason to invent a new thing for the most part.
W
15:28Will CoryGUEST
I think this is really interesting and something I thought a lot about as just someone who's building tools, right? It's like what actually does, like what does something that actually does deserve to be built new look like, right? And I think what that looks like is when kind of the fundamental math you do of like how should this abstraction look and what should it optimize for, whenever that changes based on agents, like fundamentally what you want.
W
15:54Will CoryGUEST
So like I think a really good example of this actually is just, the way we do pull requests, for example, the way we like get code merged, right? I think a lot of people will report, like if you start having like these like high velocity, many agents working at once, when it comes to this, I think you'll notice that like your agents just get stuck In rebase hell, they get just stuck having to...
B
21:19Brian DouglasHOST
And it's telling its own stories, but to all the influence.
B
21:22Brian DouglasHOST
And I wonder...
B
21:24Brian DouglasHOST
We don't need another GraphQL.
B
21:25Brian DouglasHOST
We'd rather do another OpenAPI spec.
Netflix’s Paul Bakker
P
4:35Paul BakkerGUEST
Yeah, probably.
P
4:37Paul BakkerGUEST
Maybe we have to deal with it and talk too much about GraphQL because I think we were integrating with Spring for GraphQL at the time.
J
4:45Josh LongHOST
Yeah.
P
4:45Paul BakkerGUEST
It seems many years ago now.
P
5:41Paul BakkerGUEST
Been a bunch of different teams, worked on a bunch of different things, but for the last four or five years or so, I've been in what we call the Java platform team.
P
5:49Paul BakkerGUEST
So my team is responsible for Spring Boot, for example, and making that available to all developers.
P
5:55Paul BakkerGUEST
I've worked a lot on our GraphQL stack in the past and a framework that we built for that.
P
5:59Paul BakkerGUEST
And yeah, kind of all things Java, I tend to touch.
I Woke Up In A Jail Cell - ft. Kurt Kemple
K
58:03Kurt KempleGUEST
I rebuilt their mobile app.
K
58:04Kurt KempleGUEST
Like I moved them to a technology called GraphQL, which allowed them to like get rid of a bunch of other stuff that was like overly complex and getting in the way.
K
58:13Kurt KempleGUEST
It was very cool.
K
58:14Kurt KempleGUEST
It was a fun job.
K
58:15Kurt KempleGUEST
But that's where I wrote it.
K
58:17Kurt KempleGUEST
And you know why I wrote it? Because I met so many people, a much bigger company, and two things had happened.
K
58:23Kurt KempleGUEST
I had started to build up an actual presence in the community because I was writing about and talking about these technologies like GraphQL and React Native, which were emerging at the time, right? And then I also had enough job security at that point.
K
58:38Kurt KempleGUEST
I had worked like seven or eight different jobs in tech.
1037: WebMCP is here (and you should care)
S
1:50Sarah DrasnerGUEST
That's the MCP for WebMCP, it's W3C like other standards bodies.
S
1:56Sarah DrasnerGUEST
For WebMCP, you are really only working on it on the client, but that doesn't mean that it can't negotiate or create server actions like kickoff arrest or GraphQL API interaction.
S
2:10Sarah DrasnerGUEST
Also, the way that people are using it agentically, you do have headless scenarios that you can use WebMCP.
S
2:16Sarah DrasnerGUEST
But we're also thinking about a new surface area of co-browse.
9 MINS LATER
S
11:27Sarah DrasnerGUEST
So don't leverage the existing DOM structure.
S
11:30Sarah DrasnerGUEST
Think in agent actions.
S
11:33Sarah DrasnerGUEST
I would also want to leverage existing APIs in your application like REST or GraphQL.
S
11:39Sarah DrasnerGUEST
If you have those, those can be invoked with a tool with a really good description.
PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA
S
5:10Sarah LaneHOST
Adobe says it's working on a fix but hasn't offered a release time.
S
5:15Sarah LaneHOST
Sansec recommends disabling GraphQL and rotating Magento credentials if compromise is suspected.
S
5:23Sarah LaneHOST
[transition effect] Shadow AI steps into the light.
S
5:28Sarah LaneHOST
The UK's National Cybersecurity Centre says unapproved AI tools are creating security gaps companies may not see.
🔴 Sep 8's Top Cyber News NOW! - Ep 1239
S
43:42Sarah LaneSOUNDBITE_SPEAKER
Adobe says it's working on a fix, but hasn't offered a release time.
S
43:47Sarah LaneSOUNDBITE_SPEAKER
Sansa recommends disabling GraphQL and rotating Magento credentials if compromise is suspected.
G
43:57Gerald AugerHOST
Okay.
G
44:00Gerald AugerHOST
I guess Magento...
G
47:19Gerald AugerHOST
The patches are not available yet.
G
47:22Gerald AugerHOST
They should be available September 8th, which is today, so I guess today you can patch it.
G
47:28Gerald AugerHOST
Uh, but they say if you can't do it right away, disable GraphQL.
G
47:32Gerald AugerHOST
Uh, I would strongly encourage you to figure out what disabling GraphQL does before you turn it off.
Nightmare Eclipse Drops 3 Zero-Days Targeting CrowdStrike, Avast, NVIDIA, Magento StyleSmuggler Zero-Day Exploited to Deploy Linux Backdoors, OpenAI Pledges $1 Billion in Daybreak AI Cyber Defense Tools
J
4:33James AzarHOST
Because there is no patch, your mitigation options are limited, however very important.
J
4:39James AzarHOST
SANSEC does recommend disabling GraphQL as an interim measure since the attack chain runs through that interface.
J
4:47James AzarHOST
Monitor aggressively for unexpected K-worker or FC cache processes, suspicious crone entries, and any unusual temporary files in server directories.
J
4:59James AzarHOST
And if you see any unexpected surges of payment transaction failed reminder emails, treat that as a potential exploitation indicator and investigate immediately.
37 more episodes mention GraphQL.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.