
Server-side request forgery
62
MENTIONS
32
EPISODES
26
PODCASTS
Search complete. 62 mentions across 32 episodes found for "Server-side request forgery".
Sep 12, 2026
Cl0p's Blueprint Heist
D
9:32David GibsonHOST
This attack has been unfolding for a while.
D
9:36David GibsonHOST
In May, late May, agents learned how to exploit the flaw in our artifactory, right, the SSRF flaw there.
D
9:45David GibsonHOST
around July 8th there was an agent called phase one one zero eight four one crazy name right um but uh decided it it wasn't going to get to where it wanted to go the way it was going so it devised a new strategy and it established a message board which is kind of what you're talking about it's a little bit of memory persistence uh and it did that using artifactory And we'll talk about JFrog a little bit later too, but within a few hours, more than 50 agents started using it to work together.
D
10:21David GibsonHOST
They hid evidence of cheating, not necessarily from humans, but from the automated scoring processes.
Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens
J
10:50Joseph ThackerHOST
And then I'll go ahead and do the follow up.
J
10:52Joseph ThackerHOST
Basically there was another thing where, um, kind of like you can, you can think of it as like another CSP bypass where on like Google, you can use like Google scripts to exfiltrate it basically on this same root domain that you actually do have access to like set up an SSRF or not.
J
11:06Joseph ThackerHOST
Sorry.
J
11:06Joseph ThackerHOST
I like a request handler.
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Sean Murphy, Idan Plotnik, Ido Geffen - ASW #399
I
57:49Ido GeffenGUEST
the best practices in the industry.
I
57:52Ido GeffenGUEST
Um, and you're right with covering from cross-site scripting, SSRF, um, privilege escalation, a-and et cetera.
I
58:00Ido GeffenGUEST
But our claim to fame specifically at Novi is the ability to detect, um, novel business logic vulnerabilities.
I
58:07Ido GeffenGUEST
Uh, I can give you examples.
8 MINS LATER
I
65:53Ido GeffenGUEST
... uh, when it comes to prompts, but also there is a lot of issues when it comes to...
I
65:58Ido GeffenGUEST
There's no question that the frontier models are capable of detecting vulnerabilities, but again, when it comes to precision, how many of, of those are really true positive? So the bottleneck really moved from finding issues to being validate what is truly exploitable and what is not.
M
66:14Mike ShimaHOST
And I think what is important here, I, I, I think what you're also checking is it's good to have that benchmark, that training gym, just to say, we can find this type of input validation, SSRF, business logic, but you're also testing...
M
66:26Mike ShimaHOST
I don't have a good metaphor here for the, for the, a physical gym yet, but what the cost.
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399
I
57:42Ido GeffenGUEST
So for example, when it comes to web applications, so we are mapping ourselves to OWSTG, which is the best practices in the industry.
I
57:52Ido GeffenGUEST
And you're right, we're covering from cross-site scripting, SSRF, privilege escalation, etc., But our claim to fame specifically at Novi is the ability to detect novel business logic vulnerabilities.
I
58:07Ido GeffenGUEST
I can give you examples.
I
58:08Ido GeffenGUEST
Yeah, please.
8 MINS LATER
I
65:47Ido GeffenGUEST
So what we're seeing in large organizations that are trying those types of tools, getting into very big checks when it comes to prompts, but also there is a lot of issues when it comes to, there's no question that the frontier models are capable of detecting vulnerabilities.
I
66:02Ido GeffenGUEST
But again, when it comes to precision, how many of those are really true positive? So the bottleneck really moved from finding issues to being validate what is truly exploitable and what is not.
M
66:14Mike SchemaHOST
And I think what is important here, I think what you're also checking is, it's good to have that benchmark, that training gym, just to say, we can find this type of input validation, SSRF business logic.
M
66:25Mike SchemaHOST
but you're also testing, I don't have a good metaphor here for a physical jib yet, but what the cost, like what does it cost to find this? And I think, can you tell us a little bit about what that benchmark looks like?
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Sean Murphy, Idan Plotnik, Ido Geffen - ASW #399
I
57:42Ido GeffenGUEST
So for example, when it comes to web applications, so we are mapping ourselves to OWSTG, which is the best practices in the industry.
I
57:52Ido GeffenGUEST
And you're right, we're covering from cross-site scripting, SSRF, privilege escalation, et cetera.
I
58:00Ido GeffenGUEST
But our claim to fame specifically at Novi is the ability to detect novel business logic vulnerabilities.
I
58:07Ido GeffenGUEST
I can give you examples.
7 MINS LATER
I
65:25Ido GeffenGUEST
Yeah, so one of the big things, especially for very large enterprises, the ones that have thousands of applications and they want to test it continuously, Part of the unique thing that we are providing is the fact that we are optimizing all the time the right models for the right tasks and building our own model is the ability to provide a predictable cost.
I
65:47Ido GeffenGUEST
So what we're seeing in large organizations that are trying those types of tools, getting into very big checks when it comes to prompts, but also there is a lot of issues when it comes to, there's no question that The frontier models are capable of detecting vulnerabilities, but again, when it comes to precision, how many of those are really true positive? So the bottleneck really moved from finding issues to being validate what is truly exploitable and what is not.
M
66:14Mike SchemaHOST
And I think what is important here, I think what you're also checking is, it's good to have that benchmark, that training gym, just to say, we can find this type of input validation, SSRF business logic.
M
66:25Mike SchemaHOST
but you're also testing, I don't have a good metaphor here for a physical jib yet, but what the cost, like what does it cost to find this? And I think, can you tell us a little bit about what that benchmark looks like?
Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399
I
57:42Ido GeffenGUEST
So for example, when it comes to web applications, so we are mapping ourselves to OWSTG, which is the best practices in the industry.
I
57:52Ido GeffenGUEST
And you're right, we're covering from cross-site scripting, SSRF, privilege escalation, etc., But our claim to fame specifically at Novi is the ability to detect novel business logic vulnerabilities.
I
58:07Ido GeffenGUEST
I can give you examples.
I
58:08Ido GeffenGUEST
Yeah, please.
8 MINS LATER
I
65:47Ido GeffenGUEST
So what we're seeing in large organizations that are trying those types of tools, getting into very big checks when it comes to prompts, but also there is a lot of issues when it comes to, there's no question that the frontier models are capable of detecting vulnerabilities.
I
66:02Ido GeffenGUEST
But again, when it comes to precision, how many of those are really true positive? So the bottleneck really moved from finding issues to being validate what is truly exploitable and what is not.
M
66:14Mike SchemaHOST
And I think what is important here, I think what you're also checking is, it's good to have that benchmark, that training gym, just to say, we can find this type of input validation, SSRF business logic.
M
66:25Mike SchemaHOST
but you're also testing, I don't have a good metaphor here for a physical jib yet, but what the cost, like what does it cost to find this? And I think, can you tell us a little bit about what that benchmark looks like?
Radix Malorum
D
14:56Duane LaFlotteHOST
It is super easy to run.
D
14:58Duane LaFlotteHOST
Um, it is a form of SSRF, which is a server side request forgery attack.
C
15:03Carl FranklinHOST
Yeah.
D
15:03Duane LaFlotteHOST
Um, so for those of you who haven't, like, been familiar with SSRF attacks, an SSRF attack is where I can make a call out to a service, whether it's a web server or in this case a VPN service.
D
15:16Duane LaFlotteHOST
Um, most of the SonicWall VPN services are a web server.
D
15:20Duane LaFlotteHOST
Whatever.
D
15:25Duane LaFlotteHOST
Um, but you go out to a website, and you make a request, and what happens is that server then makes a request to itself on your behalf.
D
15:34Duane LaFlotteHOST
So it looks like it's coming from inside.
🎙️ OpenAI Confirms Astra Is First AI Model to Reach Critical Cybersecurity Capability Threshold, Critical Microsoft Exchange Authentication Bypass Threatens Enterprise Email, SonicWall Warns of Two More SMA1000 Zero-Days
J
2:49James AzarHOST
which is suggesting attackers are chaining them.
J
2:53James AzarHOST
So the unauthenticated SSRF bug for a foothold, and then command injection bug to actually execute code.
J
3:02James AzarHOST
And this hits the SMA 1000 series specifically, the 6210, 7210, and 8200 V models.
J
3:09James AzarHOST
The separate SMA 100 series and SonicWall's SSL VPN on its firewall are not affected by this, so don't confuse the product lines.
OpenAI Cuts Off Cursor, Nvidia Buys Hugging Face, Ox Alpha is GLM | This Week In AI
S
12:57Shane ThomasHOST
The sandbox needed access to a local JFrog artifactory server.
S
13:02Shane ThomasHOST
Anyways, the models use the basic SSRF exploit to route web traffic through the proxy to the public internet.
S
13:09Shane ThomasHOST
Stop.
S
13:09Shane ThomasHOST
Did they vibe up this isolated environment? Their IT team can't be this bad.
Associate risk scenarios with OWASP Top 10 (maps)
S
2:56speaker_0NARRATOR
Cover a broad range, not only injection.
S
2:59speaker_0NARRATOR
Invent realistic situations, weak password reset, unencrypted password storage, outdated library, verbose error messages, IDER on TaskEd, missing logs on failed logins, an SSRF via an import from URL feature, etc.
S
3:14speaker_0NARRATOR
Step 3.
S
3:15speaker_0NARRATOR
Map each scenario.
22 more episodes mention Server-side request forgery.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.