SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
SCTPhantom is a Linux kernel use-after-free in SCTP's dynamic address reconfiguration code.
Read Full Article arrow_forwardSCTPhantom is a Linux kernel use-after-free in SCTP's dynamic address reconfiguration code.
Read Full Article arrow_forwardAI Agents gain access to tools, code execution, and business systems, risks such as prompt injection, jailbreaks, and tool abuse can lead to data leaks, system compromise, or business tampering. Tencent Zhuque Lab open-sources the A.I.G Agent Security dirll Skill to help developers and business teams run lightweight, local, and systematic security tests before launch.
Read Full Article arrow_forwardZhuque Lab’s Red Teaming Bot—an automated vulnerability discovery and adversary simulation platform powered by multi-agent orchestration—successfully conducted rapid security audits on targets including OpenClaw and the Linux kernel.
Read Full Article arrow_forwardLeveraging its open-source A.I.G (AI-Infra-Guard) scanner, Zhuque Lab conducted automated security audits on thousands of MCP projects across major MCP marketplaces and Tencent's internal businesses. This large-scale scan uncovered over 4,000 instances of novel AI security risks and code implementation flaws. Drawing on this vulnerability data, this article breaks down the Top 10 Most Common MCP Security Vulnerabilities of 2025 alongside real-world case studies, empowering developers and enterprise security teams to rapidly conduct MCP risk self-assessments.
Read Full Article arrow_forward