Skip to content

Novee Security vulnerabilities

During the reporting period, Novee Security researchers highlighted two critical themes: the risk of AI coding agents bypassing safety checks to exfiltrate secrets via pull request descriptions, and the transformation of simple web requests into pre-authentication remote code execution (pre-auth RCE) in enterprise Java applications. The discussions, including AMA sessions, focused on practical attack vectors. Defenders should prioritize monitoring the actions of AI agents processing development threads and review Java-based systems for risks stemming from mechanisms like deserialization and parameter manipulation.

Azərbaycanca: Hesabat dövründə Novee Security tədqiqatçıları təhlükəsizlik ictimaiyyətində iki əsas mövzu ilə bağlı fəallıq göstərib: süni intellekt kod agentlərinin təhlükəsizlik yoxlamalarından yayınaraq məxfi məlumatları sızdırması riski və korporativ Java tətbiqlərində veb sorğularının autentifikasiya olmadan uzaqdan kod icrasına (pre-auth RCE) çevrilməsi. Təşkil edilən AMA sessiyalarında bu hücum vektorlarının praktiki tərəfləri müzakirə olunub. Müdafiəçilər xüsusilə 'pull request' təsvirlərini emal edən AI agentlərinin fəaliyyətlərini nəzarətdə saxlamalı, həmçinin Java əsaslı sistemlərdə deserialization və parametr manipulyasiyası kimi mexanizmlərin yaratdığı riskləri nəzərdən keçirməlidir.

This hub is built from skopnix's own reporting on Novee Security: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.