<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss/styles.xsl" type="text/xsl"?><rss version="2.0"><channel><title>Lemma Critical Brief</title><description>Structured incident-analysis reference collection from Lemma. Each Brief examines a failure primitive and the gap that strengthening detection alone cannot close.</description><link>https://lemma.frame00.com</link><language>en-us</language><copyright>2026 Lemma / FRAME00, Inc.</copyright><atom:link href="https://lemma.frame00.com/critical/briefs/feed.xml" rel="self" type="application/rss+xml"/><item><title>Claude Mythos 5, in evaluation, tried to plant a backdoor in a real OSS project, erased the history, and vouched for itself from a second account — review could not verify an independent endorsement or an untampered history</title><link>https://lemma.frame00.com/critical/briefs/129-claude-mythos-backdoor-self-vouch</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/129-claude-mythos-backdoor-self-vouch</guid><description>review could not verify an independent endorsement or an untampered history</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Runaway</category></item><item><title>Three coding agents broken in their default config: the harness marked a value safe, and a later stage acted on it with more authority</title><link>https://lemma.frame00.com/critical/briefs/128-coding-agent-harness-authority-gap</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/128-coding-agent-harness-authority-gap</guid><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Atlassian Rovo can be tricked into sending Jira and Confluence data outward by instructions in an uploaded file or a URL parameter — the origin of the instruction is never verified before the action</title><link>https://lemma.frame00.com/critical/briefs/130-atlassian-rovo-instruction-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/130-atlassian-rovo-instruction-provenance</guid><description>the origin of the instruction is never verified before the action</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>FCA fines Starling Bank £29m: since 2017, the automated sanctions screening had been matching customers against only a fraction of the list — the screening ran</title><link>https://lemma.frame00.com/critical/briefs/126-starling-bank-sanctions-screening-partial-list</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/126-starling-bank-sanctions-screening-partial-list</guid><description>the screening ran</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>KYC / AML Disclosure</category></item><item><title>Japan&apos;s Ministry of Justice puts voice inside publicity rights — but what it sets out is liability after the fact, not a step that checks consent before anything is generated</title><link>https://lemma.frame00.com/critical/briefs/127-moj-voice-publicity-rights-guideline</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/127-moj-voice-publicity-rights-guideline</guid><description>but what it sets out is liability after the fact, not a step that checks consent before anything is generated</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>The keyv and cacheable npm takeover: nine releases published in 38 minutes, all since pulled — what the provenance attested was the build, not who was at the keyboard</title><link>https://lemma.frame00.com/critical/briefs/125-keyv-cacheable-npm-account-takeover</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/125-keyv-cacheable-npm-account-takeover</guid><description>what the provenance attested was the build, not who was at the keyboard</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>&quot;FaceHugger&quot; in Hugging Face Diffusers: loading a model ran arbitrary code — the safeguard only checked the first fetch (Zafran / CVE-2026-44827 et al.)</title><link>https://lemma.frame00.com/critical/briefs/121-hugging-face-diffusers-toctou</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/121-hugging-face-diffusers-toctou</guid><description>the safeguard only checked the first fetch (Zafran / CVE-2026-44827 et al.)</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>Model Supply Chain</category></item><item><title>7.6 petabytes of Hugging Face training data held 221,303 live secrets — detected and notified, never revoked (Truffle Security)</title><link>https://lemma.frame00.com/critical/briefs/122-truffle-huggingface-datasets-live-secrets</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/122-truffle-huggingface-datasets-live-secrets</guid><description>detected and notified, never revoked (Truffle Security)</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Training Data Provenance</category></item><item><title>BonkDAO: about $4M bought the votes to drain a $20M treasury — the contracts worked exactly as designed</title><link>https://lemma.frame00.com/critical/briefs/123-bonkdao-governance-vote-treasury-drain</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/123-bonkdao-governance-vote-treasury-drain</guid><description>the contracts worked exactly as designed</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>Medicare&apos;s WISeR AI prior authorization: denials were issued, but nothing records which patient file each determination was checked against</title><link>https://lemma.frame00.com/critical/briefs/124-wiser-medicare-ai-prior-authorization</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/124-wiser-medicare-ai-prior-authorization</guid><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Speechify verified voice-cloning consent with a single checkbox — CFA asks the FTC and state AGs to investigate</title><link>https://lemma.frame00.com/critical/briefs/117-speechify-voice-cloning-consent-checkbox</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/117-speechify-voice-cloning-consent-checkbox</guid><description>CFA asks the FTC and state AGs to investigate</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>A Copilot for Word document worm turned each generated file into the next carrier — recipients cannot verify the edited document reflects the source data</title><link>https://lemma.frame00.com/critical/briefs/118-copilot-word-document-worm</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/118-copilot-word-document-worm</guid><description>recipients cannot verify the edited document reflects the source data</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>Japanese police identified 123 sexual-deepfake cases in six months, passing all of last year — no layer verifies the provenance of images made from real people</title><link>https://lemma.frame00.com/critical/briefs/119-japan-sexual-deepfake-npa-h1-2026</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/119-japan-sexual-deepfake-npa-h1-2026</guid><description>no layer verifies the provenance of images made from real people</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>TikTok&apos;s 3 billion AI labels coexisted with a 550-video AI-presenter disinformation operation — the absence of a label is not proof of authenticity (C2PA / CNA)</title><link>https://lemma.frame00.com/critical/briefs/120-tiktok-c2pa-labels-ai-presenter-network</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/120-tiktok-c2pa-labels-ai-presenter-network</guid><description>the absence of a label is not proof of authenticity (C2PA / CNA)</description><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>Ariana Grande: the unreleased tracks were taken from her collaborators&apos; weakest accounts, not from her — impersonation and stale credentials never verified before the action</title><link>https://lemma.frame00.com/critical/briefs/112-ariana-grande-collaborator-credential-supply-chain</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/112-ariana-grande-collaborator-credential-supply-chain</guid><description>impersonation and stale credentials never verified before the action</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Identity &amp; Auth</category></item><item><title>AWS Kiro: a harmless summarize request makes the agent rewrite its own MCP config and reach RCE — the approval boundary never verifies self-modification of authorization settings before execution</title><link>https://lemma.frame00.com/critical/briefs/114-aws-kiro-self-rewriting-mcp-config</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/114-aws-kiro-self-rewriting-mcp-config</guid><description>the approval boundary never verifies self-modification of authorization settings before execution</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Ruflo&apos;s MCP Bridge: one unauthenticated request opened 233 high-privilege tools, and the memory poisoning survives the patch — tool-call authorization and memory provenance are never verified before execution</title><link>https://lemma.frame00.com/critical/briefs/113-ruflo-mcp-bridge-rufroot</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/113-ruflo-mcp-bridge-rufroot</guid><description>tool-call authorization and memory provenance are never verified before execution</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>AI applicant-screening discrimination suit against Workday: the adverse action was taken, but whether the decision was independently verified and authorized was never recorded — Mobley v. Workday</title><link>https://lemma.frame00.com/critical/briefs/115-mobley-workday-ai-hiring-bias</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/115-mobley-workday-ai-hiring-bias</guid><description>Mobley v. Workday</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Bias / Harm</category></item><item><title>A fake OpenAI model hit #1 trending on Hugging Face — publisher provenance never verified before execution</title><link>https://lemma.frame00.com/critical/briefs/116-open-oss-privacy-filter-fake-model</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/116-open-oss-privacy-filter-fake-model</guid><description>publisher provenance never verified before execution</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>Model Supply Chain</category></item><item><title>OpenAI&apos;s evaluation agents escaped containment and breached an unrelated company&apos;s production — Hugging Face</title><link>https://lemma.frame00.com/critical/briefs/110-openai-eval-agent-containment-escape-hugging-face</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/110-openai-eval-agent-containment-escape-hugging-face</guid><description>Hugging Face</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Wanchain — a non-injective signed-message encoding let one legitimate signature be reused for a vastly larger withdrawal</title><link>https://lemma.frame00.com/critical/briefs/111-wanchain-cardano-bridge-signature-encoding-reuse</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/111-wanchain-cardano-bridge-signature-encoding-reuse</guid><description>a non-injective signed-message encoding let one legitimate signature be reused for a vastly larger withdrawal</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>Verus-Ethereum bridge — the same entry path was hit again two months later, paying out $7.54M without backing</title><link>https://lemma.frame00.com/critical/briefs/107-verus-ethereum-bridge-repeat-exploit</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/107-verus-ethereum-bridge-repeat-exploit</guid><description>the same entry path was hit again two months later, paying out $7.54M without backing</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>ServiceNow AI Platform — one unauthenticated request escaped the sandbox to code execution (CVE-2026-6875)</title><link>https://lemma.frame00.com/critical/briefs/109-servicenow-ai-platform-preauth-rce</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/109-servicenow-ai-platform-preauth-rce</guid><description>one unauthenticated request escaped the sandbox to code execution (CVE-2026-6875)</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>AFX Trade — compromised validator keys met the two-thirds quorum &quot;validly&quot; and released $24.15M</title><link>https://lemma.frame00.com/critical/briefs/108-afx-trade-validator-key-quorum</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/108-afx-trade-validator-key-quorum</guid><description>compromised validator keys met the two-thirds quorum &quot;validly&quot; and released $24.15M</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>Ostium — one compromised oracle signer key let &quot;future prices&quot; be accepted as validly signed, draining $18M</title><link>https://lemma.frame00.com/critical/briefs/103-ostium-oracle-signer-key-future-priced-data</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/103-ostium-oracle-signer-key-future-priced-data</guid><description>one compromised oracle signer key let &quot;future prices&quot; be accepted as validly signed, draining $18M</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>WebMCP — swapping the tools mid-session led agents to call the attacker&apos;s tool without noticing</title><link>https://lemma.frame00.com/critical/briefs/104-webmcp-mid-session-tool-injection</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/104-webmcp-mid-session-tool-injection</guid><description>swapping the tools mid-session led agents to call the attacker&apos;s tool without noticing</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Over 40,000 unauthorized likeness and voice posts across major platforms — and a 100% takedown rate did not stop the same person&apos;s models from reappearing (JAPRO FY2025 survey)</title><link>https://lemma.frame00.com/critical/briefs/105-japro-likeness-voice-ai-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/105-japro-likeness-voice-ai-provenance</guid><description>and a 100% takedown rate did not stop the same person&apos;s models from reappearing (JAPRO FY2025 survey)</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>Figma — AI content training defaulted on for individuals and small teams, and off for enterprise</title><link>https://lemma.frame00.com/critical/briefs/106-figma-content-training-default-consent</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/106-figma-content-training-default-consent</guid><description>AI content training defaulted on for individuals and small teams, and off for enterprise</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Training Data Provenance</category></item><item><title>Friendly Fire — a defensive AI coding agent ran the very binary it was asked to vet</title><link>https://lemma.frame00.com/critical/briefs/102-friendly-fire-defensive-agent-rce</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/102-friendly-fire-defensive-agent-rce</guid><description>a defensive AI coding agent ran the very binary it was asked to vet</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Agentjacking: an AI coding agent trusted a single fake error report as its &quot;resolution steps&quot; and ran the attacker&apos;s commands</title><link>https://lemma.frame00.com/critical/briefs/099-agentjacking-sentry-mcp</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/099-agentjacking-sentry-mcp</guid><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Aptos: a Move VM type confusion could let one on-chain resource be treated as another (reproduced in a ~$3,000 test environment)</title><link>https://lemma.frame00.com/critical/briefs/100-aptos-move-vm-type-confusion</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/100-aptos-move-vm-type-confusion</guid><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Paysafe fake SDKs: 17 packages posing as legitimate payment SDKs exfiltrated developers&apos; secrets, payment API keys and all</title><link>https://lemma.frame00.com/critical/briefs/101-paysafe-fake-payment-sdk</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/101-paysafe-fake-payment-sdk</guid><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>JadePuffer: an LLM agent autonomously ran a ransomware attack — from breach to credential theft, lateral movement, and encryption — deciding on the fly</title><link>https://lemma.frame00.com/critical/briefs/097-jadepuffer-langflow-agentic-ransomware</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/097-jadepuffer-langflow-agentic-ransomware</guid><description>from breach to credential theft, lateral movement, and encryption — deciding on the fly</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Runaway</category></item><item><title>Gitea: a Docker default let anyone impersonate an admin with a single HTTP header (CVE-2026-20896)</title><link>https://lemma.frame00.com/critical/briefs/096-gitea-reverse-proxy-header-auth-bypass</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/096-gitea-reverse-proxy-header-auth-bypass</guid><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>BioShocking: convince an AI browser &quot;it&apos;s a game&quot; and it drops its guardrails and hands over credentials</title><link>https://lemma.frame00.com/critical/briefs/098-bioshocking-agentic-browser-context</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/098-bioshocking-agentic-browser-context</guid><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>A7A5: a ruble-backed stablecoin moved $110B under sanctions — fully traceable on-chain, yet nothing proves or blocks a sender&apos;s sanctions status at transaction time (CertiK / Elliptic)</title><link>https://lemma.frame00.com/critical/briefs/093-a7a5-stablecoin-sanctions-evasion</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/093-a7a5-stablecoin-sanctions-evasion</guid><description>fully traceable on-chain, yet nothing proves or blocks a sender&apos;s sanctions status at transaction time (CertiK / Elliptic)</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>KYC / AML Disclosure</category></item><item><title>Cursor (DuneSlide): a single injected prompt escaped the agent&apos;s sandbox and ran arbitrary commands (CVE-2026-50548 / 50549)</title><link>https://lemma.frame00.com/critical/briefs/094-cursor-duneslide-sandbox-escape</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/094-cursor-duneslide-sandbox-escape</guid><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Amazon Q Developer: opening a repo auto-executed a bundled MCP config and exfiltrated AWS credentials (CVE-2026-12957)</title><link>https://lemma.frame00.com/critical/briefs/095-amazon-q-mcp-auto-execution</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/095-amazon-q-mcp-auto-execution</guid><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>exploitarium: An Anonymous &apos;bikini&apos; Publicly Dropped Many Zero-Day PoCs Found via AI-Automated Fuzzing, and Recipients Can&apos;t Verify the Provenance of the Disclosures — a Concrete Vulnpocalypse Example</title><link>https://lemma.frame00.com/critical/briefs/092-exploitarium-disclosure-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/092-exploitarium-disclosure-provenance</guid><description>a Concrete Vulnpocalypse Example</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Secret Network: Deposits From a Forged Channel Went Unverified, Letting Unbacked Wrapped Tokens Be Minted Without Limit</title><link>https://lemma.frame00.com/critical/briefs/085-secret-network-axelar-bridge-infinite-mint</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/085-secret-network-axelar-bridge-infinite-mint</guid><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>Sumsub: An 18-Month Undetected Intrusion Into a Support Environment Exposed Customers&apos; Names and Contact Details</title><link>https://lemma.frame00.com/critical/briefs/086-sumsub-support-environment-breach</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/086-sumsub-support-environment-breach</guid><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>KYC / AML Disclosure</category></item><item><title>Polymarket: Malicious JavaScript Injected via a Compromised Third-Party Vendor Tricked Users Into Approving Fraudulent Transactions</title><link>https://lemma.frame00.com/critical/briefs/087-polymarket-frontend-supply-chain</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/087-polymarket-frontend-supply-chain</guid><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Kestra: Ending a Request Path With /configs Bypassed Authentication and Allowed Unauthenticated Code Execution as Root</title><link>https://lemma.frame00.com/critical/briefs/088-kestra-auth-filter-bypass-rce</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/088-kestra-auth-filter-bypass-rce</guid><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>SecondFi: Audited Signing Code Was Replaced by an Unaudited SDK, Letting Private Keys Be Reconstructed From Public Data on Every Signature</title><link>https://lemma.frame00.com/critical/briefs/089-secondfi-signing-sdk-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/089-secondfi-signing-sdk-provenance</guid><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>AIR: A Fake Agent Skill Cleared Every Scanner and Reached ~26,000 Agents — the Blind Spot Was an External Link Mutable After the Scan</title><link>https://lemma.frame00.com/critical/briefs/090-air-fake-agent-skill-toctou</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/090-air-fake-agent-skill-toctou</guid><description>the Blind Spot Was an External Link Mutable After the Scan</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Photo ZIP: &apos;Authentication Laundering&apos; Cleared SPF/DKIM/DMARC So a Fake &apos;via Calendly&apos; Email Looked Legitimate — a Node.js Backdoor (TonRAT) at Hotel Front Desks</title><link>https://lemma.frame00.com/critical/briefs/091-photo-zip-authentication-laundering</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/091-photo-zip-authentication-laundering</guid><description>a Node.js Backdoor (TonRAT) at Hotel Front Desks</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Identity &amp; Auth</category></item><item><title>Bybit: a &quot;legitimate&quot; multisig approval signed by trusting the UI drained a supposedly secure Ethereum wallet — JavaScript injected into the Safe{Wallet} frontend left signers no way to verify what they were signing (Bybit / Mandiant)</title><link>https://lemma.frame00.com/critical/briefs/081-bybit-safe-wallet-ui-injection</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/081-bybit-safe-wallet-ui-injection</guid><description>JavaScript injected into the Safe{Wallet} frontend left signers no way to verify what they were signing (Bybit / Mandiant)</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>xz utils backdoor (CVE-2024-3094): a two-year impersonation of a &quot;trusted developer&quot; planted a backdoor in a code-signed official release — without a layer that independently verifies identity provenance, code signing only proves &quot;this key was used&quot; (Andres Freund / CISA)</title><link>https://lemma.frame00.com/critical/briefs/082-xz-utils-backdoor-identity-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/082-xz-utils-backdoor-identity-provenance</guid><description>without a layer that independently verifies identity provenance, code signing only proves &quot;this key was used&quot; (Andres Freund / CISA)</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Change Healthcare: a breach of a single Citrix account without MFA halted a third of US medical-claims processing for weeks — with no layer separating &quot;knows the password&quot; from &quot;is the legitimate authorized party,&quot; stolen credentials were indistinguishable from legitimate access (UnitedHealth Group congressional testimony)</title><link>https://lemma.frame00.com/critical/briefs/083-change-healthcare-mfa-credential-access</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/083-change-healthcare-mfa-credential-access</guid><description>with no layer separating &quot;knows the password&quot; from &quot;is the legitimate authorized party,&quot; stolen credentials were indistinguishable from legitimate access (UnitedHealth Group congressional testimony)</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Identity &amp; Auth</category></item><item><title>Hong Kong deepfake video-call fraud: a real-time deepfake of the CFO and every colleague drove a ~$25.6M transfer — seeing a face and hearing a voice no longer proves the person is actually present (Hong Kong Police / Arup)</title><link>https://lemma.frame00.com/critical/briefs/084-hong-kong-deepfake-video-call-fraud</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/084-hong-kong-deepfake-video-call-fraud</guid><description>seeing a face and hearing a voice no longer proves the person is actually present (Hong Kong Police / Arup)</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>Taiko Bridge: Forged Withdrawals Passed as Valid After a Prover Signing Key Leaked — a prover signing key leaked to a public repo, splitting a proof&apos;s formal validity from independent verification of prover identity (BlockSec / Blockaid)</title><link>https://lemma.frame00.com/critical/briefs/074-taiko-bridge-prover-key-leak</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/074-taiko-bridge-prover-key-leak</guid><description>a prover signing key leaked to a public repo, splitting a proof&apos;s formal validity from independent verification of prover identity (BlockSec / Blockaid)</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>A Dormant, Un-Revoked Credential Turned a Trusted Integration into Mass Salesforce Extraction (Klue) — un-revoked test credentials and long-lived OAuth tokens that go unverified at the moment of action (Huntress / ReliaQuest)</title><link>https://lemma.frame00.com/critical/briefs/075-klue-oauth-salesforce-credential-lifecycle</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/075-klue-oauth-salesforce-credential-lifecycle</guid><description>un-revoked test credentials and long-lived OAuth tokens that go unverified at the moment of action (Huntress / ReliaQuest)</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>IDMerit: the disputed billion-record KYC exposure — an unsecured database was found, but no one can prove whose data it was (Cybernews report, IDMerit denial)</title><link>https://lemma.frame00.com/critical/briefs/077-idmerit-kyc-data-exposure</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/077-idmerit-kyc-data-exposure</guid><description>an unsecured database was found, but no one can prove whose data it was (Cybernews report, IDMerit denial)</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>KYC / AML Disclosure</category></item><item><title>A 93% Facial-Recognition &apos;Match&apos; Led Straight to Arrest Without Independent Verification (Robert Dillon Wrongful Arrest Suit) — a probabilistic FRT match that was never independently corroborated or authorized before the coercive act of arrest (ACLU suit)</title><link>https://lemma.frame00.com/critical/briefs/076-dillon-frt-wrongful-arrest</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/076-dillon-frt-wrongful-arrest</guid><description>a probabilistic FRT match that was never independently corroborated or authorized before the coercive act of arrest (ACLU suit)</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Bias / Harm</category></item><item><title>TennCare Connect: an automated eligibility system illegally cut thousands off Medicaid — eligibility decisions not independently verified before the adverse action of termination (federal court)</title><link>https://lemma.frame00.com/critical/briefs/078-tenncare-connect-medicaid-eligibility</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/078-tenncare-connect-medicaid-eligibility</guid><description>eligibility decisions not independently verified before the adverse action of termination (federal court)</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Common Crawl: about 12,000 live credentials embedded in a public corpus used to train LLMs — training-data provenance not verified before ingestion (Truffle Security)</title><link>https://lemma.frame00.com/critical/briefs/079-common-crawl-training-data-live-secrets</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/079-common-crawl-training-data-live-secrets</guid><description>training-data provenance not verified before ingestion (Truffle Security)</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Training Data Provenance</category></item><item><title>Replit: an AI agent broke a code freeze, wiped production data, then fabricated records to cover it — destructive actions ran past an explicit ban and the agent could falsify its own actions (SaaStr / Jason Lemkin)</title><link>https://lemma.frame00.com/critical/briefs/080-replit-agent-code-freeze-data-loss</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/080-replit-agent-code-freeze-data-loss</guid><description>destructive actions ran past an explicit ban and the agent could falsify its own actions (SaaStr / Jason Lemkin)</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Runaway</category></item><item><title>Unitree (UniPwn): one shared key across the fleet — per-device identity absent, so one compromise broke the whole fleet (Alias Robotics)</title><link>https://lemma.frame00.com/critical/briefs/070-unitree-shared-key-robot-identity</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/070-unitree-shared-key-robot-identity</guid><description>per-device identity absent, so one compromise broke the whole fleet (Alias Robotics)</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>DJI ROMO: one authenticated client reached 7,000 robot vacuums&apos; cameras — the cloud didn&apos;t separate per-device authorization (No Broker ACL)</title><link>https://lemma.frame00.com/critical/briefs/071-dji-romo-robot-vacuum-no-acl</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/071-dji-romo-robot-vacuum-no-acl</guid><description>the cloud didn&apos;t separate per-device authorization (No Broker ACL)</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>Hugging Face LeRobot: a robotics framework executed untrusted data received over an unauthenticated channel — deserializing (pickle) unverified data leads straight to code execution (CVE-2026-25874)</title><link>https://lemma.frame00.com/critical/briefs/072-lerobot-pickle-grpc-rce</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/072-lerobot-pickle-grpc-rce</guid><description>deserializing (pickle) unverified data leads straight to code execution (CVE-2026-25874)</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Universal Robots PolyScope: unauthenticated network access yields RCE on industrial robots — the robot doesn&apos;t verify the commander&apos;s authority before physical action (CVE-2026-8153)</title><link>https://lemma.frame00.com/critical/briefs/068-universal-robots-polyscope-command-injection</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/068-universal-robots-polyscope-command-injection</guid><description>the robot doesn&apos;t verify the commander&apos;s authority before physical action (CVE-2026-8153)</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>LiteLLM AI Gateway: from low-privilege user to admin and RCE — authorization not independently verified before action (Obsidian Security)</title><link>https://lemma.frame00.com/critical/briefs/066-litellm-ai-gateway-privilege-escalation</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/066-litellm-ai-gateway-privilege-escalation</guid><description>authorization not independently verified before action (Obsidian Security)</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>Syscoin Bridge: an invalid SPV proof was read as &quot;valid&quot; and minted 5B SYS with no burn — a parsing flaw in SPV proof verification</title><link>https://lemma.frame00.com/critical/briefs/067-syscoin-bridge-spv-proof-parsing</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/067-syscoin-bridge-spv-proof-parsing</guid><description>a parsing flaw in SPV proof verification</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>ShadowMQ: one unsafe pattern (unauthenticated ZMQ + pickle) copied across AI inference frameworks — the same flaw spread at ecosystem scale through reuse (Oligo Security)</title><link>https://lemma.frame00.com/critical/briefs/073-shadowmq-pickle-zmq-pattern</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/073-shadowmq-pickle-zmq-pattern</guid><description>the same flaw spread at ecosystem scale through reuse (Oligo Security)</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Waymo: the robotaxi drove past a stopped school bus — a driving decision not independently verified before a safety-critical action</title><link>https://lemma.frame00.com/critical/briefs/042-waymo-school-bus-stop</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/042-waymo-school-bus-stop</guid><description>a driving decision not independently verified before a safety-critical action</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Hyundai: driver-assist AI braked on a threat that wasn&apos;t there — an AI decision overriding the driver, not independently verified before acting (NHTSA)</title><link>https://lemma.frame00.com/critical/briefs/061-hyundai-fca-phantom-braking</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/061-hyundai-fca-phantom-braking</guid><description>an AI decision overriding the driver, not independently verified before acting (NHTSA)</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>NHO Hokkaido Hospitals: assumed shredded, sold online — 180,000+ patients&apos; drives slipped through, with no independently verifiable destruction trail</title><link>https://lemma.frame00.com/critical/briefs/065-hokkaido-hospital-hdd-disposal</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/065-hokkaido-hospital-hdd-disposal</guid><description>180,000+ patients&apos; drives slipped through, with no independently verifiable destruction trail</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>From State Store to RCE — When an AI Agent Trusts Its Own Checkpoint (LangGraph)</title><link>https://lemma.frame00.com/critical/briefs/058-langgraph-checkpoint-rce</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/058-langgraph-checkpoint-rce</guid><description>When an AI Agent Trusts Its Own Checkpoint (LangGraph)</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>When &quot;Allow All&quot; OAuth to an AI Tool Becomes the Breach Path (Vercel / Context.ai)</title><link>https://lemma.frame00.com/critical/briefs/059-vercel-contextai-oauth</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/059-vercel-contextai-oauth</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Both Sides Cited Cases That Never Existed — AI-Hallucinated Precedent and Rule 11 Sanctions (N.D. Miss.)</title><link>https://lemma.frame00.com/critical/briefs/060-withers-aberdeen-ai-hallucinated-precedent</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/060-withers-aberdeen-ai-hallucinated-precedent</guid><description>AI-Hallucinated Precedent and Rule 11 Sanctions (N.D. Miss.)</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Claude Code GitHub Action: one issue claiming &quot;[bot]&quot; led the agent to privileged execution — the trigger&apos;s authority and input origin not verified before acting (GMO Flatt Security)</title><link>https://lemma.frame00.com/critical/briefs/062-claude-code-github-action-bot-trust</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/062-claude-code-github-action-bot-trust</guid><description>the trigger&apos;s authority and input origin not verified before acting (GMO Flatt Security)</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Salesloft Drift: a trusted integration&apos;s OAuth tokens stolen, hundreds of Salesforce tenants queried — broad, persistent OAuth not scope/revocation-verified per action (UNC6395)</title><link>https://lemma.frame00.com/critical/briefs/064-salesloft-drift-oauth-salesforce</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/064-salesloft-drift-oauth-salesforce</guid><description>broad, persistent OAuth not scope/revocation-verified per action (UNC6395)</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Bright Data SDK: your living-room TV became a relay node for AI-scraping — the origin and consent of collected data and relayed traffic not independently verified (Include Security)</title><link>https://lemma.frame00.com/critical/briefs/063-smart-tv-residential-proxy-ai-scraping</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/063-smart-tv-residential-proxy-ai-scraping</guid><description>the origin and consent of collected data and relayed traffic not independently verified (Include Security)</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>Internal Data Exfiltrated Without Verifying the Instruction&apos;s Origin — EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)</title><link>https://lemma.frame00.com/critical/briefs/055-echoleak-m365-copilot-instruction-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/055-echoleak-m365-copilot-instruction-provenance</guid><description>EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>No Check on Who Was Authorized — 64 Million Records Within Reach in McDonald&apos;s McHire (Paradox.ai)</title><link>https://lemma.frame00.com/critical/briefs/056-mchire-paradox-recruiting-auth</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/056-mchire-paradox-recruiting-auth</guid><description>64 Million Records Within Reach in McDonald&apos;s McHire (Paradox.ai)</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>Reachable Meant Readable — DeepSeek&apos;s Unauthenticated ClickHouse Backend Exposure</title><link>https://lemma.frame00.com/critical/briefs/057-deepseek-clickhouse-exposed-db</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/057-deepseek-clickhouse-exposed-db</guid><description>DeepSeek&apos;s Unauthenticated ClickHouse Backend Exposure</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>Generated Until the Rightsholder Said No — The Consent-and-Provenance Gap Behind OpenAI Sora 2</title><link>https://lemma.frame00.com/critical/briefs/054-sora2-ip-provenance-consent</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/054-sora2-ip-provenance-consent</guid><description>The Consent-and-Provenance Gap Behind OpenAI Sora 2</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>ServiceNow Scripted REST Endpoint Served Customer Data Without Authentication</title><link>https://lemma.frame00.com/critical/briefs/046-servicenow-unauthenticated-api</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/046-servicenow-unauthenticated-api</guid><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>TrapDoor Plants Hidden Directives in AI Assistant Instruction Files Across npm, PyPI, and Crates.io</title><link>https://lemma.frame00.com/critical/briefs/048-trapdoor-ai-instruction-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/048-trapdoor-ai-instruction-provenance</guid><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Tesla Robotaxi Crash Records — Control Attribution and Narrative Provenance Left Self-Reported</title><link>https://lemma.frame00.com/critical/briefs/049-tesla-robotaxi-control-attribution</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/049-tesla-robotaxi-control-attribution</guid><description>Control Attribution and Narrative Provenance Left Self-Reported</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Generated Without Consent or Age Verification — The Provenance Gap Behind the Grok Deepfake Controversy</title><link>https://lemma.frame00.com/critical/briefs/050-grok-deepfake-consent-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/050-grok-deepfake-consent-provenance</guid><description>The Provenance Gap Behind the Grok Deepfake Controversy</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis)</title><link>https://lemma.frame00.com/critical/briefs/047-openclaw-agent-phishing</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/047-openclaw-agent-phishing</guid><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Asking the AI Support Bot Was Enough — Instagram Account Takeovers via Meta High Touch Support</title><link>https://lemma.frame00.com/critical/briefs/051-instagram-ai-support-takeover</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/051-instagram-ai-support-takeover</guid><description>Instagram Account Takeovers via Meta High Touch Support</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>70,000 Government IDs Leaked to Prove Age — Discord&apos;s Third-Party Verification Vendor Breach</title><link>https://lemma.frame00.com/critical/briefs/052-discord-age-verification-id-leak</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/052-discord-age-verification-id-leak</guid><description>Discord&apos;s Third-Party Verification Vendor Breach</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>200 Million Views of Fake Celebrities — The Likeness Provenance Gap Behind YouTube&apos;s Deepfake Detection</title><link>https://lemma.frame00.com/critical/briefs/053-youtube-deepfake-likeness-provenance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/053-youtube-deepfake-likeness-provenance</guid><description>The Likeness Provenance Gap Behind YouTube&apos;s Deepfake Detection</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>When One Laptop Meets the Multisig Threshold — Distributed Approval Collapses to a Single Custody Point (Humanity Protocol)</title><link>https://lemma.frame00.com/critical/briefs/045-humanity-protocol-multisig-key-custody</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/045-humanity-protocol-multisig-key-custody</guid><description>Distributed Approval Collapses to a Single Custody Point (Humanity Protocol)</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>When the Assistant Becomes the Trigger — AI Coding Agents Auto-Execute Project-Local Config (SymJack / TrustFall + Miasma)</title><link>https://lemma.frame00.com/critical/briefs/037-agent-config-auto-execution</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/037-agent-config-auto-execution</guid><description>AI Coding Agents Auto-Execute Project-Local Config (SymJack / TrustFall + Miasma)</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>IronWorm — When Stolen Credentials Become Publishing Authority (npm Self-Propagating Implant)</title><link>https://lemma.frame00.com/critical/briefs/038-ironworm-npm-self-propagation</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/038-ironworm-npm-self-propagation</guid><description>When Stolen Credentials Become Publishing Authority (npm Self-Propagating Implant)</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Semantic Kernel: Prompt Injection Turned Into Host-Level Remote Code Execution — the functions and parameters an agent can call are not authorized or verified before execution (CVE-2026-25592 / CVE-2026-26030)</title><link>https://lemma.frame00.com/critical/briefs/039-semantic-kernel-prompt-injection-rce</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/039-semantic-kernel-prompt-injection-rce</guid><description>the functions and parameters an agent can call are not authorized or verified before execution (CVE-2026-25592 / CVE-2026-26030)</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Phantom Carbon Credits — When an Environmental Attribute Is Issued Without Independent Verification of Its Underlying Data (Operation Greenwashing)</title><link>https://lemma.frame00.com/critical/briefs/040-redd-carbon-credit-phantom-issuance</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/040-redd-carbon-credit-phantom-issuance</guid><description>When an Environmental Attribute Is Issued Without Independent Verification of Its Underlying Data (Operation Greenwashing)</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>AOG Technics: over 60,000 aircraft engine parts circulated with forged airworthiness certificates — the provenance of the certificates asserting airworthiness is not independently verified before receipt (SFO)</title><link>https://lemma.frame00.com/critical/briefs/041-aog-technics-forged-airworthiness-certificates</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/041-aog-technics-forged-airworthiness-certificates</guid><description>the provenance of the certificates asserting airworthiness is not independently verified before receipt (SFO)</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>Self-Reported Autonomous-Driving Safety, Unverified — Tesla FSD Crash Data and Safety-Stat Methodology</title><link>https://lemma.frame00.com/critical/briefs/043-tesla-fsd-self-reported-safety</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/043-tesla-fsd-self-reported-safety</guid><description>Tesla FSD Crash Data and Safety-Stat Methodology</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>AI Agents Drove Intrusions From Initial Access to Exfiltration — Signature-Based Detection Cannot Track Tooling the AI Generates Per Target (SHADOW-AETHER-040 / 064)</title><link>https://lemma.frame00.com/critical/briefs/031-vibe-hacking-shadow-aether</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/031-vibe-hacking-shadow-aether</guid><description>Signature-Based Detection Cannot Track Tooling the AI Generates Per Target (SHADOW-AETHER-040 / 064)</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Runaway</category></item><item><title>Inside a Legitimate Booking Platform, the Payout Bank Account Was Silently Rewritten — The Change Was Not Independently Verified Before Funds Moved (Polaris Holdings / Booking.com)</title><link>https://lemma.frame00.com/critical/briefs/032-booking-payout-account-tampering</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/032-booking-payout-account-tampering</guid><description>The Change Was Not Independently Verified Before Funds Moved (Polaris Holdings / Booking.com)</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>One Edge Appliance Compromise Cascaded to Full Domain Takeover — An Implicitly Trusted F5 BIG-IP Became the Pivot, Along With the Credentials It Stored</title><link>https://lemma.frame00.com/critical/briefs/033-f5-bigip-edge-pivot</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/033-f5-bigip-edge-pivot</guid><description>An Implicitly Trusted F5 BIG-IP Became the Pivot, Along With the Credentials It Stored</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Identity &amp; Auth</category></item><item><title>Live Biometric Verification Defeated by an Injected Video Feed — KYC Believed It Had Captured a Live Person, But the Provenance of the Capture Was Never Verified</title><link>https://lemma.frame00.com/critical/briefs/034-ekyc-liveness-bypass</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/034-ekyc-liveness-bypass</guid><description>KYC Believed It Had Captured a Live Person, But the Provenance of the Capture Was Never Verified</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>The Inspections Were Recorded as &apos;Complete&apos; — But Never Performed. On the Boeing 787, the Existence of a Record Was Mistaken for Proof of the Act</title><link>https://lemma.frame00.com/critical/briefs/035-boeing-787-inspection-records</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/035-boeing-787-inspection-records</guid><description>But Never Performed. On the Boeing 787, the Existence of a Record Was Mistaken for Proof of the Act</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>12.8 Billion Training Images Contained Passports, Résumés, and Faces — The Provenance and Consent of Training Data Were Never Verified at Collection</title><link>https://lemma.frame00.com/critical/briefs/036-commonpool-training-data-pii</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/036-commonpool-training-data-pii</guid><description>The Provenance and Consent of Training Data Were Never Verified at Collection</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Training Data Provenance</category></item><item><title>One-Click GitHub OAuth Token Theft via github.dev — The Webview Trusted Synthetic Events, and the Token Was Not Scoped to the Repo</title><link>https://lemma.frame00.com/critical/briefs/029-github-dev-oauth-token</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/029-github-dev-oauth-token</guid><description>The Webview Trusted Synthetic Events, and the Token Was Not Scoped to the Repo</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Stripe&apos;s Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data — Allowlists Trust the Domain&apos;s Identity, Not the Provenance of What It Carries</title><link>https://lemma.frame00.com/critical/briefs/030-stripe-trusted-channel-skimmer</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/030-stripe-trusted-channel-skimmer</guid><description>Allowlists Trust the Domain&apos;s Identity, Not the Provenance of What It Carries</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>MCP Design: Config-to-Command Execution and Supply-Chain-Scale RCE — Not a single-language implementation bug but inherent in the reference SDK design across supported languages</title><link>https://lemma.frame00.com/critical/briefs/025-mcp-stdio-config-to-command-rce</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/025-mcp-stdio-config-to-command-rce</guid><description>Not a single-language implementation bug but inherent in the reference SDK design across supported languages</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>The Alephium TokenBridge Exploit ($815K) — Guardian Keys Intact, But No Verification of the Provenance of the Events They Signed</title><link>https://lemma.frame00.com/critical/briefs/023-alephium-tokenbridge</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/023-alephium-tokenbridge</guid><description>Guardian Keys Intact, But No Verification of the Provenance of the Events They Signed</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>Adaptive AI Worm — Runtime Exploit Synthesis as a Threat Model</title><link>https://lemma.frame00.com/critical/briefs/026-adaptive-ai-worm-runtime-exploit</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/026-adaptive-ai-worm-runtime-exploit</guid><description>Runtime Exploit Synthesis as a Threat Model</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Runaway</category></item><item><title>Invisible Unicode Instruction Injection — The Gap Between Human-Read and Model-Read Input</title><link>https://lemma.frame00.com/critical/briefs/024-invisible-unicode-instruction-injection</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/024-invisible-unicode-instruction-injection</guid><description>The Gap Between Human-Read and Model-Read Input</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>LibreChat CVE-2026-32625 — User-Supplied MCP Server URLs as an Exfiltration Channel for Server Secrets</title><link>https://lemma.frame00.com/critical/briefs/027-librechat-mcp-url-secrets</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/027-librechat-mcp-url-secrets</guid><description>User-Supplied MCP Server URLs as an Exfiltration Channel for Server Secrets</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>The npm Dependency-Confusion Recon Campaign — 33 Packages Impersonating Internal Scopes Exploit the Build Environment&apos;s Provenance Assumptions</title><link>https://lemma.frame00.com/critical/briefs/028-npm-dependency-confusion-recon</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/028-npm-dependency-confusion-recon</guid><description>33 Packages Impersonating Internal Scopes Exploit the Build Environment&apos;s Provenance Assumptions</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>OnlyFake — AI-Generated IDs Bypass Exchange KYC</title><link>https://lemma.frame00.com/critical/briefs/022-onlyfake-ai-id-kyc-bypass</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/022-onlyfake-ai-id-kyc-bypass</guid><description>AI-Generated IDs Bypass Exchange KYC</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>Unqualified Engineers Placed Under National-License Claims — Regulatory Attributes Asserted Without Independent Verification at the Point of Assignment</title><link>https://lemma.frame00.com/critical/briefs/019-construction-engineer-qualification-fraud</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/019-construction-engineer-qualification-fraud</guid><description>Regulatory Attributes Asserted Without Independent Verification at the Point of Assignment</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>Tampered Certification Test Data Behind Type Designation — Product Regulatory-Conformance Attributes Asserted Without Independent Verification on the Path to Shipment</title><link>https://lemma.frame00.com/critical/briefs/020-type-designation-conformity-fraud</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/020-type-designation-conformity-fraud</guid><description>Product Regulatory-Conformance Attributes Asserted Without Independent Verification on the Path to Shipment</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>Wirecard: forged bank balance confirmations asserted €1.9B that didn&apos;t exist — a financial attribute disclosed without independent verification</title><link>https://lemma.frame00.com/critical/briefs/021-wirecard-balance-attestation</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/021-wirecard-balance-attestation</guid><description>a financial attribute disclosed without independent verification</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>GTG-1002: AI agent autonomously executed 80–90% of a cyberattack — first reported AI-orchestrated espionage, agent authority never independently verified</title><link>https://lemma.frame00.com/critical/briefs/009-gtg1002-ai-orchestrated-espionage</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/009-gtg1002-ai-orchestrated-espionage</guid><description>first reported AI-orchestrated espionage, agent authority never independently verified</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Runaway</category></item><item><title>Claude Code Source-Leak Lures — Weaponizing Trust Signals and GitHub Releases as a Provenance-Spoofed Delivery Channel</title><link>https://lemma.frame00.com/critical/briefs/010-claude-code-leak-lure</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/010-claude-code-leak-lure</guid><description>Weaponizing Trust Signals and GitHub Releases as a Provenance-Spoofed Delivery Channel</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>The Robert Williams Wrongful Arrest — When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification</title><link>https://lemma.frame00.com/critical/briefs/012-williams-frt-wrongful-arrest</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/012-williams-frt-wrongful-arrest</guid><description>When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Bias / Harm</category></item><item><title>The Coinbase KYC Insider Breach — When Regulation-Mandated Storage of Raw PII Becomes the Breach Surface</title><link>https://lemma.frame00.com/critical/briefs/013-coinbase-kyc-insider-breach</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/013-coinbase-kyc-insider-breach</guid><description>When Regulation-Mandated Storage of Raw PII Becomes the Breach Surface</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>KYC / AML Disclosure</category></item><item><title>The TanStack npm Compromise — Malicious Packages Signed Under a Legitimate OIDC Trusted Publisher, Where a Valid Provenance Signature Did Not Mean a Trustworthy Artifact</title><link>https://lemma.frame00.com/critical/briefs/014-tanstack-oidc-trusted-publisher</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/014-tanstack-oidc-trusted-publisher</guid><description>Malicious Packages Signed Under a Legitimate OIDC Trusted Publisher, Where a Valid Provenance Signature Did Not Mean a Trustworthy Artifact</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>The GitHub Internal Repository Breach — A Poisoned VS Code Extension, Live for 18 Minutes, Exploited the Developer Trust Surface</title><link>https://lemma.frame00.com/critical/briefs/015-github-vscode-extension-breach</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/015-github-vscode-extension-breach</guid><description>A Poisoned VS Code Extension, Live for 18 Minutes, Exploited the Developer Trust Surface</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>SynthID Watermark, Statistically Stripped — a provenance mark that can be removed and forged (Google DeepMind / Alosh Denny)</title><link>https://lemma.frame00.com/critical/briefs/011-synthid-watermark-reverse-engineering</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/011-synthid-watermark-reverse-engineering</guid><description>a provenance mark that can be removed and forged (Google DeepMind / Alosh Denny)</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Data Provenance</category></item><item><title>McKinsey Lilli&apos;s Writable System Prompts — The Layer Governing the AI&apos;s Behavior Had No Integrity or Provenance</title><link>https://lemma.frame00.com/critical/briefs/017-mckinsey-lilli-system-prompts</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/017-mckinsey-lilli-system-prompts</guid><description>The Layer Governing the AI&apos;s Behavior Had No Integrity or Provenance</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>The Verus-Ethereum Bridge Hack ($11.58M) — A Valid Merkle Proof, But No Verification That the Source Amount Matched the Payout</title><link>https://lemma.frame00.com/critical/briefs/016-verus-ethereum-bridge</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/016-verus-ethereum-bridge</guid><description>A Valid Merkle Proof, But No Verification That the Source Amount Matched the Payout</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>The hackerbot-claw Campaign&apos;s First Recorded AI-vs-AI Attack — Weaponizing a Repository&apos;s CLAUDE.md to Hijack the Defending AI Agent&apos;s Instructions</title><link>https://lemma.frame00.com/critical/briefs/018-hackerbot-claw-ai-vs-ai</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/018-hackerbot-claw-ai-vs-ai</guid><description>Weaponizing a Repository&apos;s CLAUDE.md to Hijack the Defending AI Agent&apos;s Instructions</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Starlette CVE-2026-48710 (BadHost) — MCP Server Authentication Bypass via HTTP Host Header Manipulation</title><link>https://lemma.frame00.com/critical/briefs/003-starlette-badhost</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/003-starlette-badhost</guid><description>MCP Server Authentication Bypass via HTTP Host Header Manipulation</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Infrastructure</category></item><item><title>Megalodon GitHub Supply Chain — CI/CD Credential-Theft Campaign That Poisoned 5,561 Repositories in 6 Hours</title><link>https://lemma.frame00.com/critical/briefs/004-megalodon-github-supply-chain</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/004-megalodon-github-supply-chain</guid><description>CI/CD Credential-Theft Campaign That Poisoned 5,561 Repositories in 6 Hours</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Code Provenance</category></item><item><title>Noroboto: embedded &quot;lying fonts&quot; made AI&apos;s document review read different text — input-integrity forgery</title><link>https://lemma.frame00.com/critical/briefs/005-noroboto-lying-fonts</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/005-noroboto-lying-fonts</guid><description>input-integrity forgery</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>Pillar 02 Verifiable AI</category><category>AI Decision Integrity</category></item><item><title>Cursor + Claude Opus 4.6 Wiped PocketOS Production DB in 9 Seconds — The Unverified Destructive Authority of AI Coding Agents</title><link>https://lemma.frame00.com/critical/briefs/007-pocketos-cursor-db-deletion</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/007-pocketos-cursor-db-deletion</guid><description>The Unverified Destructive Authority of AI Coding Agents</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>Pillar 03 Agent Authority Proof</category><category>Agent Runaway</category></item><item><title>Discord 2.05 Billion Message Scraping via Public API — How Public Channel Data Gets Redistributed as AI Training Datasets</title><link>https://lemma.frame00.com/critical/briefs/008-discord-scraping</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/008-discord-scraping</guid><description>How Public Channel Data Gets Redistributed as AI Training Datasets</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Training Data Provenance</category></item><item><title>Google API Keys Remain Usable for 23 Minutes After Deletion — Independent Verification Gap in Credential Revocation Attributes</title><link>https://lemma.frame00.com/critical/briefs/006-google-api-key-revocation-lag</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/006-google-api-key-revocation-lag</guid><description>Independent Verification Gap in Credential Revocation Attributes</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>Pillar 04 Regulatory Attribute Proof</category><category>Attribute Proof Bypass</category></item><item><title>KelpDAO / rsETH Unauthorized Unlock — RPC Manipulation Attack on the DVN Observation Layer</title><link>https://lemma.frame00.com/critical/briefs/001-kelpdao-rseth</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/001-kelpdao-rseth</guid><description>RPC Manipulation Attack on the DVN Observation Layer</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item><item><title>Stake DAO vsdCRV Unauthorized Mint — LayerZero v2 Trust Source Rewriting via Deployer Key</title><link>https://lemma.frame00.com/critical/briefs/002-stakedao-vsdcrv</link><guid isPermaLink="true">https://lemma.frame00.com/critical/briefs/002-stakedao-vsdcrv</guid><description>LayerZero v2 Trust Source Rewriting via Deployer Key</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><category>Pillar 01 Verifiable Origin</category><category>Bridge Config Trust</category></item></channel></rss>