OpenBao v2.6.3 is out! 🔐 Our latest 2.6 patch release is focused on security and bug fixes. Make sure to patch your instances accordingly! This update also includes fixes identified through the Patch the Planet initiative in partnership with Trail of Bits and OpenAI. Big thanks to all reporters, contributors, and the entire community! 🔗 Read the full changelog here: https://lnkd.in/e_CZjAUQ #OpenBao #SecretsManagement #OpenSSF #OpenSource #Security
OpenBao’s Post
More Relevant Posts
-
The OpenBao v2.7.0 Beta is here! 🚀✨ This major release brings game-changing post-quantum security, external cryptographic key support, and huge upgrades to scalability and control: 🔑 External Keys: Offload cryptographic operations directly to HSM or KMS-backed keys without storing key material in OpenBao. 🛡️ Post-Quantum Cryptography (PQC): Future-proof your stack with NIST FIPS 204 (ML-DSA) support in PKI and Transit engines, and more. 🐘 PostgreSQL Horizontal Scalability: Scale read traffic across standby nodes on the PostgreSQL storage backend using physical replication and RPC forwarding. ⚡ Strong Consistency Control: Prevent stale reads using X-Vault-Index and X-Vault-Inconsistent headers, complete with configurable node fallback behavior. 👥 Control Groups: Enforce dual-custody authorization with a new "control_group" ACL policy stanza, requiring second-party approval for sensitive paths. 📦 PebbleDB Storage Backend: A new embedded, high-performance storage backend built for single-node deployments using PebbleDB. A massive shoutout to all our incredible contributors helping us shape this major release! 🙌 Because this is a beta, your feedback is crucial to making the final GA release rock-solid! 👉 Check out the full release notes and grab the build here: https://lnkd.in/evJfcSrd #OpenBao #SecretsManagement #OpenSSF #OpenSource #Security #PostQuantum #PQC
To view or add a comment, sign in
-
New case study is up! We worked with TrustedStake so the system that automatically allocates delegated TAO on Bittensor is protected using confidential compute, and fully verifiable. TrustedStake manages over $20 million for 3,000+ delegators, with 500,000 transactions and $250M+ in volume processed year to date. The risk in a system like that is an attacker quietly changing code to steer stake into a thin subnet they set up in advance or stealing the delegator keys. Nobody notices until people try to exit. Now the signer builds reproducibly and runs in an enclave on Caution (YC S26). Change anything, app to OS, and the measurement no longer matches. The keys stay inside the enclave so if surrounding infra is compromised the keys remain secure. Working with the TrustedStake team was fantastic. They wanted security they could verify, not a box to check. World-class team, offering an amazing service to the Bittensor network. Full case study in the comments 👇
To view or add a comment, sign in
-
Spent a few hours on the `secretsync seal` command, which was writing out non-existent files if they didn't exist beforehand. Now it creates them first as needed when sealing, in line with how `--set` values work. Authenticated encryption is now correctly handling the case where the key doesn't match; it will unseal only what's been sealed under that key, rather than throwing away all data and starting over. This change affects the `--key` option for sealing. It checks if a file exists before writing to it, so there's no need to manually create the `.sealpub` label beforehand. If you don't specify a path, it will default to `~/.sealkey`. Key rotation is still built in, but now it also handles re-sealing under a new key without having to write the plaintext out first. https://lnkd.in/e_8gCaPv #AISecurity #AgentSecurity
secretsync — live run
To view or add a comment, sign in
-
In a company running several hundred in-house services, nobody can say which of this release's findings matter. That is not a staffing problem. Each service has an owner who knows what it does. Nobody knows what all of them load. The security team is asked to rank the scanner's list and has only a severity score to rank with. That score knows nothing about whether the package ever ran in this cluster. The gap is structural. Context lives per service, in the heads of the people who wrote it. The question is asked across all of them at once. No org chart closes that. What closes it is evidence nobody has to remember: which code, in each workload, actually executed under real traffic. With that, the list sorts itself. Without it, the order is a guess. More on ranking findings when nobody has the whole picture: https://lnkd.in/d9Ffkeem #VulnerabilityManagement #AppSec #PlatformEngineering
To view or add a comment, sign in
-
-
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.
To view or add a comment, sign in
-
-
Unbound’s DNSSEC validator can overflow a heap buffer while parsing a DNSKEY record supplied by a malicious DNS zone. CVE-2026-81642 affects teams running validating recursive resolvers. The issue is in DNSKEY parsing, where a crafted record can overrun the validator’s heap buffer. The practical priority: update to Unbound 1.26.1, or confirm that your vendor has backported the fix. Read the full SecAlerts article: https://lnkd.in/exw6wJur #DNSSEC #DNSecurity
To view or add a comment, sign in
-
-
Check Point has identified a critical vulnerability affecting several product versions, including R81.20, R82, R82.10, R81.10.x and R82.00.x. The vulnerability could allow a remote attacker to execute code on an affected Check Point Security Gateway or Management Server. The issue has been fixed, so I’d recommend checking your environment and making sure the appropriate update has been applied. Full remediation procedure and details from Check Point: https://lnkd.in/ep_VfcbQ
To view or add a comment, sign in
-
🚨 Medium-severity security fix in hbs@4.3.1 just released! Patches CVE-2026-87123: hbs vulnerable to Denial of Service via unhandled exception in async helper output escaping https://lnkd.in/edGuYu7X
To view or add a comment, sign in
-
Tool chaining turns two authorized tools into one attack. The agent has permission for every step, so identity controls flag nothing. In his latest blog, Jacob Abrams explains what containment requires: ��� Ringfence the environments where tools and MCP servers run 🔒 • Bind policy to process identity, not IP address 🧬 • Automate containment at machine speed⚡ Check it out: https://ow.ly/SJQR50ZJcaY
To view or add a comment, sign in
-
-
For years, the standard advice for grading your security headers was: run your site through a free online scanner, get a letter grade, done. In April 2026, after a year's notice, that scanner's programmatic API was shut down. The manual one-off scan still works. What stopped working is anything built to call it automatically, on a schedule, as part of a pipeline. That distinction matters because headers don't fail loudly. A reverse proxy migration drops one nobody remembered to carry over. A CDN config change resets what the origin sends. The site still loads. Nothing announces the regression — it just sits there until someone happens to re-run a scan by hand. Six headers cover most of the real risk: CSP, HSTS, a frame-blocking directive, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. Check your own right now: curl -sI https://yourdomain.com | grep -i -E "content-security-policy|strict-transport-security|x-frame-options"
To view or add a comment, sign in
👏