Blogs by Eran Segal

When the AI Edits Its Own Trust Boundary: Remote Code Execution Vulnerability in AWS's Agentic IDE

We found a vulnerability in Kiro, AWS's agentic IDE, that breaks this promise. By planting hidden instructions in a web page Kiro reads, an attacker can make Kiro rewrite its own MCP (Model Context Protocol) server configuration file and gain arbitrary code execution on the developer's machine.

How Attackers Are Gaining Access to LLM Inference

New Kodem and Intezer research reveals how attackers steal LLM inference, from exposed Ollama servers and leaked API keys to live AI malware running in the wild.

Circumventing Security in Claude Code: Misconfiguration and Denial-of-Service

Kodem recently identified two security issues in Claude Code: a misconfiguration allowing circumvention of user approval and a subsequent Denial-of-Service (DoS) condition.