<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Work on b̷I̶a̸c̷k̶r̷0̴s̸e̷</title><link>https://biackr0se.github.io/blog/projects/</link><description>Recent content in Work on b̷I̶a̸c̷k̶r̷0̴s̸e̷</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 26 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://biackr0se.github.io/blog/projects/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-58196: SSRF in ToolHive, host-side and past the sandbox</title><link>https://biackr0se.github.io/blog/projects/toolhive-ssrf/</link><pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate><guid>https://biackr0se.github.io/blog/projects/toolhive-ssrf/</guid><description>&lt;h2 id="the-target"&gt;The target&lt;/h2&gt;
&lt;p&gt;ToolHive (Stacklok) runs Model Context Protocol servers for you, each one in its own isolated container, behind an egress proxy, with no local credentials handed to it. The security model is explicit in the README: every MCP server is untrusted, so it stays boxed. That promise is the whole point of the tool.&lt;/p&gt;
&lt;p&gt;Before a remote MCP server ever reaches its container, ToolHive runs OAuth discovery against it to work out how to authenticate. That discovery runs host-side, in the ToolHive process, outside the per-server sandbox. The question, then, is whether the untrusted server gets to influence what the trusted host fetches during discovery. It does, and that is the finding.&lt;/p&gt;</description></item><item><title>AutoMCP: Elastic Purple Team MCP Server</title><link>https://biackr0se.github.io/blog/projects/automcp/</link><pubDate>Sat, 04 Apr 2026 00:00:00 +0000</pubDate><guid>https://biackr0se.github.io/blog/projects/automcp/</guid><description>&lt;h2 id="what-it-is"&gt;What it is&lt;/h2&gt;
&lt;p&gt;AutoMCP is an MCP server built on LangGraph that plugs LLM agents into an Elastic SIEM. It pulls security alerts, triages them, drives response actions, and performs counter-reconnaissance against the source of an attack.&lt;/p&gt;
&lt;h2 id="why-it-exists"&gt;Why it exists&lt;/h2&gt;
&lt;p&gt;Alert triage is the part of detection engineering that burns analysts out. The interesting question is how far an agent can go past summarizing an alert: pivoting on it, enriching it, and acting on it, while staying inside guardrails a SOC would accept.&lt;/p&gt;</description></item></channel></rss>