S6 Blog

Security research, product updates, and field notes

Practical guidance for security leaders and practitioners building with agentic AI.

NoiseCloud turns YouTube into a DLP problem
dlpdata-exfiltrationsteganography

NoiseCloud turns YouTube into a DLP problem

NoiseCloud is framed as weird storage, but the security lesson is cleaner than that: if a platform accepts user video, it can become a bulk data carrier. DLP programs need to think beyond files, forms, and obvious cloud drives.

S6 Security Labs
5 min read
Drupal Core SQL injection is a useful reminder that CMS risk never really left
application-securityvulnerability-managementsoc

Drupal Core SQL injection is a useful reminder that CMS risk never really left

CISA listed this issue as known exploited. The useful SOC question is where the affected system sits, what it can reach, and whether logs can prove if it was touched.

S6 Security Labs
3 min read
Langflow CORS exposure is a quiet AI-workflow data-path problem
ai-securityapplication-securityautomation

Langflow CORS exposure is a quiet AI-workflow data-path problem

CISA listed this issue as known exploited. The useful SOC question is where the affected system sits, what it can reach, and whether logs can prove if it was touched.

S6 Security Labs
3 min read
Cisco SD-WAN controller authentication bypass is a control-plane incident waiting to happen
edge-securitynetwork-securityvulnerability-management

Cisco SD-WAN controller authentication bypass is a control-plane incident waiting to happen

CISA listed this issue as known exploited. The useful SOC question is where the affected system sits, what it can reach, and whether logs can prove if it was touched.

S6 Security Labs
3 min read
LiteLLM SQL injection is what happens when AI gateways become real infrastructure
ai-securityapplication-securityautomation

LiteLLM SQL injection is what happens when AI gateways become real infrastructure

CISA listed this issue as known exploited. The useful SOC question is where the affected system sits, what it can reach, and whether logs can prove if it was touched.

S6 Security Labs
3 min read
PAN-OS captive portal exploitation risk puts identity-facing firewall services under pressure
edge-securitynetwork-securityvulnerability-management

PAN-OS captive portal exploitation risk puts identity-facing firewall services under pressure

CISA listed this issue as known exploited. The useful SOC question is where the affected system sits, what it can reach, and whether logs can prove if it was touched.

S6 Security Labs
3 min read
ConnectWise ScreenConnect path traversal keeps remote-support tooling in the attacker playbook
remote-accessvulnerability-managementsoc

ConnectWise ScreenConnect path traversal keeps remote-support tooling in the attacker playbook

CISA listed this issue as known exploited. The useful SOC question is where the affected system sits, what it can reach, and whether logs can prove if it was touched.

S6 Security Labs
3 min read
Marimo RCE is another reason notebooks and data apps need production-grade controls
ai-securityapplication-securityautomation

Marimo RCE is another reason notebooks and data apps need production-grade controls

CISA listed this issue as known exploited. The useful SOC question is where the affected system sits, what it can reach, and whether logs can prove if it was touched.

S6 Security Labs
3 min read
Cisco SD-WAN privileged API issues turn network management into a hunt target
edge-securitynetwork-securityvulnerability-management

Cisco SD-WAN privileged API issues turn network management into a hunt target

CISA listed this issue as known exploited. The useful SOC question is where the affected system sits, what it can reach, and whether logs can prove if it was touched.

S6 Security Labs
3 min read