<?xml version="1.0" encoding="UTF-8"?>
<!-- This sitemap was dynamically generated on June 25, 2026 at 2:15 am by All in One SEO v4.9.8 - the original SEO plugin for WordPress. -->

<?xml-stylesheet type="text/xsl" href="https://security.unboundcompute.com/default-sitemap.xsl"?>

<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>UnboundCompute Security</title>
		<link><![CDATA[https://security.unboundcompute.com]]></link>
		<description><![CDATA[UnboundCompute Security]]></description>
		<lastBuildDate><![CDATA[Thu, 25 Jun 2026 02:10:01 +0000]]></lastBuildDate>
		<docs>https://validator.w3.org/feed/docs/rss2.html</docs>
		<atom:link href="https://security.unboundcompute.com/sitemap.rss" rel="self" type="application/rss+xml" />
		<ttl><![CDATA[60]]></ttl>

		<item>
			<guid><![CDATA[https://security.unboundcompute.com/oauth-redirect-uri-manipulation/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/oauth-redirect-uri-manipulation/]]></link>
			<title>OAuth redirect_uri Manipulation: How a Loose Callback Check Leaks Your Code</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:10:01 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/aes-gcm-nonce-reuse/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/aes-gcm-nonce-reuse/]]></link>
			<title>AES GCM Nonce Reuse: The Forbidden Attack Explained</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:59 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/hash-length-extension-attack/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/hash-length-extension-attack/]]></link>
			<title>Hash Length Extension Attack: How to Forge a MAC Without the Secret</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:56 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/double-clickjacking/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/double-clickjacking/]]></link>
			<title>Double Clickjacking: The Clickjacking Revival That Beats Frame Defenses</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:54 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/poisoned-pipeline-execution/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/poisoned-pipeline-execution/]]></link>
			<title>Poisoned Pipeline Execution: When Your CI Runs Attacker Code With Your Secrets</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:52 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/postmessage-vulnerabilities/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/postmessage-vulnerabilities/]]></link>
			<title>postMessage Vulnerabilities: When Cross Origin Messages Turn Into XSS</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:50 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/client-side-path-traversal/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/client-side-path-traversal/]]></link>
			<title>Client Side Path Traversal: When the Browser Sends Your Fetch Somewhere Else</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:47 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/cross-site-websocket-hijacking/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/cross-site-websocket-hijacking/]]></link>
			<title>Cross Site WebSocket Hijacking: The CSRF of WebSockets</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:45 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/system-prompt-extraction/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/system-prompt-extraction/]]></link>
			<title>System Prompt Extraction: Why Keeping the Prompt Secret Is Not Security</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:42 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/denial-of-wallet-ai-agents/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/denial-of-wallet-ai-agents/]]></link>
			<title>Denial of Wallet: When Attackers Run Up Your AI Agent&#8217;s Bill</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:40 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/mcp-rug-pull-attack/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/mcp-rug-pull-attack/]]></link>
			<title>The MCP Rug Pull: When an Approved Tool Changes After You Trust It</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:53:47 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/llm-data-exfiltration-markdown/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/llm-data-exfiltration-markdown/]]></link>
			<title>LLM Data Exfiltration Through Markdown Image Rendering</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:53:45 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/confused-deputy-ai-agents/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/confused-deputy-ai-agents/]]></link>
			<title>The Confused Deputy Attack in AI Agents Explained</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:53:42 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/excessive-agency-in-ai-agents/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/excessive-agency-in-ai-agents/]]></link>
			<title>Excessive Agency in AI Agents: When a Tool Can Do Too Much</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:53:40 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/agent-memory-poisoning/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/agent-memory-poisoning/]]></link>
			<title>Agent Memory Poisoning: When an AI Agent Remembers an Attacker&#8217;s Instruction</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:53:38 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-web-cache-poisoning/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-web-cache-poisoning/]]></link>
			<title>What is Web Cache Poisoning? How One Request Hits Many Users</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:33:11 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-nosql-injection/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-nosql-injection/]]></link>
			<title>What is NoSQL Injection? How Query Operators Get Abused</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:33:09 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-mass-assignment/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-mass-assignment/]]></link>
			<title>What is a Mass Assignment Vulnerability? How Extra Fields Break Access Control</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:33:06 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/mcp-tool-shadowing/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/mcp-tool-shadowing/]]></link>
			<title>MCP Tool Shadowing: When One Server Hijacks Another&#8217;s Tools</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:37 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/ascii-smuggling-prompt-injection/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/ascii-smuggling-prompt-injection/]]></link>
			<title>ASCII Smuggling: Invisible Unicode Prompt Injection That Humans Cannot See</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:35 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/slopsquatting-attack/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/slopsquatting-attack/]]></link>
			<title>Slopsquatting: When Attackers Register the Packages AI Hallucinates</title>
			<pubDate><![CDATA[Thu, 25 Jun 2026 02:09:32 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-host-header-injection/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-host-header-injection/]]></link>
			<title>What is Host Header Injection? How a Trusted Header Goes Wrong</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:33:04 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-cors-misconfiguration/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-cors-misconfiguration/]]></link>
			<title>What is a CORS Misconfiguration? How It Leaks Data</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:33:01 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-server-side-template-injection/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-server-side-template-injection/]]></link>
			<title>What is Server Side Template Injection? SSTI Explained</title>
			<pubDate><![CDATA[Wed, 24 Jun 2026 04:32:59 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/kubernetes-service-account-token-abuse/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/kubernetes-service-account-token-abuse/]]></link>
			<title>Kubernetes service account token abuse: from one pod to cluster admin</title>
			<pubDate><![CDATA[Tue, 23 Jun 2026 02:21:14 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/saml-signature-wrapping/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/saml-signature-wrapping/]]></link>
			<title>SAML Signature Wrapping Explained: When a Valid Signature Lies</title>
			<pubDate><![CDATA[Tue, 23 Jun 2026 02:21:12 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/dependency-confusion-attack/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/dependency-confusion-attack/]]></link>
			<title>Dependency Confusion Attack Explained</title>
			<pubDate><![CDATA[Tue, 23 Jun 2026 02:21:10 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/rag-data-poisoning/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/rag-data-poisoning/]]></link>
			<title>RAG Data Poisoning: How Attackers Corrupt the Knowledge Base Behind an LLM</title>
			<pubDate><![CDATA[Tue, 23 Jun 2026 02:21:07 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/the-lethal-trifecta/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/the-lethal-trifecta/]]></link>
			<title>The lethal trifecta in AI agents</title>
			<pubDate><![CDATA[Tue, 23 Jun 2026 02:21:05 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/]]></link>
			<title>Home</title>
			<pubDate><![CDATA[Sat, 20 Jun 2026 02:09:26 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/jwt-algorithm-confusion-attack/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/jwt-algorithm-confusion-attack/]]></link>
			<title>JWT Algorithm Confusion Attack Explained</title>
			<pubDate><![CDATA[Tue, 23 Jun 2026 02:21:02 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/blog/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/blog/]]></link>
			<title>Blog</title>
			<pubDate><![CDATA[Sat, 20 Jun 2026 01:29:58 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-insecure-deserialization/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-insecure-deserialization/]]></link>
			<title>What is insecure deserialization?</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:41 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/how-do-hackers-find-vulnerabilities/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/how-do-hackers-find-vulnerabilities/]]></link>
			<title>How do hackers find vulnerabilities?</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:39 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/teardown-chaining-bugs-into-a-breach/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/teardown-chaining-bugs-into-a-breach/]]></link>
			<title>Teardown: chaining small bugs into a real breach</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:37 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/how-browser-fingerprinting-works/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/how-browser-fingerprinting-works/]]></link>
			<title>How Browser Fingerprinting Identifies You Without a Cookie</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:35 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-command-injection/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-command-injection/]]></link>
			<title>What is command injection? Examples explained</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/sast-vs-dast-vs-iast/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/sast-vs-dast-vs-iast/]]></link>
			<title>SAST vs DAST vs IAST, what is the difference?</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:31 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-a-padding-oracle-attack/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-a-padding-oracle-attack/]]></link>
			<title>What Is a Padding Oracle Attack and How It Decrypts CBC Without the Key</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:29 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/how-tls-fingerprinting-works/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/how-tls-fingerprinting-works/]]></link>
			<title>How TLS Fingerprinting Works: JA3, JA4, and the ClientHello</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:27 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-a-hash-flooding-attack/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-a-hash-flooding-attack/]]></link>
			<title>What Is a Hash Flooding Attack and Why It Stalls a Server With Bytes</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:25 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/llm-security-testing-tools/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/llm-security-testing-tools/]]></link>
			<title>LLM Security Testing Tools: A Vendor Neutral Landscape Guide</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:23 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/mcp-tool-poisoning-explained/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/mcp-tool-poisoning-explained/]]></link>
			<title>MCP Tool Poisoning: When the Tool Description Is the Attack</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:21 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-indirect-prompt-injection/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-indirect-prompt-injection/]]></link>
			<title>What Is Indirect Prompt Injection and Why It Is So Hard to Stop</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:18 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-ssrf/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-ssrf/]]></link>
			<title>What is SSRF? Server Side Request Forgery Explained</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:16 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-an-open-redirect/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-an-open-redirect/]]></link>
			<title>What is an open redirect vulnerability?</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:13 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-dom-based-xss/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-dom-based-xss/]]></link>
			<title>What is DOM based XSS?</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:11 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-xss-and-how-does-it-work/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-xss-and-how-does-it-work/]]></link>
			<title>What is XSS and how does it work? With examples</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 12:13:09 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/what-is-web-application-security/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/what-is-web-application-security/]]></link>
			<title>What is web application security?</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 10:42:43 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://security.unboundcompute.com/authentication-vs-authorization/]]></guid>
			<link><![CDATA[https://security.unboundcompute.com/authentication-vs-authorization/]]></link>
			<title>Authentication vs authorization, explained with examples</title>
			<pubDate><![CDATA[Mon, 22 Jun 2026 10:42:41 +0000]]></pubDate>
		</item>
				</channel>
</rss>
