
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Shellvoide Blog - AI-Powered Cybersecurity, Compliance &amp; Penetration Testing</title>
      <link>https://shellvoide.com/blog/blog</link>
      <description>The Shellvoide security blog: AI-driven penetration testing, vulnerability research, and application security insights from the team behind KLUE.</description>
      <language>en-us</language>
      <managingEditor>info@shellvoide.com (Shellvoide)</managingEditor>
      <webMaster>info@shellvoide.com (Shellvoide)</webMaster>
      <lastBuildDate>Wed, 07 Oct 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://shellvoide.com/blog/tags/machine-learning/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://shellvoide.com/blog/blog/hydra-untrusted-config-rce</guid>
    <title>Two Code-Execution CVEs in Hydra: CVE-2026-106441 and CVE-2026-106442</title>
    <link>https://shellvoide.com/blog/blog/hydra-untrusted-config-rce</link>
    <description>Hydra is the configuration framework a large part of the Python machine-learning world uses to wire up experiments and apps. We pointed KLUE, our AI security agent, at it, and it found two ways to run code on a machine that loads an untrusted Hydra config. Both get around the blocklist Hydra had already added to stop exactly this. One slips through gaps in that blocklist; the other goes through the logging system, a door the blocklist never guarded. Both were reported, accepted, assigned CVEs (CVE-2026-106441 and CVE-2026-106442), rated High, and fixed.</description>
    <pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate>
    <author>info@shellvoide.com (Shellvoide)</author>
    <category>klue</category><category>case-study</category><category>vulnerability-research</category><category>code-execution</category><category>code-injection</category><category>deserialization</category><category>pickle</category><category>python</category><category>machine-learning</category><category>hydra</category><category>config-security</category><category>autonomous-security</category><category>appsec</category>
  </item>

    </channel>
  </rss>
