Tag: ai-security
All the articles with the tag "ai-security".
-
HTB Fawn — The FTP Door Left Open
HackTheBox Fawn exploits anonymous FTP login on vsftpd 3.0.3. The same pattern — a data store designed for openness that was never locked down — maps directly to unauthenticated vector databases in production AI deployments.
-
HTB Meow — Root with No Password
HackTheBox Meow exploits a Telnet service running with a blank root password. The same failure pattern — a powerful interface with no credential gate — shows up in unauthenticated MCP servers and AI agent endpoints.