<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Veria Labs</title><description>Automated offensive security for high-stakes industries.</description><link>https://verialabs.com/</link><item><title>Pwning Pydantic&apos;s Monty: A $5K Sandbox Escape</title><link>https://verialabs.com/blog/pwning-pydantic-monty/</link><guid isPermaLink="true">https://verialabs.com/blog/pwning-pydantic-monty/</guid><description>Pydantic offered $5,000 to escape Monty, their Rust-built Python sandbox for AI agents. We chained two GC bugs into a use-after-free and walked away with the bounty.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Securing Open Source Part 2: Cracking Kraken</title><link>https://verialabs.com/blog/securing-open-source-part-2-cracking-kraken/</link><guid isPermaLink="true">https://verialabs.com/blog/securing-open-source-part-2-cracking-kraken/</guid><description>Malicious dApps can impersonate trusted apps and disguise Solana transactions as harmless message signatures, allowing potential fund theft when chained together.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Securing Open Source Part 1: Goose 1-Click RCE</title><link>https://verialabs.com/blog/securing-open-source-part-1-block-goose/</link><guid isPermaLink="true">https://verialabs.com/blog/securing-open-source-part-1-block-goose/</guid><description>We found a 1-click RCE in Block&apos;s Goose AI agent - any website could silently execute commands on your machine.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Announcing our $3.2M Seed Round</title><link>https://verialabs.com/blog/announcing-veria-labs-seed-round/</link><guid isPermaLink="true">https://verialabs.com/blog/announcing-veria-labs-seed-round/</guid><description>We spun out of the #1 hacking team in the US and raised a $3.2M seed to make getting hacked a thing of the past.</description><pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Breaking FRI in Eigen&apos;s zkVM</title><link>https://verialabs.com/blog/breaking-fri-in-zkvm/</link><guid isPermaLink="true">https://verialabs.com/blog/breaking-fri-in-zkvm/</guid><description>How Missing Index Checks Allows Full Proof Forgery</description><pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate></item><item><title>From MCP to Shell</title><link>https://verialabs.com/blog/from-mcp-to-shell/</link><guid isPermaLink="true">https://verialabs.com/blog/from-mcp-to-shell/</guid><description>How MCP Authentication Flaws Enable RCE in Claude Code, Gemini CLI, and More</description><pubDate>Tue, 23 Sep 2025 00:00:00 GMT</pubDate></item></channel></rss>