Secure GenAI
Secure GenAI Podcast
Another CloudFlare Outage, Oracle’s Zero-day victim, AI Safety Index - Winter 2025, Poetry bypasses AI safety guardrails, NextJS and React CVSS 10.0
0:00
-5:58

Another CloudFlare Outage, Oracle’s Zero-day victim, AI Safety Index - Winter 2025, Poetry bypasses AI safety guardrails, NextJS and React CVSS 10.0

GenAI Safety & Security | Dec 1 - Dec 7, 2025

If you enjoy our newsletter, please consider to be a paid subscriber to help us keep more news and updates coming out.

Secure GenAI is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Highlights

  • Another CloudFlare Outage.

  • Oracle’s Zero-day victim.

  • AI Safety Index - Winter 2025.

  • Poetry bypasses AI safety guardrails.

  • NextJS and React CVSS 10.0.


Deep Dive

Another Cloudflare Outage The Guardian

  • Issue with Dashboard and related APIs.

  • Affected LinkedIn, X, Canvas, DownDetector.

  • It took less than an hour.

  • Issues are under active investigation.

  • Last month, an outage lasted three hours.

Oracle’s Zero-day Victim BleepingComputer

  • Clop exploited Oracle EBS flaw.

  • Invoices with personal data stolen.

  • Former staff info also exposed.

  • Accounting files from 2024 impacted.

  • Data leaked on dark-web portal.

  • Theft detected months after attack.

  • Multiple victims impacted by the incidents.

AI Safety Index - Winter 2025 FutureOfLife

  • Industry safety practices are poor.

  • The highest grade is C+.

  • Safety lags behind capabilities.

  • Anthropic/ Claude ranks first overall.

  • OpenAI/ ChatGPT follows in second.

  • Google DeepMind/ Gemini ranks third.

  • Existential safety plans missing.

  • Independent oversight is lacking.

  • Whistleblower protections remain weak.

  • Measurable safety thresholds missing.

Poetry bypasses AI safety guardrails. The Guardian

  • Researchers tested “adversarial poetry.”

  • 62% of prompts generated harm.

  • Google’s model failed 100%.

  • The OpenAI model resisted attacks.

  • Unpredictable structure confuses filters.

  • Exploit is easy to replicate.

  • Companies alerted to vulnerability.

NextJS and React CVSS 10.0 TheHackerNews

  • Critical React CVE-2025-55182

  • Codenamed React2shell.

  • Exploits unsafe deserialization.

  • No authentication required.

  • Affects React Server Components.

  • Patches released immediately.

  • Web Application Firewall rules mitigate attacks.

Thanks for reading Secure GenAI ! This post is public so feel free to share it.

Share

Discussion about this episode

User's avatar

Ready for more?