<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security-Audit on Oob Skulden</title><link>https://oobskulden.com/categories/security-audit/</link><description>Recent content in Security-Audit on Oob Skulden</description><generator>Hugo -- 0.153.2</generator><language>en-us</language><lastBuildDate>Thu, 02 Apr 2026 08:00:00 -0500</lastBuildDate><atom:link href="https://oobskulden.com/categories/security-audit/index.xml" rel="self" type="application/rss+xml"/><item><title>Your AI Has a Memory. Anyone Can Read It. Anyone Can Poison It.</title><link>https://oobskulden.com/2026/04/your-ai-has-a-memory.-anyone-can-read-it.-anyone-can-poison-it./</link><pubDate>Thu, 02 Apr 2026 08:00:00 -0500</pubDate><guid>https://oobskulden.com/2026/04/your-ai-has-a-memory.-anyone-can-read-it.-anyone-can-poison-it./</guid><description>ChromaDB ships with no authentication. This episode breaks the RAG stack built in 3.4A -- exfiltrating every internal document, poisoning the knowledge base to phish users via the AI, jamming retrieval with blocker documents, and deleting the entire collection. All from the network, with curl and five lines of Python.</description></item></channel></rss>