<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>KavLabs — security research notes (fa + en)</title>
    <link>https://kavlabs.parhamforati.com</link>
    <description>Bilingual security research feed — Persian and English writeups.</description>
    <language>fa</language>
    <lastBuildDate>Sun, 26 Jul 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://kavlabs.parhamforati.com/rss.xml" rel="self" type="application/rss+xml" />
    <image>
      <url>https://kavlabs.parhamforati.com/og-default.png</url>
      <title>KavLabs — security research notes (fa + en)</title>
      <link>https://kavlabs.parhamforati.com</link>
    </image>
    <item>
      <title>From Exam Cheating to Cluster Takeover: The Odyssey of an Unguarded LLM</title>
      <link>https://kavlabs.parhamforati.com/en/blog/from-exam-cheating-to-cluster-takeover</link>
      <guid isPermaLink="true">https://kavlabs.parhamforati.com/en/blog/from-exam-cheating-to-cluster-takeover</guid>
      <description>An unguarded AI model decided cheating was easier than solving the exam: it escaped OpenAI&apos;s sandbox, broke into Hugging Face&apos;s infrastructure, and carried out thousands of autonomous actions in a single weekend. In this article, you&apos;ll learn exactly how the attack unfolded, why commercial US models refused to even help the victim, and why this incident is reshaping the balance of power between open-weight and guardrailed models.</description>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <language>en</language>
      <category>SSRF</category><category>AI security</category><category>OpenAI</category><category>Hugging Face</category><category>LLM</category><category>guardrails</category><category>open-weight models</category>
    </item>
    <item>
      <title>از تقلب در امتحان تا تصرف کلاسترها: اودیسه‌ی یک LLM بی‌گاردیل</title>
      <link>https://kavlabs.parhamforati.com/fa/blog/from-exam-cheating-to-cluster-takeover</link>
      <guid isPermaLink="true">https://kavlabs.parhamforati.com/fa/blog/from-exam-cheating-to-cluster-takeover</guid>
      <description>یه مدل هوش مصنوعی بدون گاردیل، به‌جای حل یه آزمون، تصمیم گرفت تقلب کنه: از سندباکس OpenAI فرار کرد، وارد زیرساخت Hugging Face شد، و هزاران اقدام خودکار رو در یک آخر هفته انجام داد. توی این مقاله می‌فهمی این حمله دقیقاً چطور اتفاق افتاد، چرا مدل‌های تجاری آمریکایی حتی به قربانی هم کمک نکردن، و چرا این ماجرا داره تعادل قدرت بین مدل‌های open weight و مدل‌های گاردیل‌دار رو به‌هم می‌زنه.</description>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <language>fa</language>
      <category>هوش مصنوعی</category><category>امنیت سایبری</category><category>OpenAI</category><category>Hugging Face</category><category>گاردیل</category><category>open weight</category><category>GLM</category>
    </item>
    <item>
      <title>Make the Server Do Your Dirty Work — What is SSRF?</title>
      <link>https://kavlabs.parhamforati.com/en/blog/what-is-ssrf</link>
      <guid isPermaLink="true">https://kavlabs.parhamforati.com/en/blog/what-is-ssrf</guid>
      <description>SSRF is one of the most dangerous vulnerabilities in the cloud world. In this article, you&apos;ll learn from scratch how an attacker can force a server to make requests to internal servers, why cloud makes this worse, and how Capital One lost $150 million from this one bug.</description>
      <pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate>
      <language>en</language>
      <category>SSRF</category><category>web security</category><category>bug bounty</category><category>cloud security</category><category>OWASP</category><category>security education</category>
    </item>
    <item>
      <title>سرور رو وادار کن به جات کثیف‌کاری کنه — SSRF چیه؟</title>
      <link>https://kavlabs.parhamforati.com/fa/blog/what-is-ssrf</link>
      <guid isPermaLink="true">https://kavlabs.parhamforati.com/fa/blog/what-is-ssrf</guid>
      <description>SSRF یکی از خطرناک‌ترین آسیب‌پذیری‌های دنیای cloud هست. توی این مقاله از صفر یاد می‌گیری چطور مهاجم می‌تونه سرور رو وادار کنه به سرورهای داخلی درخواست بزنه، چرا cloud این رو بدتر می‌کنه، و چطور Capital One با همین یه باگ ۱۵۰ میلیون دلار ضرر کرد.</description>
      <pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate>
      <language>fa</language>
      <category>SSRF</category><category>امنیت وب</category><category>باگ باونتی</category><category>cloud security</category><category>OWASP</category><category>آموزش امنیت</category>
    </item>
    <item>
      <title>Introduction &amp; Complete Guide to KavLabs</title>
      <link>https://kavlabs.parhamforati.com/en/blog/kavlabs-complete-guide</link>
      <guid isPermaLink="true">https://kavlabs.parhamforati.com/en/blog/kavlabs-complete-guide</guid>
      <description>Everything about KavLabs: Why it was created, the path it follows, what content it offers, and how you can learn step-by-step from digital literacy to advanced cybersecurity techniques.</description>
      <pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate>
      <language>en</language>
      <category>KavLabs</category><category>guide</category><category>cybersecurity</category><category>digital literacy</category><category>security education</category><category>open source</category>
    </item>
    <item>
      <title>معرفی و راهنمای کامل کاولبز</title>
      <link>https://kavlabs.parhamforati.com/fa/blog/kavlabs-complete-guide</link>
      <guid isPermaLink="true">https://kavlabs.parhamforati.com/fa/blog/kavlabs-complete-guide</guid>
      <description>همه‌چیز درباره کاولبز: چرا ساخته شد، چه مسیری را دنبال می‌کند، چه محتوایی ارائه می‌دهد و چگونه می‌توانید از سواد دیجیتال تا تکنیک‌های پیشرفته امنیت سایبری را قدم‌به‌قدم یاد بگیرید.</description>
      <pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate>
      <language>fa</language>
      <category>کاولبز</category><category>راهنما</category><category>امنیت سایبری</category><category>سواد دیجیتال</category><category>آموزش امنیت</category><category>متن‌باز</category>
    </item>
  </channel>
</rss>