Noma Labs
Noma Labs is an elite team of AI security researchers uncovering enterprise AI vulnerabilities before attackers do - giving organizations the knowledge and tools to innovate securely.
Workflow Identity Hijacking: The Silent Backdoor in AI Workflows
Workflow Identity Hijacking discovered by Noma Labs The Silent Backdoor in AI Workflows
.png)
Latest from Noma Labs
Workflow Identity Hijacking: The Silent Backdoor in AI Workflows
Workflow Identity Hijacking discovered by Noma Labs The Silent Backdoor in AI Workflows
.png)
In this novel attack vector disclosure by Noma Labs, Workflow Identity Hijacking is explained and documented. Described as a scenario where the underlying model is not manipulated, tricked, or jailbroken. Attackers are able to bypass standard controls by sending normal, benign requests through an unauthenticated entry point (such as a support inbox, GitHub issue, web form, or shared document). The enterprise AI pipeline reads the input, interprets the request, and executes the action exactly as designed. The core failure is that the requester had no authority to make that request. The root cause is an authorization design flaw in modern enterprise AI pipelines: the identity and permissions of the user who triggers a workflow are decoupled from the identity and permissions used to execute it.
RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726)
RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726)

GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos

GrafanaGhost: The Phantom Stealing Your Data
GrafanaGhost: The Phantom Stealing Your Data

At Noma, our mission is simple: identify and reduce emerging AI risk before it impacts your business. Following our discoveries of ForcedLeak, GeminiJack, and DockerDash, the Noma Labs Team has identified a new critical vulnerability: GrafanaGhost.
ContextCrush: The Context7 MCP Server Vulnerability Hiding in Plain Sight
ContextCrush: The Context7 MCP Server Vulnerability Hiding in Plain Sight

Trust is the most vulnerable component of the modern development stack. Today, we are disclosing a critical vulnerability in Upstash’s Context7 MCP Server, one of the most popular MCP servers on GitHub, with approximately 50,000 stars and more than 8 million npm downloads.
DockerDash: Two Attack Paths, One AI Supply Chain Crisis
DockerDash: Two Attack Paths, One AI Supply Chain Crisis

Hacking Google Gemini Enterprise with an Indirect Prompt Injection
Hacking Google Gemini Enterprise with an Indirect Prompt Injection
AI Agent risk exposed in Salesforce Agentforce
AI Agent risk exposed in Salesforce Agentforce
