<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Protocol-Security on CuraSec</title><link>https://curasec.metacog.co.kr/tags/protocol-security/</link><description>Recent content in Protocol-Security on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 15:10:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/protocol-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Protocol-Level Structural Attacks on Agentic Commerce Platforms: 100% ASR</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-protocol-level-attacks-on-agentic-commerce-platforms-a-cross/</link><pubDate>Mon, 27 Jul 2026 15:10:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-protocol-level-attacks-on-agentic-commerce-platforms-a-cross/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research identifies 33 deterministic, model-agnostic vulnerabilities across three agentic commerce platforms—including an end-to-end payment hijack chain—plus a proposed defense (PCAT). No active exploitation or PoC in the wild yet, but if you are building agent-to-service protocols, audit your authentication and credential-passing layers against the paper&amp;rsquo;s taxonomy before production deployment.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no observed campaigns, and no ATT&amp;amp;CK mappings to hunt against yet; this is early-stage research. File as context for when agentic payment workflows appear in your estate—credential-channel and payment-hijack patterns will eventually need detection logic if your org adopts these platforms.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Systemic 100%-ASR protocol flaws across multiple independently-built agentic commerce platforms—handling real payments and user credentials—represent a new vendor-risk category. If your organization is adopting or evaluating AI agents with payment or credential authority, initiate vendor security questionnaires and establish an internal policy on agentic system trust boundaries this quarter before deployments scale.&lt;/li>
&lt;/ul></description></item></channel></rss>