<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Exit on VPNW.com</title>
    <link>https://vpnw.com/tags/exit/</link>
    <description>Recent content in Exit on VPNW.com</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 06 Oct 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://vpnw.com/tags/exit/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Fixed Exit Case Study: A Stolen Agent Token Reaches Nothing Its Policy Refuses, Even Sent Straight to the Exit</title>
      <link>https://vpnw.com/fixed-exit-case-study-a-stolen-agent-token-reaches-nothing-its-policy-refuses-even-sent-straight-to-the-exit/</link>
      <pubDate>Tue, 06 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/fixed-exit-case-study-a-stolen-agent-token-reaches-nothing-its-policy-refuses-even-sent-straight-to-the-exit/</guid>
      <description>&lt;p&gt;Partners often let traffic in by IP address: an API kept for one customer, a database behind an allowlist, an internal system that trusts only the office. For AI agents and CI jobs that means fixed addresses to leave from, and the usual answer is a proxy with a fixed address.&lt;/p&gt;&#xA;&lt;p&gt;A plain proxy trusts whatever reaches it. If an agent&amp;rsquo;s machine is hijacked, or its token copied, the proxy forwards whatever the new owner asks for, from the trusted address. The policy the agent was meant to follow lives on the agent&amp;rsquo;s side, which is where the attacker now sits.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
