» Tag
security
518 postsFIPS 140-3 Certifies a Module, Not Your Actual Security Posture
FIPS 140-3 validates a crypto module's algorithms, not overall product security. Real incidents show why engineers should read the fine print.
CVE-2026-64560: Use-After-Free in Linux posix-cpu-timers
CVE-2026-64560 details a Linux kernel posix-cpu-timers use-after-free caused by an exec() race condition, along with its memory-ordering fix.
Git worktrees don't isolate AI coding agents, despite the hype
Git worktrees share refs, config, stash and hooks with the parent repo, making them unsafe as an isolation boundary for AI coding agents.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comVisa Turns Claude Mythos on Its Payment Network, Then Open-Sources the Harness
Visa used Anthropic's Claude Mythos to stress-test its payment network, then open-sourced the harness and its new Mean Time to Adapt metric.
Belay: a local firewall for AI coding agents
Belay is an open-source, local-first security layer that gates AI coding agent tool calls, blocking secret leaks and destructive commands in real time.
Evaluating Agentic Autofix: Canary Gates and Failure Taxonomies
GitHub's July 2026 agentic autofix preview prompts a proposed framework for evaluating AI security patches via canary testing and failure classes.
MemGhost: One Email Can Permanently Poison an AI Agent's Memory
MemGhost attack lets a single email permanently poison AI agent memory, exposing gaps in how agent write-authorization is designed.
AI Coding CLI Uploads Entire Git History, Bypassing Privacy Opt-Out
An AI coding CLI was found silently uploading full Git history and secrets to vendor storage, bypassing the privacy opt-out users trusted.
AWS WAF Dynamic Label Interpolation Tames Bot False Positives
AWS WAF's dynamic label interpolation embeds bot-detection labels and fingerprints into headers and pages, speeding false-positive recovery.
ENDGAME C2: AI-Powered Open Source Go C2 Framework
ENDGAME C2 is a Go-based framework with AI Console converting natural language to C2 commands, supporting Windows and Linux agents.