» Tag
security
437 postsAgent payments need separation of duties, not just signatures
A signature alone can't secure agent payments; execution must be bound to a still-valid mandate, verified by a party that cannot forge it.
Zero-Trust Workload Identity in Kubernetes: SPIFFE, SPIRE, Cilium
Why IP-based network policies fail in Kubernetes, and how SPIFFE, SPIRE, and Cilium enable cryptographic workload identity and enforced mutual TLS.
Bad Epoll Flaw Grants Root Access on Linux and Android
CVE-2026-46242, dubbed Bad Epoll, lets unprivileged local users gain root via a race-condition bug in the Linux kernel's epoll subsystem; a patch is already out.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comWallet SDK Generates BIP39 Seeds from Math.random() — Is This Bounty-Eligible?
A security researcher questions the bounty eligibility of a wallet SDK's use of Math.random() for BIP39 seed generation.
An Open Agent Security Benchmark: Uncaught Attacks
An open benchmark featuring 497 attacks targeting modern LLM agents has been established.
We hired a security engineer and got back 123 findings
Profullstack's security audit revealed 123 findings across two repositories, offering vital lessons for engineers.
Post-Quantum TLS: New Approaches for Cloud APIs and Microservices
Learn about the significance of post-quantum TLS migration and the directional TLS links between termination points for cloud APIs.
Hunt NGINX Proxies with Damn Vulnerable NGINX Proxy
Damn Vulnerable NGINX Proxy provides a resource for discovering vulnerabilities in NGINX servers.
Hacker with a vendetta against Microsoft reveals new zero-day exploit
Nightmare Eclipse has unveiled ShieldBreak, a new zero-day exploit granting SYSTEM privileges on Windows systems.
Malicious SIM Cards Can Shut Down Phones and Steal Files
Malicious SIM cards can shut down phones and steal files, revealing serious security risks. Researchers highlight vulnerabilities in cellular devices.