» Tag
security
437 postsDesigning UX Without a Screen: Lessons from an MCP Server
A developer shares how building an MCP server forced UX decisions into tool names, schemas and auth design—with no screen, buttons or visual cues to rely on.
Metis: Arm's Open-Source Agentic Security Review Tool
Metis, built by Arm's Product Security Team, is an open-source framework that uses LLM reasoning to find security vulnerabilities across large codebases.
AI Code Audit: 15 Security Flaws Claude Found in Production
An LLM-based security audit uncovered 15 OWASP-classified flaws-SQL/NoSQL injection, IDOR, path traversal-each shown with vulnerable and fixed code.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comResearchers Uncover Git Hash Chain Malleability in Signed Commits
New research shows signed Git commit hashes can be altered while keeping a valid signature and GitHub's Verified badge, undermining commit integrity assumptions.
Kars: A Kubernetes-Native Zero-Trust Runtime for AI Agents
Kars runs each AI agent in an isolated Kubernetes sandbox, routing every external call through a Rust-based zero-trust broker with no agent-held credentials.
How context is managed in long-running agentic systems
A look at how Director's Journal, Critic's Review and Timeline mechanisms keep multi-agent security investigation systems coherent over long-running sessions.
Innersource security advisories go GA
GitHub has made innersource security advisories generally available. This feature is a significant step in managing vulnerabilities more effectively.
Grok chat duped into swallowing injected instructions
xAI's Grok chat agent is exposed to a new prompt injection attack discovered by Adversa AI.
Europe Cannot Govern AI by Cloud Region Alone: An Architecture for AI Sovereignty
The new AI architecture offers secure authorization domains without specific hardware dependencies.
Research Reveals Some RISC-V Chips Are Vulnerable to Spectre Attacks
Some RISC-V chips are found to be vulnerable to Spectre attacks, posing significant risks for engineers. Awareness and mitigation strategies are essential.