» Tag
security
437 postsYour URL-fetching Service is an SSRF Engine - Here's Our Two-Layer Guard
Services fetching user-supplied URLs server-side create SSRF engines. NorthDuty implements a two-layer guard for enhanced security.
MemGhost: Attacker Model Plants Persistent False Memories via Email
MemGhost successfully injects persistent false memories into OpenClaw and Claude Code SDK agents using just one email.
Insecure Argument Handling in Tailscale SSH Allowed Root Access
A vulnerability in Tailscale SSH allowed root access via usernames with a leading '-'. Upgrade recommended.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comLeaving Auth0: What Really Migrates and What You Won't Get
Learn about the challenges of leaving Auth0 and how Authagonal simplifies migration.
Did AI Write Your Code? It Might Have Introduced Vulnerabilities
Explore the security risks of AI-generated code and how to mitigate them.
Four Eras of Cloud Security: Tools and Evaluation
Scott Piper's retrospective on four eras of cloud security research provides key insights for engineers.
Verify a Self-Hosted Installer Before Running It as Root
Learn how to verify a self-hosted installer before executing it as root.
Validators Judge. They Don't Help.
The article discusses the importance of keeping validators focused on judgment, not remediation, to maintain security and audit integrity.
I Built a Firewall for My AI Agents: The Near-Miss That Prompted It
Bastion Gateway enhances AI agent security. Learn about the near-miss experience and the security measures implemented.
xAI's Grok Build CLI Stops Uploading Git Repositories to Google Cloud
xAI has halted the Grok Build CLI's ability to upload developer repositories to Google Cloud. Learn more about the implications.