» Tag
security
437 postsWhy Node.js Can't Be Hardened Against Prototype Pollution
Node.js security reports on prototype pollution gadgets are symptoms, not bugs. The real fix belongs at the application boundary, not in core.
Broken .AL DNSSEC Rollover Caused Outage; 1.1.1.1 Adds Bypass Alerts
Cloudflare fixed a broken .AL DNSSEC rollover with a Negative Trust Anchor and introduced a new EDE code that flags bypassed DNS validation.
Popular ModHeader Chrome Extension Exfiltrates User Data
Reverse engineering reveals ModHeader, a 1.6M-install Chrome extension, secretly exfiltrates encrypted browsing data via a hidden AES-GCM pipeline.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comRootless Edge Deployments: Daemonless CI/CD with Podman and Buildah
Mounting a root Docker socket in CI/CD pipelines with hardware access is a major risk. Podman and Buildah's rootless, daemonless design mitigates it.
NixOS Study Extends Trusting-Trust Backdoor Attack Beyond Compilers
New research shows Thompson's trusting-trust attack works via GNU strip, not just compilers, silently backdooring NixOS package builds.
Jailbox: Hardened, Network-Isolated KVM VMs for AI Coding Agents
Jailbox creates hardened, network-isolated KVM VMs to contain AI coding agents and untrusted code, with no route back to your host or LAN.
QuantmLayer Locks Down AI Coding Agents with Kernel-Level Sandboxing
QuantmLayer sandboxes AI coding agents with kernel-level containment (BPF-LSM, seccomp, cgroups), blocking attacks default Docker can't stop.
A Portable Passkey Record Format and Go API Proposal
A proposed portable string format for WebAuthn passkey records, plus a stateless Go API draft, aiming to simplify interoperable credential storage.
Hugging Face Discloses Breach Driven by an Autonomous AI Agent
Hugging Face discloses a breach by an autonomous AI agent, detected via LLM-based analysis after commercial models blocked forensic work.
Bernstein 2.16: The Output-Economy Suite and Safer Agent Summaries
Bernstein 2.16 adds per-role cost attribution, a cost-quality A/B harness, safer proactive context compaction, and schema-enforced completions.