» Tag
security
518 postsCodeCrucible: A Reusable Blueprint for LLM-Driven SAST
Block's CodeCrucible offers a reusable design blueprint for LLM-driven SAST, using whole-repo analysis instead of snippet-anchored vulnerability scanning.
How Anthropic bakes security into its Claude-driven dev lifecycle
A look at how Anthropic embeds AI-driven security checks across coding, CI review, and deployment in its Claude-based dev lifecycle.
Static Scanner Finds 30 Unguarded Destructive Actions in AI Agent Frameworks
An open-source scanner analyzed 25 AI agent frameworks and confirmed 30 cases where models can delete data, deploy, or send webhooks unauthorized.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comLLM-Assisted Formal Verification Uncovers Two Critical nftables Bugs
Basis used LLM-guided formal verification in Rocq to audit Linux's nftables optimizer, uncovering two critical bugs since 2022.
Why Node.js Can't Be Hardened Against Prototype Pollution
Node.js security reports on prototype pollution gadgets are symptoms, not bugs. The real fix belongs at the application boundary, not in core.
Broken .AL DNSSEC Rollover Caused Outage; 1.1.1.1 Adds Bypass Alerts
Cloudflare fixed a broken .AL DNSSEC rollover with a Negative Trust Anchor and introduced a new EDE code that flags bypassed DNS validation.
Popular ModHeader Chrome Extension Exfiltrates User Data
Reverse engineering reveals ModHeader, a 1.6M-install Chrome extension, secretly exfiltrates encrypted browsing data via a hidden AES-GCM pipeline.
Rootless Edge Deployments: Daemonless CI/CD with Podman and Buildah
Mounting a root Docker socket in CI/CD pipelines with hardware access is a major risk. Podman and Buildah's rootless, daemonless design mitigates it.
File-Notification APIs Leak User Activity Across Linux, Android, Windows, macOS
CCS 2026 research shows file-notification APIs on Linux, Android, Windows, and macOS leak user activity by bypassing intended permission boundaries.
NixOS Study Extends Trusting-Trust Backdoor Attack Beyond Compilers
New research shows Thompson's trusting-trust attack works via GNU strip, not just compilers, silently backdooring NixOS package builds.