» Tag
security
92 postsKeyless AWS to Google Cloud: Expanding Terraform CI/CD Pipeline
inDrive expanded its Terraform CI/CD from AWS to Google Cloud without keys, leveraging Workload Identity Federation for secure access.
Stealing Reasoning Traces from Proprietary LLM APIs
We found a way to extract reasoning traces from frontier AI APIs, highlighting significant security risks and potential data leaks for engineers.
Defense-in-Depth and Linux Capabilities: A Study on Seccomp Filters
This study examines defense-in-depth through Linux capabilities and seccomp filters, illustrating how security layers can effectively integrate.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comI tested my own security tool and found four bugs
Agentmetry is a flight recorder for AI coding agents. In this entry, I discuss four bugs found and their implications for security tools.
Wallet SDK Generates BIP39 Seeds from Math.random() — Is This Bounty-Eligible?
A security researcher questions the bounty eligibility of a wallet SDK's use of Math.random() for BIP39 seed generation.
An Open Agent Security Benchmark: Uncaught Attacks
An open benchmark featuring 497 attacks targeting modern LLM agents has been established.
We hired a security engineer and got back 123 findings
Profullstack's security audit revealed 123 findings across two repositories, offering vital lessons for engineers.
Post-Quantum TLS: New Approaches for Cloud APIs and Microservices
Learn about the significance of post-quantum TLS migration and the directional TLS links between termination points for cloud APIs.
Hunt NGINX Proxies with Damn Vulnerable NGINX Proxy
Damn Vulnerable NGINX Proxy provides a resource for discovering vulnerabilities in NGINX servers.
Hacker with a vendetta against Microsoft reveals new zero-day exploit
Nightmare Eclipse has unveiled ShieldBreak, a new zero-day exploit granting SYSTEM privileges on Windows systems.