» Tag
security
437 postsThe AI Supply Chain: The Next Evolution of Third Party Risk
AI supply chain risk is evolving beyond traditional third-party risk management.
ExporTheft: 11 Chrome extensions upload full chat content on PDF export
11 Chrome extensions upload full chat content during PDF export, posing risks to user data security.
What I Learned Trying to Revoke an AI Agent Mid-Task
Explore four key principles for effectively revoking an AI agent mid-task.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comImplementing RFC 8693 Token Exchange in AgentGateway: A Complete Tutorial
Comprehensive tutorial on implementing RFC 8693 token exchange in AgentGateway. Essential steps for secure identity management.
Debugging a Legacy CRA and Django Deployment Pipeline
Challenges and solutions encountered while containerizing legacy CRA and Django applications. Key lessons for engineers.
Stop Mass Assignment Before It Reaches Your Authorization Layer
Implement a three-tier authorization process to prevent mass assignment.
Background Subagents Can Leak Secrets
Claude Code's background subagents emit system prompt fragments, including authorization data. A security issue to be aware of!
Cloudflare Opens Self-Managed OAuth to All Developers
Cloudflare rolled out self-managed OAuth for all developers, simplifying delegated API access while carefully upgrading its underlying Hydra OAuth engine.
Slack Speeds Up Security Investigations with a Multi-Agent Architecture
Slack's security engineering team explains how it evolved a simple prompt prototype into a structured multi-agent system with Director, Expert, and Critic roles.
AWS Security Makes an Inscrutable Choice
AWS aims to limit potential damage from leaked keys with a quarantine policy, but this may impact user workloads.