» Tag
security
518 postsFurtex: Linux Post-Exploitation and Evasion Research Toolkit
Furtex is a Linux post-exploitation and evasion research toolkit based on io_uring and eBPF, designed for authorized research.
Study Finds AI Text Watermarks Fail Legal Evidence Standards
Study finds AI watermarking schemes KGW, Unigram, and SynthID fail Daubert legal criteria after simple paraphrase attacks strip out marks.
TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
TP-Link's Kasa EC71 camera exposed precise GPS coordinates via a 6-year-old unauthenticated protocol flaw, plus a fleet-wide RSA key and MD5 password storage.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comImplementing FIDO's passkey-export format: cxf-kit and 5 spec bugs found
cxf-kit is the first TypeScript implementation of FIDO's CXF passkey-export standard, exposing five spec bugs found during development.
agent-gate: keep your AI agents from having unchecked power
agent-gate is a dependency-free MIT Python layer that gates AI agent actions behind deterministic checks and one-time tokens, blocking prompt injection and irreversible mistakes.
Why AI Agents Must Never Choose Their Own Acting Subject
AI agents shouldn't self-assign identity via tool arguments. Learn why acting subjects must come from trusted boundaries, not model output.
8 security layers for an MCP marketplace: what each one catches
A developer built 8 defense-in-depth security layers for an MCP marketplace after a trojan slipped through — here's what each layer actually catches.
Open AI-Agent Incident Database Lists 32 Failures, Admits Its Gaps
ARE Incident Database catalogs 32 real AI agent failures mapped to OWASP ASI Top 10, with runnable repros and honestly flagged coverage gaps.
Study Finds 38.9% of AI Coding Agent PRs Contain Security Smells
Large-scale study of AI coding agent PRs finds 38.9% contain security smells, with most leaked credentials introduced by human developers, not AI.
Clawk Gives Coding Agents a Disposable Linux VM, Not Your Laptop
Clawk runs coding agents in isolated, disposable Linux VMs instead of your host machine, using hypervisor-level isolation instead of prompt rules.