» Tag
security
92 postsUnderstanding PandoCore's Security Webhook Fail-Open Policy
PandoCore's security webhook uses a fail-open policy, managing potential risks effectively.
Coinkite's AI Audit Didn't Fail, It Was Pointed in the Wrong Direction
Coinkite's AI audit didn't fail; it was misdirected. Lessons for software security practices must be learned.
AutoGPT Email Block: SSRF Vulnerability and Its Implications
The SSRF vulnerability in AutoGPT's `SendEmailBlock` feature allows internal network scanning and service information exfiltration.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comCopilot reveals how to hack itself through manipulation
Microsoft Copilot was manipulated by researchers to reveal its own vulnerabilities, named "CoSnitch" by Varonis.
Trust Without Boundaries: An Architectural Analysis of Satellite Flight Software
An analysis of security vulnerabilities in spacecraft flight software, focusing on NASA's cFS architecture and experimental findings.
Xaidr: In-process Runtime Security and Governance for AI Agents
Xaidr offers local security and governance for AI agents by blocking harmful inputs.
Coldcard’s Entropy Bug Reveals Hidden Vulnerability in Hardware Wallet Security
The Coldcard entropy bug exposes critical vulnerabilities in hardware wallet security. Essential insights for users.
Signal Adds New Security Layer for Safe Messaging Verification
Signal introduces Automatic Key Verification (AKV) to enhance chat security.
Open-Source eBPF Volumetric DDoS Protection
Tempesta xFW is an open-source volumetric DDoS protection for Linux, powered by XDP and eBPF.
Supply Chain Attack Discovered in BdThemes WordPress Plugins
Supply chain attack in BdThemes WordPress plugins: hidden admin accounts created.