Skip to content
Category

Security

Security from a builder's seat. Vulnerability disclosures, supply-chain attacks, secrets management, and defensive engineering patterns — explained with enough depth to act on, not just react to.

Inside JumpServer: Open-Source PAM for Modern Infrastructure
Article 52m ago 0

Inside JumpServer: Open-Source PAM for Modern Infrastructure

A self-hostable alternative to commercial PAM platforms brings browser-based access control, but its multi-component architecture requires careful management.

Emeka Okafor
Beyond Code: How StegoAd Hid Malware in Fonts and Images

Beyond Code: How StegoAd Hid Malware in Fonts and Images

Article · 10h ago2
How to Stop AI Agents From Committing Your Secrets

How to Stop AI Agents From Committing Your Secrets

Article · 2d ago0
Stop GitHub Copilot From Sabotaging Your Terraform Security

Stop GitHub Copilot From Sabotaging Your Terraform Security

Article · 2d ago2
The MCP Security Blind Spot in AI Coding Assistants

The MCP Security Blind Spot in AI Coding Assistants

Article · 2d ago0
Inside PinpinRAT: How APTs Hijack Developer Build Pipelines

Inside PinpinRAT: How APTs Hijack Developer Build Pipelines

Article · 3d ago5
AI Coding Assistants Turn Local Git Repos Into Cloud Exploits

AI Coding Assistants Turn Local Git Repos Into Cloud Exploits

Article · 3d ago2
The MCP Security Blind Spot in AI Coding Assistants

The MCP Security Blind Spot in AI Coding Assistants

Article · 3d ago0
When Seven AI Security Gates All Say LGTM

When Seven AI Security Gates All Say LGTM

Article · 3d ago2
Node.js as a Portable Attack Vector in Phishing Campaigns

Node.js as a Portable Attack Vector in Phishing Campaigns

Article · 3d ago0
Miasma Proves Trusted Publishing Can Backfire Spectacularly

Miasma Proves Trusted Publishing Can Backfire Spectacularly

Article · 3d ago0
The Client-Side Illusion: Lessons from the J&J Web App Vulnerabilities

The Client-Side Illusion: Lessons from the J&J Web App Vulnerabilities

Article · 4d ago0
The AI Auditing Wave and the End of Battle-Tested Code

The AI Auditing Wave and the End of Battle-Tested Code

Article · 4d ago1
The OAuth Supply Chain: Lessons From the LastPass Breach

The OAuth Supply Chain: Lessons From the LastPass Breach

Article · 4d ago4
The CAPTCHA is Dead (And AI Killed It)

The CAPTCHA is Dead (And AI Killed It)

Article · 5d ago3
The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

Article · 5d ago0