Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Windows Zero-Days, Recall Bypasses, RDP Exfiltration: Key Security Threats

Windows Zero-Days, Recall Bypasses, RDP Exfiltration: Key Security Threats

Comments
4 min read
The Cloud Security Checklist I Use at Every Enterprise Engagement

The Cloud Security Checklist I Use at Every Enterprise Engagement

Comments
2 min read
IDOR in AI-Generated Code: What Cursor Won't Check for You
Cover image for IDOR in AI-Generated Code: What Cursor Won't Check for You

IDOR in AI-Generated Code: What Cursor Won't Check for You

1
Comments
2 min read
GhostLine — Real-Time Encrypted Chat (No Signup Required)

GhostLine — Real-Time Encrypted Chat (No Signup Required)

2
Comments
1 min read
I Ran a Subdomain Takeover Checker on GitHub.com and Found a Vulnerable Subdomain
Cover image for I Ran a Subdomain Takeover Checker on GitHub.com and Found a Vulnerable Subdomain

I Ran a Subdomain Takeover Checker on GitHub.com and Found a Vulnerable Subdomain

2
Comments
2 min read
$60K Billed in 13 Hours: Why Leaked Firebase Keys Keep Killing AI-Built Apps

$60K Billed in 13 Hours: Why Leaked Firebase Keys Keep Killing AI-Built Apps

Comments
5 min read
PostgreSQL Row Level Security: A Complete Guide

PostgreSQL Row Level Security: A Complete Guide

1
Comments
2 min read
How Commit Scores npm Packages: The Methodology Behind getcommit.dev/audit

How Commit Scores npm Packages: The Methodology Behind getcommit.dev/audit

Comments
9 min read
Vercel Hack: Why You Need to Rotate Your "Non-Sensitive" Environment Variables Today

Vercel Hack: Why You Need to Rotate Your "Non-Sensitive" Environment Variables Today

14
Comments 1
2 min read
The Agent Identity Stack: What Shipped in April 2026

The Agent Identity Stack: What Shipped in April 2026

Comments
9 min read
A 300-Line GitHub Actions Security Linter: Five Rules That Catch the CVE Patterns

A 300-Line GitHub Actions Security Linter: Five Rules That Catch the CVE Patterns

Comments
7 min read
Beyond Vibe-Coding: Why we built a "Stripe for App-Security" using LightRAG

Beyond Vibe-Coding: Why we built a "Stripe for App-Security" using LightRAG

Comments 2
2 min read
CVE-2026-34197: el bug de ActiveMQ que vivió 13 años y ahora CISA obliga a parchar

CVE-2026-34197: el bug de ActiveMQ que vivió 13 años y ahora CISA obliga a parchar

Comments
8 min read
World ID for Agents Is L1/L2. Here's Why L4 Still Doesn't Exist.

World ID for Agents Is L1/L2. Here's Why L4 Still Doesn't Exist.

Comments
5 min read
DraftKings Credential Trafficking: Post-Plea Monetization & Detection Gaps
Cover image for DraftKings Credential Trafficking: Post-Plea Monetization & Detection Gaps

DraftKings Credential Trafficking: Post-Plea Monetization & Detection Gaps

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.