Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Cheapest Way to Self-Host Vaultwarden in 2026

The Cheapest Way to Self-Host Vaultwarden in 2026

Comments
9 min read
Why I built attack-chain correlation on top of Semgrep and Joern
Cover image for Why I built attack-chain correlation on top of Semgrep and Joern

Why I built attack-chain correlation on top of Semgrep and Joern

Comments
3 min read
Securing Package Manager Postinstall Scripts: Mitigating Access to Sensitive User Data During Installation

Securing Package Manager Postinstall Scripts: Mitigating Access to Sensitive User Data During Installation

Comments
8 min read
When Your Security Scanner Becomes the Weapon: Lessons from the Trivy Supply Chain Attack

When Your Security Scanner Becomes the Weapon: Lessons from the Trivy Supply Chain Attack

1
Comments
2 min read
Why AI Agent Authorization Is Still Unsolved in 2026

Why AI Agent Authorization Is Still Unsolved in 2026

Comments
7 min read
Beyond the Token: Securing Your Localhost with Biometric Passkeys

Beyond the Token: Securing Your Localhost with Biometric Passkeys

Comments
9 min read
I Added Minimum GitHub Security Settings to My OSS Repositories and Created a Setup Guide

I Added Minimum GitHub Security Settings to My OSS Repositories and Created a Setup Guide

Comments
4 min read
Every Compliance Framework Requires Key Rotation. No Platform Tells You When.
Cover image for Every Compliance Framework Requires Key Rotation. No Platform Tells You When.

Every Compliance Framework Requires Key Rotation. No Platform Tells You When.

Comments
5 min read
I Built an Open-Source Security Middleware for LLMs, Here's How It Works

I Built an Open-Source Security Middleware for LLMs, Here's How It Works

1
Comments 1
4 min read
How I built a real-time LLM "Kill-Switch" for Vercel Edge using Atomic Redis

How I built a real-time LLM "Kill-Switch" for Vercel Edge using Atomic Redis

Comments
3 min read
Global Web Encryption Relies on Single U.S. Non-Profit, Raising Centralization and Geopolitical Risks

Global Web Encryption Relies on Single U.S. Non-Profit, Raising Centralization and Geopolitical Risks

Comments
10 min read
OpenAI's trust problem is getting worse — here's your local plan B

OpenAI's trust problem is getting worse — here's your local plan B

Comments
3 min read
How HookProbe Detects CVE-2026-3502 (TrueConf Client) and Prevents Code Execution
Cover image for How HookProbe Detects CVE-2026-3502 (TrueConf Client) and Prevents Code Execution

How HookProbe Detects CVE-2026-3502 (TrueConf Client) and Prevents Code Execution

Comments
5 min read
Full Attack‑Chain Breakdown: How XSS Becomes a Silent Session Hijack (CAISD)

Full Attack‑Chain Breakdown: How XSS Becomes a Silent Session Hijack (CAISD)

Comments
2 min read
pip-guardian on Pypi

pip-guardian on Pypi

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.