Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
AI News Roundup: Claude Code Security, ggml.ai + Hugging Face, and 17K tok/s Silicon Llama

AI News Roundup: Claude Code Security, ggml.ai + Hugging Face, and 17K tok/s Silicon Llama

Comments
3 min read
Your Terraform Is Probably Insecure — Here Are 90 Patterns to Check

Your Terraform Is Probably Insecure — Here Are 90 Patterns to Check

Comments
4 min read
MCP tool spoofing succeeds 100% of the time. A new paper maps 12 security risks across 4 agent protocols.

MCP tool spoofing succeeds 100% of the time. A new paper maps 12 security risks across 4 agent protocols.

3
Comments 2
3 min read
CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK

CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK

Comments
2 min read
Vercel’s "Agentic" Shift: Is Your Proprietary Code Now Training AI?
Cover image for Vercel’s "Agentic" Shift: Is Your Proprietary Code Now Training AI?

Vercel’s "Agentic" Shift: Is Your Proprietary Code Now Training AI?

7
Comments
2 min read
Guardrails deleted, now what?

Guardrails deleted, now what?

Comments
4 min read
Authelia vs Authentik: Which Auth Server?

Authelia vs Authentik: Which Auth Server?

Comments
4 min read
CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the <

CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the <

Comments
2 min read
We built a free CRA compliance scorer into a silicon advisor. Here's what we learned.
Cover image for We built a free CRA compliance scorer into a silicon advisor. Here's what we learned.

We built a free CRA compliance scorer into a silicon advisor. Here's what we learned.

1
Comments
3 min read
RASP vs WAF: The Key Differences and Why You Need a Third Approach

RASP vs WAF: The Key Differences and Why You Need a Third Approach

Comments
9 min read
Building a Cost-Effective Windows Code Signing Pipeline with Sectigo, Google Cloud KMS, and GitHub Actions

Building a Cost-Effective Windows Code Signing Pipeline with Sectigo, Google Cloud KMS, and GitHub Actions

Comments
9 min read
Your LangChain Agent Has No Security. Neither Does CrewAI, OpenAI, or 6 Others.

Your LangChain Agent Has No Security. Neither Does CrewAI, OpenAI, or 6 Others.

2
Comments
4 min read
We Built a Python SDK Where the Credentials Never Enter Your Code

We Built a Python SDK Where the Credentials Never Enter Your Code

6
Comments
3 min read
I Spent 3 Months Solving a Security Gap Nobody Talks About: LLM Artifact Integrity

I Spent 3 Months Solving a Security Gap Nobody Talks About: LLM Artifact Integrity

Comments
5 min read
Android 2026: Google Closes the Door. "What Every Developer Should Know"
Cover image for Android 2026: Google Closes the Door. "What Every Developer Should Know"

Android 2026: Google Closes the Door. "What Every Developer Should Know"

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.