Forem

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Review: GitHub Security Lab's Open-Source AI Vulnerability-Scanning Framework for Drupal Module and WordPress Plugin CI Pipel...
Cover image for Review: GitHub Security Lab's Open-Source AI Vulnerability-Scanning Framework for Drupal Module and WordPress Plugin CI Pipel...

Review: GitHub Security Lab's Open-Source AI Vulnerability-Scanning Framework for Drupal Module and WordPress Plugin CI Pipel...

Comments
4 min read
The Claude CLI "Leak": Nobody Won, AI Still Hallucinates, and Companies Are Still Making the Same Mistake
Cover image for The Claude CLI "Leak": Nobody Won, AI Still Hallucinates, and Companies Are Still Making the Same Mistake

The Claude CLI "Leak": Nobody Won, AI Still Hallucinates, and Companies Are Still Making the Same Mistake

2
Comments
7 min read
How SMS Verification Actually Works: Architecture, Failures, and Why 30% of Codes Never Arrive

How SMS Verification Actually Works: Architecture, Failures, and Why 30% of Codes Never Arrive

Comments
4 min read
🔐 Why a GitHub-Based Store? — Security and Community Sharing for Local AI Agents

🔐 Why a GitHub-Based Store? — Security and Community Sharing for Local AI Agents

Comments
3 min read
I Got Sick of Getting Rugged, So I Built a Rug-Pull Detection Engine in Rust

I Got Sick of Getting Rugged, So I Built a Rug-Pull Detection Engine in Rust

2
Comments
6 min read
Why I ditched "Soft Deletes" for S3: Building a Physical Purge Workflow

Why I ditched "Soft Deletes" for S3: Building a Physical Purge Workflow

1
Comments
2 min read
I built a free dev tools site after almost leaking my staging credentials into a "popular" online JWT decoder
Cover image for I built a free dev tools site after almost leaking my staging credentials into a "popular" online JWT decoder

I built a free dev tools site after almost leaking my staging credentials into a "popular" online JWT decoder

Comments
1 min read
1,149 Humans Tried to Social-Engineer Our AI Banker. Here's What OWASP's Agentic Framework Missed.

1,149 Humans Tried to Social-Engineer Our AI Banker. Here's What OWASP's Agentic Framework Missed.

1
Comments
8 min read
GitGuardian MCP: Secret Scanning as a Hard Merge Gate for AI-Generated Code
Cover image for GitGuardian MCP: Secret Scanning as a Hard Merge Gate for AI-Generated Code

GitGuardian MCP: Secret Scanning as a Hard Merge Gate for AI-Generated Code

1
Comments
4 min read
axios Was Compromised on npm — What Happened, How It Works, and What You Must Do Right Now
Cover image for axios Was Compromised on npm — What Happened, How It Works, and What You Must Do Right Now

axios Was Compromised on npm — What Happened, How It Works, and What You Must Do Right Now

5
Comments
9 min read
MCP Scanner Comparison: Cisco vs Snyk vs Pipelock

MCP Scanner Comparison: Cisco vs Snyk vs Pipelock

3
Comments
7 min read
Prompt Chainmail: Workflows and integration examples - part 2

Prompt Chainmail: Workflows and integration examples - part 2

1
Comments
5 min read
Bank of Scotland was fined £160K for a Cyrillic transliteration failure. Here's the technical breakdown.

Bank of Scotland was fined £160K for a Cyrillic transliteration failure. Here's the technical breakdown.

1
Comments
3 min read
Building a KYC Compliance Pipeline in Python: Sanctions Screening + PII Detection

Building a KYC Compliance Pipeline in Python: Sanctions Screening + PII Detection

Comments
5 min read
AI ethics is everywhere. Execution models are nowhere. So I built one.

AI ethics is everywhere. Execution models are nowhere. So I built one.

Comments 1
1 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.