Forem

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
40,000 Exposed OpenClaw Instances — and 6 New CVEs This Week

40,000 Exposed OpenClaw Instances — and 6 New CVEs This Week

Comments
3 min read
CVE-2026-27942: Infinite Loops & Broken Dreams: The fast-xml-parser Stack Exhaustion

CVE-2026-27942: Infinite Loops & Broken Dreams: The fast-xml-parser Stack Exhaustion

Comments
2 min read
The Gap Between Encrypting Secrets and Proving You Handled Them Right
Cover image for The Gap Between Encrypting Secrets and Proving You Handled Them Right

The Gap Between Encrypting Secrets and Proving You Handled Them Right

1
Comments
4 min read
Dispatch From the Other Side: Aligned Incentives
Cover image for Dispatch From the Other Side: Aligned Incentives

Dispatch From the Other Side: Aligned Incentives

1
Comments
2 min read
HTML Entities: The Complete Guide to Special Characters and XSS Prevention

HTML Entities: The Complete Guide to Special Characters and XSS Prevention

Comments
2 min read
Starkiller Phishing: MFA Bypass via Reverse Proxies

Starkiller Phishing: MFA Bypass via Reverse Proxies

Comments
6 min read
I realized my AI tools were leaking sensitive data. So I built a local proxy to stop it
Cover image for I realized my AI tools were leaking sensitive data. So I built a local proxy to stop it

I realized my AI tools were leaking sensitive data. So I built a local proxy to stop it

Comments
3 min read
How to Stop Your App from Leaking User Locations (Yes, It Matters)
Cover image for How to Stop Your App from Leaking User Locations (Yes, It Matters)

How to Stop Your App from Leaking User Locations (Yes, It Matters)

1
Comments
5 min read
I built Actra: a governance layer to control what AI agents are allowed to do
Cover image for I built Actra: a governance layer to control what AI agents are allowed to do

I built Actra: a governance layer to control what AI agents are allowed to do

5
Comments
4 min read
Claude Code's Entire Source Code Was Just Leaked via npm Source Maps — Here's What's Inside

Claude Code's Entire Source Code Was Just Leaked via npm Source Maps — Here's What's Inside

81
Comments 2
5 min read
The Illusion of Data Custody in Legal AI — and the Architecture I Built to Replace It

The Illusion of Data Custody in Legal AI — and the Architecture I Built to Replace It

1
Comments
4 min read
Why Proof-of-Work Beats CAPTCHA for Form Protection

Why Proof-of-Work Beats CAPTCHA for Form Protection

1
Comments 2
3 min read
Whole-laptop scanner for the Axios supply chain attack
Cover image for Whole-laptop scanner for the Axios supply chain attack

Whole-laptop scanner for the Axios supply chain attack

5
Comments
3 min read
CVE-2026-27965: Manifest Destiny: How Vitess Backups Became a Shell-Popping Paradise

CVE-2026-27965: Manifest Destiny: How Vitess Backups Became a Shell-Popping Paradise

Comments
2 min read
FullAgenticStack WhatsApp-first: RFC-WF-0015
Cover image for FullAgenticStack WhatsApp-first: RFC-WF-0015

FullAgenticStack WhatsApp-first: RFC-WF-0015

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.