Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Prompt Injection in AI Coding Agents: 3 Attack Vectors, 4 Defenses

Prompt Injection in AI Coding Agents: 3 Attack Vectors, 4 Defenses

Comments
12 min read
AI Ops Agents Are a New Class of Attack Surface
Cover image for AI Ops Agents Are a New Class of Attack Surface

AI Ops Agents Are a New Class of Attack Surface

Comments
7 min read
How to Protect Your IP Prefixes from BGP Hijacking
Cover image for How to Protect Your IP Prefixes from BGP Hijacking

How to Protect Your IP Prefixes from BGP Hijacking

Comments
5 min read
Trained, Not Prompted: Why Fine-Tuned Models Beat LLM Wrappers for Offensive Security

Trained, Not Prompted: Why Fine-Tuned Models Beat LLM Wrappers for Offensive Security

Comments
2 min read
The npm Package That Backdoored Every Build Pulling It Last Week
Cover image for The npm Package That Backdoored Every Build Pulling It Last Week

The npm Package That Backdoored Every Build Pulling It Last Week

Comments
8 min read
Securely Deploying OpenClaw on a VPS With Enterprise Grade Access Control
Cover image for Securely Deploying OpenClaw on a VPS With Enterprise Grade Access Control

Securely Deploying OpenClaw on a VPS With Enterprise Grade Access Control

5
Comments
11 min read
We Reviewed 10 PDF Tools — Here's What Happens to Your Files

We Reviewed 10 PDF Tools — Here's What Happens to Your Files

Comments
1 min read
How I Secured an Autonomous AI Agent on Oracle’s Free Tier (Without MicroVMs)

How I Secured an Autonomous AI Agent on Oracle’s Free Tier (Without MicroVMs)

Comments
4 min read
GHSA-C4QG-J8JG-42Q5: GHSA-C4QG-J8JG-42Q5: Server-Side Request Forgery in OpenClaw QQBot Extension

GHSA-C4QG-J8JG-42Q5: GHSA-C4QG-J8JG-42Q5: Server-Side Request Forgery in OpenClaw QQBot Extension

Comments
2 min read
Multi-Turn Jailbreaks Are the New Prompt Injection
Cover image for Multi-Turn Jailbreaks Are the New Prompt Injection

Multi-Turn Jailbreaks Are the New Prompt Injection

Comments
8 min read
MCP Server Exploitation Is the Attack Surface Nobody Audited Yet
Cover image for MCP Server Exploitation Is the Attack Surface Nobody Audited Yet

MCP Server Exploitation Is the Attack Surface Nobody Audited Yet

Comments
8 min read
Meta's Internal AI Agent Leaked Sensitive Data. There Was No Attacker.
Cover image for Meta's Internal AI Agent Leaked Sensitive Data. There Was No Attacker.

Meta's Internal AI Agent Leaked Sensitive Data. There Was No Attacker.

Comments
8 min read
Replit's AI Wiped a Production Database on Day 9 — Then Reported False Test Results
Cover image for Replit's AI Wiped a Production Database on Day 9 — Then Reported False Test Results

Replit's AI Wiped a Production Database on Day 9 — Then Reported False Test Results

Comments
6 min read
SecAudit: I built a passive web security auditor in Python (TLS, headers, CSP, cookies, DNS — all parallel)

SecAudit: I built a passive web security auditor in Python (TLS, headers, CSP, cookies, DNS — all parallel)

Comments
1 min read
Authenticating AI Agents Without Shared Secrets

Authenticating AI Agents Without Shared Secrets

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.