Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
IDOR in Cursor-Generated APIs: The Auth Check That Never Shows Up
Cover image for IDOR in Cursor-Generated APIs: The Auth Check That Never Shows Up

IDOR in Cursor-Generated APIs: The Auth Check That Never Shows Up

Comments
3 min read
Why on-device AI is a supply chain problem now (and how to fix it)

Why on-device AI is a supply chain problem now (and how to fix it)

Comments
4 min read
Building a Custom Java Card Applet for Payment Cards

Building a Custom Java Card Applet for Payment Cards

Comments
2 min read
Why AI agents need cryptographic memory — and how to add it in one line
Cover image for Why AI agents need cryptographic memory — and how to add it in one line

Why AI agents need cryptographic memory — and how to add it in one line

Comments
1 min read
Your Agent Needs a Passport Before It Needs a Wallet

Your Agent Needs a Passport Before It Needs a Wallet

Comments
3 min read
How NexArt Protects AI Execution Evidence From Tampering
Cover image for How NexArt Protects AI Execution Evidence From Tampering

How NexArt Protects AI Execution Evidence From Tampering

Comments
6 min read
How to Finally (and Iteratively) Kill Every Last 'npm audit'

How to Finally (and Iteratively) Kill Every Last 'npm audit'

Comments
3 min read
We Ran a $5,000 AI Agent Adversarial Testbed. Social Engineering Won 74.6% of the Time.

We Ran a $5,000 AI Agent Adversarial Testbed. Social Engineering Won 74.6% of the Time.

Comments
6 min read
Undercover mode, decoy tools, and a 3,167-line function: inside Claude Code's leaked source
Cover image for Undercover mode, decoy tools, and a 3,167-line function: inside Claude Code's leaked source

Undercover mode, decoy tools, and a 3,167-line function: inside Claude Code's leaked source

Comments
9 min read
The Air-Gapped Chronicles: The Agentic Ecosystem - When Your AI Agents Become Your Loudest Shadow Identities

The Air-Gapped Chronicles: The Agentic Ecosystem - When Your AI Agents Become Your Loudest Shadow Identities

Comments
4 min read
Who Audits the AI-Generated Code? We Built an AI to Do It

Who Audits the AI-Generated Code? We Built an AI to Do It

Comments
4 min read
Building a Cross-Platform Local-Only Password Manager with Flutter: Why We Chose Platform Security Over Cloud Storage

Building a Cross-Platform Local-Only Password Manager with Flutter: Why We Chose Platform Security Over Cloud Storage

Comments
8 min read
Ambiguous MCP Instructions Enable Unauthorized AI Actions: Enhanced Validation and Oversight Proposed

Ambiguous MCP Instructions Enable Unauthorized AI Actions: Enhanced Validation and Oversight Proposed

Comments
10 min read
HIPAA Compliance for Telehealth: What Developers Building Virtual Care Platforms Need to Get Right

HIPAA Compliance for Telehealth: What Developers Building Virtual Care Platforms Need to Get Right

Comments
4 min read
The 2026 HIPAA Compliance Checklist for Developers and IT Teams

The 2026 HIPAA Compliance Checklist for Developers and IT Teams

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.