SECURITY (64)
- When the Test Subject Breaks Out: OpenAI's Agents and Hugging Face
- Your First AI Agent Should Only Be Able to Read
- The Agent Harness: What to Build Around the Model and What to Rip Out
- Giving AI Agents a Shared Vocabulary with OWL and SHACL
- What's Actually Inside an AI Agent
- Hermes Agent: How a Self-Improving AI Agent Remembers What It Learns
- Hermes Agent v0.2.0 Is Out. Here's What I'd Actually Use It For
- MCP or Just Your API? What the Protocol Actually Adds
- DST Root CA X3 Expires September 30, and Old OpenSSL Is the Real Risk
- GitHub Stops Taking Your Password for Git This Friday
- GitHub Copilot's Technical Preview: Read the FAQ Before You Hit Tab
- The Codecov Bash Uploader Breach and the Problem With Curl to Bash in CI
- Patching On-Prem Exchange After ProxyLogon Is Only the First Step
- SolarWinds Orion and the Build Pipeline You Probably Aren't Guarding
- Zerologon: Patch Every Domain Controller, Then Get Ready for February
- Python 2 Sunsets on January 1: What It Means and How to Get Off It
- GitHub Actions Hits GA: Free CI for Side Projects
- IMDSv2 and SSRF: Putting a Session in Front of EC2 Metadata
- Chrome 80 Plans to Make Cookies SameSite=Lax by Default: What Breaks and How to Prepare
- DNS over HTTPS Is Coming to Firefox and Chrome
- After Capital One: SSRF and the Metadata Endpoint
- BlueKeep (CVE-2019-0708): Patch RDP Before Somebody Writes the Worm
- Why PHP Can't Talk to Your New MySQL 8
- The Docker Hub Breach Is a Good Reason to Audit Your Build Credentials
- WebAuthn Is a W3C Standard. Passwords Get a Real Rival
- runc CVE-2019-5736: Containers Are Not a Security Boundary
- CVE-2018-1002105: The Kubernetes API Server Flaw and What to Check on Your Cluster
- event-stream and flatmap-stream: What a New Maintainer Can Ship
- TLS 1.3 Is Now RFC 8446: What It Cuts, What It Speeds Up, and When Your Server Gets It
- npm audit in npm 6: Read the Report Before You Reach for audit fix
- GDPR for Web Developers: What the Regulation Means in Code
- VPNFilter: Why the FBI Wants You to Reboot Your Router
- Let's Encrypt Wildcards Are Here, and They Run Through Your DNS
- Meltdown and Spectre: What Patching Looks Like One Week In
- Chrome 62 Says Not Secure When You Type: Moving Your Site to HTTPS
- KRACK and WPA2: What It Means for Your Home Wi-Fi and Smart Devices
- Equifax and Apache Struts: Know Your Dependencies and Patch Fast
- WannaCry Is Your Reason to Patch MS17-010 and Turn Off SMBv1
- The First SHA-1 Collision: What It Means for Certificates and Git
- After the Dyn Attack: Keeping Your Cameras, DVRs and Routers Out of a Botnet
- Dirty COW: Patch the Kernel, Then Make Sure You're Running It
- HTTPoxy: Strip the Proxy Header Before It Becomes HTTP_PROXY
- ImageTragick: Treat Every Uploaded Image as Untrusted Input
- Let's Encrypt Is in Public Beta: Free Certificates for Anyone Who Automates
- Kubernetes 1.0 for People Who Just Learned Docker
- Logjam: Kill Export Diffie-Hellman and Bring Your Own Group
- FREAK and the Export Ciphers Still Hiding in Your Server Config
- POODLE Is Your Cue to Turn Off SSLv3
- Shellshock: What the Bash Bug Is and What to Patch
- Docker 1.0 for Web Developers: What Changes and What to Ask
- You Patched Heartbleed. Now Finish the Job
- Adobe's Breach: Encrypted Passwords Are Not Hashed Passwords
- GitHub Two-Factor Authentication: Turn It On, Then Clean Up Your SSH Keys
- Forward Secrecy for Everyday HTTPS: Put ECDHE and DHE First
- OWASP Top 10 2013: What Changed and One Habit for Each Risk
- Lucky Thirteen or RC4? Picking a TLS Cipher Order
- The PHP-CGI Query String Bug, Explained
- Patch Apache: The Range Header DoS
- PHP 5.3.7 Broke crypt(). Go Straight to 5.3.8
- Lessons from 2011's Breach Parade
- After Gawker, Please Hash Passwords with bcrypt
- Firesheep Is Out. Lock Down Your PHP Sessions
- Stop Gluing SQL Strings Together with PDO Prepared Statements
- Slowloris vs Apache 2.2: What You Can Actually Tune
all tags · all posts