560 blogs tracked4,950 posts indexed

#security

49 posts · 15 companies · newest first

Curated view of this subject:Topic: Security144
1

How one bug bounty researcher chooses the features they investigate (opens on the source site)

As we kick off Cybersecurity Awareness Month, the GitHub Bug Bounty team spotlights @vaib25vicky, exploring their methodology, techniques, and experiences hacking on GitHub. The post How one bug bounty researcher chooses the features they investigate appeared first on The GitHub Blog.

securitybug-bountyexcerpt only · body stays at the source
From the web
2

Guide to the OWASP LLM Top 10 (opens on the source site)

Large language models (LLMs) have become mainstream. Recent estimates suggest there are over 1.1 billion ChatGPT users. LLMs and AI agents have become a part of every aspect of our lives, from writing emails to coding and everything in between. Yet, this scenario is a cybersecurity incident waiting to happen. Many developers aren’t used to ...

blogsecurityexcerpt only · body stays at the source
From the web
3

Building an evidence-grounded agentic security operations harness on Cloudflare (opens on the source site)

Cloudflare Managed Defense uses a team of specialized AI agents built on Workers and global network telemetry to analyze security alerts. By separating deterministic evidence collection from model inference, the system delivers grounded recommendations to Managed Defense Analysts.

artificial-intelligencecloudforce-oneexcerpt only · body stays at the source
From the web
4

Twenty-two pending curl vulnerabilities (opens on the source site)

On October 14 2026 we will ship curl 8.23.0. The next iteration in the never-ending series of version bumps from the curl project. We always think of the next release as the best version we ever did – and this time is no exception. Decades of collected experiences and meticulous polishing has lead us to … Continue reading Twenty-two pending curl vulnerabilities →

curl-and-libcurlsecurityexcerpt only · body stays at the source 31 comment on HN (opens the discussion)
From the web
5

Security Baked Into the JVM: no single party controls the outcome (opens on the source site)

A URL is a name, and names get reused. Replace the bytes behind https://repo.example.org/order-processor.jar and every permission granted to that URL still applies, now to code nobody audited. So far in this series, Part 1 declared constraints on a remote call, Part 2 vetted code before a client loaded it, Part 3 established who is calling, and Part 4 carried that chain of identities across the wire.

javajvmexcerpt only · body stays at the source
From the web
9

Is sandboxing sufficient to contain rogue agents? (opens on the source site)

Quick caveats: this is a post on AI safety, written by a cryptography professor. If that troubles you, you should read something else. I try hard not to work on AI (except when the topic occasionally tosses itself in my path), so in this post I’m mostly trying to referee arguments made by others. If … Continue reading Is sandboxing sufficient to contain rogue agents? →

aisecurity-researchexcerpt only · body stays at the source 54100 comments on HN (opens the discussion)
From the web
10

Building a certificate authority for the whole Internet (opens on the source site)

Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web.

birthday-weekcryptographyexcerpt only · body stays at the source 7457 comments on HN (opens the discussion)
From the web
12

Building a post-quantum certificate authority with Merkle Tree Certificates (opens on the source site)

As post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs, Merkle Tree Certificates offer a path to compact, auditable authentication. Cloudflare’s new certificate authority will support MTC issuance at scale.

birthday-weekcertificate-transparencyexcerpt only · body stays at the source
From the web
13

How we found 24 Android vulnerabilities using our open source AI security agent (opens on the source site)

A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app. The post How we found 24 Android vulnerabilities using our open source AI security agent appeared first on The GitHub Blog.

securitygithub-security-labexcerpt only · body stays at the source 82 comments on HN (opens the discussion)
From the web
14

Trading a Cloud Identity for Your Own: Workload Attestation on Managed Compute (opens on the source site)

By Dhruv PratapIntroductionOrganizations that have been around for a while usually run two identity systems side by side. One belongs to the cloud provider: IAM roles, instance profiles, execution roles. The other is your own, and it is the one your internal services actually check when they decide whether to answer a request.On infrastructure you build yourself, you can bootstrap your own identity however you like. On managed compute you cannot. The provider hands your process a cloud identity and nothing else.This post describes how we close that gap for Apache Spark workloads running on…

identityaws-emrexcerpt only · body stays at the source
From the web
17

Microsoft is updating its author-signing certificate starting September 23, 2026 (opens on the source site)

Starting September 23, 2026, Microsoft is updating the author-signing certificate used for NuGet packages. Customers using trusted signer policies or certificate fingerprint verification should add the new certificate as soon as possible. The post Microsoft is updating its author-signing certificate starting September 23, 2026 appeared first on .NET Blog.

.netnugetexcerpt only · body stays at the source
From the web
19

AI cybersecurity is a cat and mouse game (opens on the source site)

Ryan chats with Sam Curry, CSO at Zscaler, about where human intelligence sits in the new security landscape with AI, why shifting security protections closer to applications helps limit probes for vulnerabilities, and why building more resilient code infrastructure is the best way to address the vulnerabilities AI does discover.

podcastse-techexcerpt only · body stays at the source
From the web
20

Set Up Cloud OIDC From the Pulumi CLI (opens on the source site)

Pulumi ESC can act as an OpenID Connect (OIDC) provider for AWS, Azure, and Google Cloud, issuing short-lived, signed tokens that these clouds exchange for temporary credentials. This eliminates hard-coded credentials and improves your security posture. Last year, we introduced an onboarding flow in the Pulumi Cloud console that makes it super easy to configure OIDC for your cloud provider in a few guided steps. We’re bringing Pulumi Cloud into the CLI so agents can use its capabilities directly from the terminal, without requiring a human to complete steps in the console. The new pulumi env…

escpulumi-cliexcerpt only · body stays at the source
From the web
21

How to build a secure-by-default AI coding agent (opens on the source site)

Ryan chats with Greg Jennings, VP of Engineering for AI Products at Anaconda, about what it takes to build a secure-by-default AI coding agent, why prompts shouldn't be treated as strict security guardrails, and how Anaconda is using strategic acquisitions to secure the AI software supply chain.

podcastse-techexcerpt only · body stays at the source
From the web
23

How Identity Federation Empowers Partner API Strategy (opens on the source site)

Business identity is a complex issue rife with risks across the board. Large enterprises often require deep, flexible integrations with dozens or hundreds of partners, but this comes with significant risk — between the potential for information leakage, concerns around replays or data usage for continued insecure access, and the sheer friction of such a ...

blogsecurityexcerpt only · body stays at the source
From the web
24

Important Update for GitHub Actions OIDC: Immutable Subject Claims (opens on the source site)

GitHub has introduced Immutable Subject Claims for OIDC (OpenID Connect) in GitHub Actions. This update fixes a security issue where the subject claim in the OIDC token used to be based on organisation and repository names instead of permanent identifiers. What was the problem? Organisation and repository names can be changed or reused. This means that if an organisation or repository is deleted or renamed, another actor could, in theory, create a new repository or organisation with the same name. This would let them land in the same namespace within the subject claim, and in the worst case…

github-actionsoidcexcerpt only · body stays at the source
From the web
26

Neo Security: Securing Infrastructure in the Agentic Era (opens on the source site)

Recently, AI systems have started turning up exploitable flaws in code that survived decades of human review. The frontier labs have released useful tools to help uncover many of these flaws through agent-led static code analysis. This is a huge leap ahead, but cloud infrastructure has many exploitable flaws that code analysis alone cannot find. These flaws are often as severe as the ones in code, or worse, and they await discovery by malicious agents on offense. We realized recently we can uniquely help here. At Pulumi, we have complete visibility into your entire cloud estate:…

aisecurityexcerpt only · body stays at the source
From the web
27

OpenClaw went viral. Meet the maintainers building and securing it. (opens on the source site)

OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months. The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog.

maintainersopen-sourceexcerpt only · body stays at the source
From the web
30

Security Baked Into the JVM: sixteen Subjects on the wire (opens on the source site)

Alice calls the order service. The order service calls the ledger on her behalf. At the second hop, the ledger has to decide whose authority the debit is being made under. Most stacks answer badly. Forward Alice’s bearer token verbatim, and the ledger cannot tell her from the service that relayed it. Drop the token and the ledger sees a machine, with no record that a human started the chain. Neither option lets the ledger authorize the combination.

javajvmexcerpt only · body stays at the source
From the web
32

Black-box pen tests on Replit (opens on the source site)

Replit enables you to build apps to create and launch apps that hold real customer data within a day. Before coding agents, a full pre-launch security review required procuring a pen test from a vendor that would cost thousands, and weeks of back-and-forth. A penetration (”pen”) test is a safe, authorized mock cyberattack that helps you fix security flaws before bad hackers find them. As we have democratized software creation, we have also sought to democratize securing it. A new generation of creators needs to ensure their apps are hardened against attackers, who look at apps built with AI…

securityexcerpt only · body stays at the source
From the web
33

Make zero CVEs your new default (opens on the source site)

Supply-chain attacks have kept escalating while AI writes more of the code you ship. Docker's latest updates bring more software built from source into your images, keep security coverage running past end of life, carry every guarantee through your customized images, and move policy enforcement onto every developer machine.

communityenterpriseexcerpt only · body stays at the source
From the web
34

Govern Replit at scale (opens on the source site)

New Admin API, Audit Logs, and Workspace Settings give organizations more insight and flexibility into how they adopt AI with Replit. Replit helps teams turn ideas into working software quickly. Most companies start with a handful of builders and a few prototypes. Then it works, and it spreads: more teams, more projects, more software running in production. That shift creates work for a specific group of people. As AI tools spread across a company: IT, procurement, and admin teams absorb the cost. They field permission requests, run access reviews, make policy decisions tool by tool, and…

securityenterpriseexcerpt only · body stays at the source
From the web
35

What 50 open source projects taught us about security in the AI era (opens on the source site)

See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security. The post What 50 open source projects taught us about security in the AI era appeared first on The GitHub Blog.

maintainersopen-sourceexcerpt only · body stays at the source 41 comment on HN (opens the discussion)
From the web
36

A new security baseline for enterprise agentic adoption (opens on the source site)

Agent Baseline is a blueprint for AI adoption that defines six security outcomes for putting enterprise agents to work without giving them unchecked authority. Consider this scenario: a customer-support agent receives a ticket with an attachment. Hidden inside the attachment is an instruction: query the customer database and send the results to an external address....

partnershipssecurityexcerpt only · body stays at the source
From the web
38

Security Baked Into the JVM: two Subjects, one call (opens on the source site)

The constraint system stops a bad call before it leaves the JVM. The Safe Codebase Audit Pipeline stops bad code before a client ever loads it. What remains is identity: who is calling, and can you verify it? Most frameworks answer with a token check at the door. A filter validates a bearer token, sets a thread-local variable, and hopes that nothing downstream forgets to look at it. DirtyChai answers differently.

javajvmexcerpt only · body stays at the source
From the web
39

YOLO Mode Is the Right Default. Your Laptop Is the Wrong Place for It. (opens on the source site)

Claude Code calls the flag --dangerously-skip-permissions, and the community long ago renamed it YOLO mode. It lets your coding agent run any command it wants without ever asking for permission. Every agent has some version of it, Codex and Cursor included, and if you use these tools seriously, you are probably running one of them every day. I am. YOLO mode is also what makes a coding agent worth having. An agent that stops for approval before every command is not autonomous; it’s a slow pair programmer. But you cannot let it run wild on your machine without real guardrails either. You have…

aiai-agentsexcerpt only · body stays at the source
From the web
41

What the bliss taught us (opens on the source site)

At this exact moment curl’s summer of bliss 2026 ends. We (the maintainers of curl) took the entire month of July off from vulnerability reporting and in this post I will try to explain how this went. (If you feel like skipping the wordy blab below, the single word answer is: fine) This was possibly … Continue reading What the bliss taught us →

curl-and-libcurlsecurityexcerpt only · body stays at the source 91 comment on HN (opens the discussion)
From the web
43

Tame Dependabot: Group your updates, slow the cadence, keep security fast (opens on the source site)

Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. The post Tame Dependabot: Group your updates, slow the cadence, keep security fast appeared first on The GitHub Blog.

engineeringsecurityexcerpt only · body stays at the source
From the web
44

What Happens After Every Company Becomes a Data Company? (opens on the source site)

In a 2018 Forbes article, Jedidiah Yueh and Randy Bean argued that every company is now a data company. “Leveraging data — in an ethical manner — has to be at the heart of your company and product strategy,” they wrote. “Collect, sift, then monetize.” Just shy of a decade later, virtually every company (in ...

blogsecurityexcerpt only · body stays at the source
From the web
45

Enforce Access Token Expiry Policies in Pulumi Cloud (opens on the source site)

Pulumi Cloud organizations can now enforce a maximum expiry on the access tokens used against them. Organization admins can set a cap in days, and from that point on, personal, organization, and team tokens operating on resources in the org must carry an expiration within the cap for requests to succeed. Tokens that never expire, or that have too much lifetime remaining, get rejected with an error that tells the user exactly how to regain access. Why cap token lifetimes Many organizations already have a credential rotation policy that says tokens must expire, but until now, Pulumi Cloud could…

featuressecurityexcerpt only · body stays at the source
From the web
46

5 Signs That Authenticated API Traffic Is Actually Malicious (opens on the source site)

A recent report from Salt Security published a truly alarming statistic. According to the report, 95% of API attacks come from authenticated sources. This should raise alarms for anyone who knows anything about cybersecurity, as it means API attacks are seemingly real transactions. These attacks won’t even be noticed by average cybersecurity systems, as, for ...

blogsecurityexcerpt only · body stays at the source
From the web
47

How to Install and Secure Docker + Docker Compose on Ubuntu 26.04 (opens on the source site)

Docker is open-source software that can package, deploy, and distribute applications consistently across different environments, ensuring they run as intended. ... Read More The post How to Install and Secure Docker + Docker Compose on Ubuntu 26.04 appeared first on RoseHosting.

securityubuntuexcerpt only · body stays at the source
From the web
48

Security Baked Into the JVM: the Safe Codebase Audit Pipeline (opens on the source site)

In Part 1, the minimal deployment showed constraints traveling with the proxy: authentication, encryption, hardened deserialization, all declared in configuration and enforced at the call boundary. The proxy is a JAR. That JAR was downloaded and unmarshalled before any constraint ran. That step is the earlier problem. Distributed Java systems that load remote code are vulnerable to supply chain compromise: an attacker can replace a legitimate JAR with one containing malicious bytecode.

javajvmexcerpt only · body stays at the source
From the web
49

Sign in to Pulumi Cloud with Passkeys (opens on the source site)

Pulumi Cloud now supports passkeys for users who sign in with email and password. Select a button, approve with Touch ID, Face ID, Windows Hello, or your hardware key, and you’re signed in. A passkey is a public-key credential stored on your device: your phone, your laptop, a hardware key (YubiKey, Google Titan, etc.), or your password manager can all function as the authenticator. When you sign in, your device authenticates you locally and signs a challenge from Pulumi Cloud with the private key. The private key stays on your device — Pulumi Cloud never sees or stores it. Passkeys are built…

featuressecurityexcerpt only · body stays at the source
From the web
49 shown

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.