Security
We track 144 posts about Security from 57 engineering blogs. Most active: Cloudflare, Docker, Snyk. Latest post: Oct 8, 2026.
Companies writing about Security
Recent posts
How one bug bounty researcher chooses the features they investigate (opens on the source site)
As we kick off Cybersecurity Awareness Month, the GitHub Bug Bounty team spotlights @vaib25vicky, exploring their methodology, techniques, and experiences hacking on GitHub. The post How one bug bounty researcher chooses the features they investigate appeared first on The GitHub Blog.
Can Agentic AI Find the Security Vulnerabilities Other Tests Miss? (opens on the source site)
Security teams are good at finding problems. The difficult part is finding the right problems across a growing codebase, a changing application and the connections between them. A scanner can flag a known pattern quickly. A skilled tester can follow a complicated line of enquiry. Neither has unlimited time, and there will always be a question nobody thought to ask. Could AI agents take on more of that investigative work? I think the answer is yes, provided we are precise about what “find” means. Agents can produce leads, test assumptions and uncover issues that established checks have missed.…
Guide to the OWASP LLM Top 10 (opens on the source site)
Large language models (LLMs) have become mainstream. Recent estimates suggest there are over 1.1 billion ChatGPT users. LLMs and AI agents have become a part of every aspect of our lives, from writing emails to coding and everything in between. Yet, this scenario is a cybersecurity incident waiting to happen. Many developers aren’t used to ...
Building an evidence-grounded agentic security operations harness on Cloudflare (opens on the source site)
Cloudflare Managed Defense uses a team of specialized AI agents built on Workers and global network telemetry to analyze security alerts. By separating deterministic evidence collection from model inference, the system delivers grounded recommendations to Managed Defense Analysts.
Twenty-two pending curl vulnerabilities (opens on the source site)
On October 14 2026 we will ship curl 8.23.0. The next iteration in the never-ending series of version bumps from the curl project. We always think of the next release as the best version we ever did – and this time is no exception. Decades of collected experiences and meticulous polishing has lead us to … Continue reading Twenty-two pending curl vulnerabilities →
Rossoctl for agent discoverability, security, and observability on Kubernetes (opens on the source site)
Red Hat ·
Imagine deploying a pair of agents to Red Hat OpenShift and watching them thrive. But fast-forward 6 months and you find your environment cluttered with 40 of them, their purposes largely unknown. Redundant agents emerge across namespaces, duplicating work. Meanwhile, a security review uncovers agents utilizing static API keys over insecure HTTP. When an agent falters, the lack of tracing makes it impossible to distinguish between model hallucinations, tool errors, or downstream failures. The post Rossoctl for agent discoverability, security, and observability on Kubernetes appeared first on…
Elastic Security and OpenAI GPT Cyber models: What frontier cyber defense means for the public sector (opens on the source site)
Elastic ·
Elastic responded to OpenAI’s call for stronger, faster cyber defense against AI-enabled threats by joining the OpenAI Daybreak Defense Network and announcing plans to integrate OpenAI GPT Cyber models directly into Elastic Security.
Security Baked Into the JVM: no single party controls the outcome (opens on the source site)
A URL is a name, and names get reused. Replace the bytes behind https://repo.example.org/order-processor.jar and every permission granted to that URL still applies, now to code nobody audited. So far in this series, Part 1 declared constraints on a remote call, Part 2 vetted code before a client loaded it, Part 3 established who is calling, and Part 4 carried that chain of identities across the wire.
Follow the thread: a new dashboard to investigate account abuse (opens on the source site)
Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed User IDs to help teams investigate and block account abuse.
Trust Docker for the agents you don’t (opens on the source site)
Docker ·
At WeAreDevelopers, Docker introduced Cloud Sandboxes, the open Sandbox Kit specification, and a commitment to bring Kits to the CNCF for neutral governance.
One year later: Sovereign AI and the fight for choice (opens on the source site)
AI sovereignty is not a zero-sum game, but many governments now believe it is. Cloudflare's answer: more local open-source models, model-agnostic security tools, and a commitment to giving nations genuine choice.
Is sandboxing sufficient to contain rogue agents? (opens on the source site)
Quick caveats: this is a post on AI safety, written by a cryptography professor. If that troubles you, you should read something else. I try hard not to work on AI (except when the topic occasionally tosses itself in my path), so in this post I’m mostly trying to referee arguments made by others. If … Continue reading Is sandboxing sufficient to contain rogue agents? →
Laravel AI SDK and Laravel MCP Security Fixes: Update Now (opens on the source site)
Laravel ·
Security advisories for the Laravel AI SDK and Laravel MCP fix an SSRF bug and an OAuth redirect issue. Here are the affected versions and how to update. The post Laravel AI SDK and Laravel MCP Security Fixes: Update Now appeared first on Laravel News. Join the Laravel Newsletter to get Laravel articles like this directly in your inbox.
Enforce positive security with Cloudflare Application Profiles (opens on the source site)
Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate and vary payloads.
Building a post-quantum certificate authority with Merkle Tree Certificates (opens on the source site)
As post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs, Merkle Tree Certificates offer a path to compact, auditable authentication. Cloudflare’s new certificate authority will support MTC issuance at scale.
Building a certificate authority for the whole Internet (opens on the source site)
Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web.
Adaptive application security for the AI era: how Cloudflare connects code, traffic, and intelligence to stop attacks (opens on the source site)
Cloudflare introduces an adaptive security framework connecting risk discovery, agent governance, runtime protection, and AI-powered response in a continuous learning loop.
How we found 24 Android vulnerabilities using our open source AI security agent (opens on the source site)
A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app. The post How we found 24 Android vulnerabilities using our open source AI security agent appeared first on The GitHub Blog.
Trading a Cloud Identity for Your Own: Workload Attestation on Managed Compute (opens on the source site)
Netflix ·
By Dhruv PratapIntroductionOrganizations that have been around for a while usually run two identity systems side by side. One belongs to the cloud provider: IAM roles, instance profiles, execution roles. The other is your own, and it is the one your internal services actually check when they decide whether to answer a request.On infrastructure you build yourself, you can bootstrap your own identity however you like. On managed compute you cannot. The provider hands your process a cloud identity and nothing else.This post describes how we close that gap for Apache Spark workloads running on…
Agents can now set up your website’s security with Turnstile Spin (opens on the source site)
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.
AI-powered fuzzing with the GitHub Security Lab Taskflow Agent (opens on the source site)
In this blog post, I explain how to use the new fuzzing taskflow based on the GitHub Security Lab Taskflow Agent AI framework. The post AI-powered fuzzing with the GitHub Security Lab Taskflow Agent appeared first on The GitHub Blog.
Microsoft is updating its author-signing certificate starting September 23, 2026 (opens on the source site)
.NET ·
Starting September 23, 2026, Microsoft is updating the author-signing certificate used for NuGet packages. Customers using trusted signer policies or certificate fingerprint verification should add the new certificate as soon as possible. The post Microsoft is updating its author-signing certificate starting September 23, 2026 appeared first on .NET Blog.
AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack (opens on the source site)
Nvidia ·
AI security is an engineering problem. That means defined security requirements, enforceable controls, named owners and evidence that protections work. As AI becomes more capable, the industry must accelerate security engineering, broaden access to defensive tools and share what works faster. Technology Changes, Security Fundamentals Endure The internet and cloud computing changed how software operates, […]
AI Agent Security in the Enterprise: Interview With Isabelle Mauny (opens on the source site)
AI agents are quickly rising in the enterprise. They’re granting more powers to knowledge workers across sales, finance, engineering, marketing, and other disciplines in the process. Yet, as most quick technological adoptions go, security is often falling by the wayside or being implemented after the fact. Ahead of Nordic APIs Summit 2026, we’re connecting with ...
September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack (opens on the source site)
On September 16, 2026, we faced a zero-day attack targeting one of our servers in Brazil. Our security team detected an attack exploiting a previously undetected vulnerability … The post September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack appeared first on Hostinger Blog.
When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts (opens on the source site)
A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side attacks for analyst investigation.
Give every teammate and agent the right level of access to your Workers (opens on the source site)
You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.
AI cybersecurity is a cat and mouse game (opens on the source site)
Ryan chats with Sam Curry, CSO at Zscaler, about where human intelligence sits in the new security landscape with AI, why shifting security protections closer to applications helps limit probes for vulnerabilities, and why building more resilient code infrastructure is the best way to address the vulnerabilities AI does discover.
Set Up Cloud OIDC From the Pulumi CLI (opens on the source site)
Pulumi ·
Pulumi ESC can act as an OpenID Connect (OIDC) provider for AWS, Azure, and Google Cloud, issuing short-lived, signed tokens that these clouds exchange for temporary credentials. This eliminates hard-coded credentials and improves your security posture. Last year, we introduced an onboarding flow in the Pulumi Cloud console that makes it super easy to configure OIDC for your cloud provider in a few guided steps. We’re bringing Pulumi Cloud into the CLI so agents can use its capabilities directly from the terminal, without requiring a human to complete steps in the console. The new pulumi env…
Reference architecture for HA scanning with Red Hat Advanced Cluster Security for Kubernetes (opens on the source site)
Red Hat ·
Red Hat Advanced Cluster Security for Kubernetes provides an image scanning API through its Central component that CI/CD pipelines depend on for vulnerability assessment. Red Hat Advanced Cluster Security upgrades and restarts introduce downtime windows that can block critical build paths. This post describes a reference architecture that eliminates scan API downtime by running two Central service instances with a client-side failover mechanism. The post Reference architecture for HA scanning with Red Hat Advanced Cluster Security for Kubernetes appeared first on Red Hat Developer.
Related topics
This page is generated automatically from the engineering blogs we follow. Every post links to its source, where it was published. See all sources.