Browsing Tag
security
335 posts
AI wave
SOP – User Hardening Automation 1. Objective To automate Aerospike user hardening by removing unwanted users from the…
mcp-tool-sanitizer v0.1.0: Making the MCP approval-view match the bytes the model gets
mcp-tool-sanitizer v0.1.0: Making the MCP approval-view match the bytes the model gets A sanitizer that strips Unicode concealment…
I Tried to Prompt-Inject My Own Agent Engine. It Didn’t Work. Here’s Why.
This is article 5 in a series about building PlannerCritic, an open-source engine where one LLM writes a…
Grok Decrypted an Attacker’s Payload Mid-Execution, Then Exfiltrated Your Chat History
A webpage that just sits there, encrypted blob and all, waiting for an LLM agent to walk in…
¿Qué es la criptografía post-cuántica y por qué deberías migrar ya?
La criptografía que protege hoy tus datos —claves, HTTPS, firmas— se apoya en problemas matemáticos que los ordenadores…
Prompt injection: your customer-facing AI is an attack surface
Here is a fun little exercise. Imagine you hired a brilliant, tireless, endlessly polite support rep. They memorized…
CrossSessionMemoryGuard: vigilando la exfiltración de memoria cross-session en agentes multi-tenant
CrossSessionMemoryGuard: vigilando la exfiltración de memoria cross-session en agentes multi-tenant TL;DR Los agentes con memoria persistente compartida entre…
I re-scanned the launches I flagged last week — here’s who actually shipped the fixes
For the past two weeks I’ve been running passive, read-only security scans on products that launch here on…
Environment Variables the Safe Way
Why Environment Variables Matter Every app has secrets: API keys, database URLs, admin passwords. Hardcoding them in source…
Designing a Privacy-Safe Gift Card Image Submission Pipeline
A gift card image is not an ordinary profile photo. It can contain a redeemable code, a PIN,…