Generate an SBOM with Syft, Filter Grype with VEX
Generate a CycloneDX SBOM with Syft, scan it with Grype, and suppress non-exploitable CVEs with VEX not_affected statements in your CI gate.
Read moreHonest notes on infrastructure, security, and running technical teams, documenting the shift from human-scale systems to autonomous technical architectures.
Generate a CycloneDX SBOM with Syft, scan it with Grype, and suppress non-exploitable CVEs with VEX not_affected statements in your CI gate.
Read moreOnly 8.5% of MCP servers use OAuth. Audit audience validation and add the resource parameter before the July 28 OAuth 2.1 spec rewrite lands.
Read moreTrivy vs Grype in 2026: Trivy scans everything, Grype matches CVEs from an SBOM. Pick by the job, and pin your scanner after Q1's supply-chain hit.
Read moreWire GitHub Actions OIDC to AWS correctly: scope the sub claim, handle the July 15 immutable-claim change, and avoid the trust policy traps tutorials skip.
Read moreRun a default-deny egress NetworkPolicy to stop a compromised pod from phoning home. Two manifests, one DNS gotcha that breaks it, and the CNI fix.
Read moreFalco detects, Tetragon enforces in the kernel, Tracee does forensics. Picking one as a drop-in for another is the costly mistake. How to choose.
Read moreDeep dives into infrastructure, security, and technical leadership. No noise, just engineering rigor. Subscribe and grab the 2026 AI-agent & infrastructure security checklist.
Cosign v3 flips three flags on by default and breaks Harbor detection. Here are the fallback flags that keep CI signing and verification working.
Read moreio_uring skips system calls for speed, and that same trick lets a rootkit run while Falco, Tetragon, and Defender see nothing. Here is how to close the gap.
Read moreBattle-tested agentic SOC tips: gate autonomy on 90% shadow-mode concordance, split verdict from action, and treat every log line as attacker-authored.
Read moreA signed A2A agent card still lets attackers inject instructions into the description field your orchestrator feeds directly to the LLM router.
Read moreFind, patch, and block the CVSS 9.9 Fission container escape (CVE-2026-50566) on Kubernetes with version 1.24.0, Pod Security Standards, and a Kyverno rule.
Read moreOne crafted URL drained Comet's Gmail and ChatGPT Atlas blocked just 5.8% of phishing. Agentic browsers run with all your logged-in sessions, and that is the bug.
Read moreHybrid post-quantum TLS (X25519MLKEM768) is negotiating by default right now, and the operator problem is a 1,400-byte ClientHello that fragments and breaks SNI routing.
Read moreOSS-Fuzz-Gen, Buttercup, and Atheris run on a laptop with one LLM key. Ten practical commands to fuzz your own repo before attackers do.
Read moreAn unpatched WinRE exploit, GreatXML, bypasses BitLocker on any Windows 11 machine that ran a Defender offline scan. The fix is TPM+PIN, not a patch.
Read moreA remote code execution flaw sits in Anthropic's official MCP SDKs across 150M downloads. It's stdio command execution by design, and Anthropic calls it expected.
Read moreThe default Isaac GR00T N1.7 inference server binds to 0.0.0.0:5555 with no auth. Here is how to lock it to loopback behind mutual TLS.
Read moreMicrosoft's June 2026 Patch Tuesday fixed a record 206 CVEs and 3 zero-days. The real shift is AI-found bugs outrunning the human patch cycle.
Read moreThe fix for AI agent identity is two layers: SPIFFE proves what the agent is, OAuth token exchange proves what it may do right now and for whom.
Read moreRun npm approve-scripts --allow-scripts-pending to list every pending package, then approve each one. npm 12 turns this warning into a hard install failure in July 2026.
Read moreShadow AI now factors into 1 in 5 breaches and adds $670K in cost. Why banning tools backfires, and how to actually find ungoverned GenAI in 2026.
Read moreBattle-tested OWASP API Security Top 10 tips for 2026: hunt shadow and zombie APIs at runtime, test BOLA in CI, and close the gaps that breached Optus.
Read moreThe EU AI Act's high-risk obligations become enforceable on August 2, 2026, a deferral isn't law yet, and ISO 42001 won't cover you. Here's the engineering work.
Read moreBuild a Tetragon TracingPolicy that kills a process at the kernel before it reads a secret, plus the CONFIG_BPF_KPROBE_OVERRIDE gotcha that breaks it.
Read moreWhy LLM agent guardrails fail under adaptive attack, and the architectural patterns that actually contain prompt injection in 2026.
Read moreA hands-on 2026 guide to migrating off the retiring Ingress-NGINX to the Gateway API with ingress2gateway 1.0 and Envoy Gateway, including the annotations that silently drop.
Read moreKernel 6.3 (not 5.12), containerd 2.0+, and /etc/subuid setup for Kubernetes 1.36 user namespaces. Covers the silent failures that cost you an afternoon.
Read moreAI agent sandboxes isolate untrusted AI-generated code with Firecracker microVMs and gVisor. Here's how to pick an execution runtime in 2026.
Read moreA practical 2026 guide to securing MCP servers: inspect tool descriptions, scan for poisoning, pin versions against rug pulls, and add a runtime guardrail.
Read moreHow to discover, scope, and govern service accounts, API keys, tokens, and AI agents before machine credentials become your breach path.
Read moreDependency cooldowns delay installing brand-new package versions a few days, blocking most npm and RubyGems supply chain attacks before malware lands.
Read moreNo articles match your search. Try a different term or topic.