Skip to content
Category

Security

Security from a builder's seat. Vulnerability disclosures, supply-chain attacks, secrets management, and defensive engineering patterns — explained with enough depth to act on, not just react to.

AI Didn't Kill JS Obfuscation, It Repriced It
Article 3d ago 3

AI Didn't Kill JS Obfuscation, It Repriced It

LLMs erased renaming and shred obfuscator.io defaults, but runtime-dependent and polymorphic protection still costs attackers real money.

Ji-ho Choi
The OIDC Double-Edge: Inside the Injective SDK Backdoor

The OIDC Double-Edge: Inside the Injective SDK Backdoor

Article · 1mo ago0
Why AI Editors Keep Generating Prototype Pollution Vulnerabilities

Why AI Editors Keep Generating Prototype Pollution Vulnerabilities

Article · 1mo ago0
Why You Need a Vulnerability Harness, Not a Security Agent

Why You Need a Vulnerability Harness, Not a Security Agent

Article · 1mo ago0
How Serverless SQL Injection Becomes Cloud Privilege Escalation

How Serverless SQL Injection Becomes Cloud Privilege Escalation

Article · 1mo ago0
Stop Using Self-Signed Certificates for Internal Services

Stop Using Self-Signed Certificates for Internal Services

Article · 1mo ago0
OpenBSD kernel race gives local users a root shell

OpenBSD kernel race gives local users a root shell

News · 1mo ago2
GitLost Proves Agentic Workflows Have No Trust Boundary

GitLost Proves Agentic Workflows Have No Trust Boundary

News · 1mo ago1
The Tenda Firmware Backdoor and the Cost of Silent Vendors

The Tenda Firmware Backdoor and the Cost of Silent Vendors

Article · 1mo ago0
Why a "Verified" GitHub Commit Hash Is Not Unique

Why a "Verified" GitHub Commit Hash Is Not Unique

Article · 1mo ago0
Securing GitHub Agentic Workflows Against the GitLost Exploit

Securing GitHub Agentic Workflows Against the GitLost Exploit

Article · 1mo ago0
A 19-Year-Old Linux Kernel Zero-Day Discovered via kernelCTF

A 19-Year-Old Linux Kernel Zero-Day Discovered via kernelCTF

Article · 1mo ago0
Hardening the Pipe: Why OpenSSH 10.4 is a Mandatory Upgrade

Hardening the Pipe: Why OpenSSH 10.4 is a Mandatory Upgrade

Release · 1mo ago0
Januscape: The 16-Year-Old KVM Flaw Breaking x86 Isolation

Januscape: The 16-Year-Old KVM Flaw Breaking x86 Isolation

Article · 1mo ago0
When Your Agent Starts Building Someone Else's Minecraft Temple

When Your Agent Starts Building Someone Else's Minecraft Temple

Article · 1mo ago1
Why Your Security Fails: The Case for Informal Threat Models

Why Your Security Fails: The Case for Informal Threat Models

Article · 1mo ago1