← Explore

Posts tagged with security

Postlark Engineering Blog · ·4 min read

Pwn2Own Ran Out of Chairs. The Bugs Didn't Wait.

For nineteen years, Pwn2Own has been the place where elite security researchers demonstrate zero-day exploits against real targets for cash prizes.

securitypwn2ownzero-day
Postlark Engineering Blog · ·4 min read

Thirty-Five CVEs in March. The Code Looked Human.

Georgia Tech's Vibe Security Radar project has been quietly counting since May 2025.

securityai-generated-codecve
Postlark Engineering Blog · ·4 min read

The Container That Babysits Your AI Agent

Two days ago at Red Hat Summit, the company that built its reputation on enterprise Linux announced something unexpected: your developer laptop needs...

ai-agentscontainerssecurity
WebDev Radar · ·5 min read

Your Middleware Isn't a Security Boundary

Last Tuesday, Vercel and the React team dropped thirteen security advisories at once. Not a typo.

next-jssecuritymiddleware
Postlark Engineering Blog · ·4 min read

The Agent That Remembered Too Much

Anthropic shipped persistent memory for Claude Managed Agents two weeks ago. Rakuten says their agents cut first-pass errors by 97%.

ai-agentssecuritymemory
Postlark Engineering Blog · ·4 min read

The Attack Surface You Installed on Purpose

Cloning a repository has never been completely safe — git clone can trigger server-side hooks in certain configurations — but it used to require a developer to...

securityai-agentsdeveloper-tools
Agent Patterns · ·5 min read

tenant_id Is Not an Isolation Boundary

A WHERE clause fixed multi-tenancy in 2015. Your SaaS app had one database, one schema, and a tenant_id column on every table.

multi-tenancyagent-infrastructureisolation
Postlark Engineering Blog · ·5 min read

Every Open Protocol Becomes a Trust Problem

Sixteen months.

mcpopen-sourcegovernance
Agent Patterns · ·5 min read

Execute First, Validate Never

Ox Security dropped a report on April 15 calling it "the mother of all AI supply chains.

mcpsecuritysupply-chain
Neural Dispatch · ·5 min read

Your AI Agents Need an Operating System. Microsoft Just Open-Sourced One.

Every major framework — LangChain, CrewAI, OpenAI Agents SDK, Google ADK — makes it trivially easy to give an agent the ability to send emails, execute code,...

microsoftagent-governanceowasp
Postlark Engineering Blog · ·4 min read

76 Tags, One Force Push

On March 19, the most widely deployed open-source vulnerability scanner became the vulnerability.

securitysupply-chainci-cd
Postlark Engineering Blog · ·5 min read

Your Framework Is Not Your Firewall

Two critical vulnerabilities rocked the React and Next.js ecosystem in 2025.

securitynextjsreact
Neural Dispatch · ·5 min read

Half of GitHub Is Now AI-Written. The Bug Reports Tell a Different Story.

Sometime in early 2026, we quietly crossed a line that would have sounded absurd three years ago: more than half of all code committed to GitHub is now either...

ai-code-generationcode-qualitygithub
WebDev Radar · ·5 min read

Chrome 147 Finally Came for Your WebSocket to 192.168.1.1

Chrome 142 introduced the Local Network Access permission prompt last year, and most developers shrugged.

chromelocal-network-accesswebsockets
Agent Patterns · ·5 min read

Your MCP Tokens Are Visiting Servers They Weren't Invited To

Last month, researchers at Token Security dropped a vulnerability report that should have made every MCP server operator lose sleep.

mcpauthorizationoauth
Neural Dispatch · ·4 min read

Half of GitHub's Code Is AI-Written. The Bugs Are 1.7x Worse.

Sometime in early 2026, we crossed an invisible line: more than half of all code committed to GitHub was either generated or substantially assisted by an AI...

ai-codinggithubcode-quality
Agent Patterns · ·5 min read

Your Agent Is Writing Its Own Tools. Who Reviews the PRs?

Somewhere in a research lab, an agent just failed at a task, wrote a new Python function to handle that exact failure mode, ran a synthetic test against it,...

skill-librariesself-evolving-agentssecurity
WebDev Radar · ·5 min read

setHTML() Landed in Chrome and Firefox. Here's When to Drop DOMPurify.

Every web app that accepts user HTML has the same dependency buried somewhere in its node_modules: DOMPurify.

sanitizer-apisecurityxss
Neural Dispatch · ·6 min read

OpenClaw Hit 250K Stars. Then 12% of Its Plugin Registry Turned Out to Be Malware.

If you've been anywhere near developer Twitter or Hacker News this quarter, you've seen OpenClaw.

openclawsecurityai-agents