Skip to main content

99 posts tagged with "Cybersecurity"

Cybersecurity threats and defenses

View all tags

Your Registry Is a Trust Root: What the JFrog Artifactory Breach Campaign Teaches Self-Hosters
·Dora Noda·10 min

Your Registry Is a Trust Root: What the JFrog Artifactory Breach Campaign Teaches Self-Hosters

Attackers chained three Artifactory flaws into full admin takeover of self-hosted registries — then planted backdoors that survive patching. The timeline, the kill chain, and a 7-item hardening checklist for your own OCI store.

cybersecurity
self-hosting
infrastructure
guide
Your Build Server Was Owned for 24 Days. Patching It Doesn't Tell You What Shipped Clean.
·Dora Noda·12 min

Your Build Server Was Owned for 24 Days. Patching It Doesn't Tell You What Shipped Clean.

Attackers held admin access to self-hosted JFrog Artifactory servers for 24 days in August-September 2026, planting Rust backdoors with remote C2. A triage table for which window artifacts are suspect, the rebuild-and-compare procedure that re-verifies them, and the SLSA signing checklist that makes the next incident answerable.

cybersecurity
self-hosting
engineering
guide
CIS Shipped the First MCP Server Benchmark: A 10-Domain Hardening Checklist Before Agents Get Production Credentials
·Dora Noda·11 min

CIS Shipped the First MCP Server Benchmark: A 10-Domain Hardening Checklist Before Agents Get Production Credentials

The CIS MCP Server Benchmark v1.0.0 packs 55 recommendations into 10 security domains — here is each domain mapped to a concrete pass/fail check for a self-hosted PaaS deploy/operate surface, plus the four gaps to close before agent credentials touch production.

Model Context Protocol
AI agents
cybersecurity
self-hosting
+1
The npm Worm With Valid Provenance: What ChainDrop's 400 Poisoned Packages Mean for Anyone Building Tenant Images
·Dora Noda·11 min

The npm Worm With Valid Provenance: What ChainDrop's 400 Poisoned Packages Mean for Anyone Building Tenant Images

ChainDrop poisoned 400+ npm packages with valid SLSA provenance after the keyv maintainer's GitHub account was compromised. Here is what provenance-only trust breaks and the five build-pipeline controls every tenant-image builder needs.

cybersecurity
PaaS
self-hosting
16 Claude Code CVEs and Counting: Why Container Sandbox Escape Is a Vulnerability Class, Not a Bug
·Dora Noda·8 min

16 Claude Code CVEs and Counting: Why Container Sandbox Escape Is a Vulnerability Class, Not a Bug

Sixteen CVEs against one coding agent prove container sandbox escape is a permanent vulnerability class, not a patchable bug. Here is the CVE record, the isolation ladder with real latency numbers, and why agent-generated code belongs behind its own kernel.

cybersecurity
AI agents
Claude
self-hosting
+1
CrowdSec vs fail2ban on the Nodes You Own: Who Guards a Self-Hosted PaaS's SSH and HTTP Edge
·Dora Noda·8 min

CrowdSec vs fail2ban on the Nodes You Own: Who Guards a Self-Hosted PaaS's SSH and HTTP Edge

fail2ban guards one box well but never shares what it learns. This comparison shows where fail2ban still wins, where CrowdSec's crowd-sourced blocklists and fleet-wide bouncers take over, and how to place each one on a self-hosted fleet.

cybersecurity
self-hosting
Kubernetes
infrastructure
Your Deploy Agent Can Be Talked Into Anything: Deterministic Policy for MCP Tools That Ship Production
·Dora Noda·12 min

Your Deploy Agent Can Be Talked Into Anything: Deterministic Policy for MCP Tools That Ship Production

Sente Labs' extensible-mcp proxy puts deterministic policy between the LLM and its MCP servers — on-demand tool discovery, Rego-enforced calls, and signed approvals on the roadmap. What that buys any MCP surface whose tools can deploy and roll back production.

Model Context Protocol
AI agents
cybersecurity
self-hosting
Your Deploy MCP Server Is Production Infrastructure: Scoring Golf's Built-In Auth, Tracing, and Telemetry
·Dora Noda·12 min

Your Deploy MCP Server Is Production Infrastructure: Scoring Golf's Built-In Auth, Tracing, and Telemetry

Golf promises MCP servers with auth, observability, and telemetry included instead of bolted on. A row-by-row check of that claim for a deploy/scale/rollback toolset — what the framework covers, what needs its Gateway, and why the tagline's debugger gets an asterisk.

Model Context Protocol
cybersecurity
self-hosting
AI agents
Rubrik Just Gave Enterprise Agents a Governed MCP Path Into Its Security Cloud: Steal the Governed-Tool Pattern for Your Infra MCP Server
·Dora Noda·11 min

Rubrik Just Gave Enterprise Agents a Governed MCP Path Into Its Security Cloud: Steal the Governed-Tool Pattern for Your Infra MCP Server

Rubrik's September 2026 MCP launch gave enterprise agents a governed path into backup and recovery workflows — narrow tools, per-call scoped tokens, and server-side policy instead of ambient API authority. What the governed-tool pattern means for a deploy/rollback/log MCP server, and the six controls to ship on day one.

Model Context Protocol
AI agents
cybersecurity
self-hosting
Showing 1–9 of 99 posts