
Vercel's fingerprintTools and detectToolDrift: The First Drift-Detection Primitives for MCP Tool Execution
Vercel's AI SDK added fingerprintTools and detectToolDrift to catch MCP servers silently mutating approved tool definitions. Here is how the pinning works, the behavior-swap hole it leaves open, and what a self-hosted deploy MCP server should adopt.

Detectify Turned Its Scanner Into an Agent Tool: What 'Call the Scanner Like a Test Runner' Means for Your Deploy Pipeline
Detectify's May 2026 MCP Server hands security findings to coding agents as structured tasks with validation scans. How the Find & Fix loop works, what a scan phase between build and promote looks like for a git-push PaaS, and what stays human.

Firecracker's First Escape CVEs: What CVE-2026-5747 and CVE-2026-1386 Mean for MicroVM Sandboxes
Firecracker's zero-escape-CVE record broke twice in 2026: an out-of-bounds write in the virtio-pci transport and a symlink overwrite in the jailer. What both bugs mean for teams running AI-agent sandboxes on microVMs, and the patching checklist that keeps the isolation story intact.

15,465 MCP Servers, 0 Governance: What OX Security's Census Means for Your Deploy Tools
OX Security mapped 15,465 MCP servers and found agents reaching China, Russia, home networks, and six abandoned domains buyable for $4. The four findings with exact numbers, the Always-Allow attack chain, and a control matrix for governing deploy agents' tools.

GitLab's CVSS 10.0 File-Read Flaw: The Self-Hosted Patch Playbook for a 24-Hour Probe Window
CVE-2026-85706 lets unauthenticated attackers read any file off a self-managed GitLab server — and honeypots saw probes within 24 hours of disclosure. The four-step playbook: inventory, patch, forensic triage, and secret rotation.

Coolify's Second Critical RCE of 2026: How a Dockerfile Path Became a Shell (CVE-2026-34038)
Coolify's CVE-2026-34038 lets any user with application write access run shell commands on the host and pull secrets out through deployment logs — the sixth deploy-field injection in seven months, and a case study in single-daemon blast radius.

The EU CRA's 24-Hour Clock Is Now Running: What the First Week of Mandatory Vulnerability Reporting Demands of a Self-Hosted PaaS Vendor
Since September 11, 2026, software vendors selling into the EU must report actively exploited vulnerabilities within 24 hours through ENISA's Single Reporting Platform. Here is the three-stage clock, what the first week of coverage revealed, and the readiness checklist for a self-hosted PaaS vendor.

GitHub's September 25 Runner Deadline: What the Version Floor Actually Fixes (and the Build-Fleet Holes It Leaves Open)
GitHub starts enforcing self-hosted runner versions on September 25. Here is exactly what changes, why the last three CI supply-chain attacks would not have been stopped by a version floor, and the checklist to run before Friday.

2 Billion Installs, Valid Signatures: What the Shai-Hulud Keyv Wave Means for Anyone Who Builds Untrusted Code
The August 2026 keyv wave spread a self-propagating npm worm to 400+ packages and 2 billion installs — with valid Sigstore provenance on every poisoned release. Here is what that proves about build-pipeline trust, and the nine build-layer controls that contain the next wave.