Skip to main content

99 posts tagged with "Cybersecurity"

Cybersecurity threats and defenses

View all tags

Vercel's fingerprintTools and detectToolDrift: The First Drift-Detection Primitives for MCP Tool Execution
·Dora Noda·9 min

Vercel's fingerprintTools and detectToolDrift: The First Drift-Detection Primitives for MCP Tool Execution

Vercel's AI SDK added fingerprintTools and detectToolDrift to catch MCP servers silently mutating approved tool definitions. Here is how the pinning works, the behavior-swap hole it leaves open, and what a self-hosted deploy MCP server should adopt.

Model Context Protocol
cybersecurity
self-hosting
AI agents
Detectify Turned Its Scanner Into an Agent Tool: What 'Call the Scanner Like a Test Runner' Means for Your Deploy Pipeline
·Dora Noda·10 min

Detectify Turned Its Scanner Into an Agent Tool: What 'Call the Scanner Like a Test Runner' Means for Your Deploy Pipeline

Detectify's May 2026 MCP Server hands security findings to coding agents as structured tasks with validation scans. How the Find & Fix loop works, what a scan phase between build and promote looks like for a git-push PaaS, and what stays human.

Model Context Protocol
AI agents
security
self-hosting
+1
Firecracker's First Escape CVEs: What CVE-2026-5747 and CVE-2026-1386 Mean for MicroVM Sandboxes
·Dora Noda·11 min

Firecracker's First Escape CVEs: What CVE-2026-5747 and CVE-2026-1386 Mean for MicroVM Sandboxes

Firecracker's zero-escape-CVE record broke twice in 2026: an out-of-bounds write in the virtio-pci transport and a symlink overwrite in the jailer. What both bugs mean for teams running AI-agent sandboxes on microVMs, and the patching checklist that keeps the isolation story intact.

cybersecurity
AI agents
self-hosting
engineering
15,465 MCP Servers, 0 Governance: What OX Security's Census Means for Your Deploy Tools
·Dora Noda·8 min

15,465 MCP Servers, 0 Governance: What OX Security's Census Means for Your Deploy Tools

OX Security mapped 15,465 MCP servers and found agents reaching China, Russia, home networks, and six abandoned domains buyable for $4. The four findings with exact numbers, the Always-Allow attack chain, and a control matrix for governing deploy agents' tools.

Model Context Protocol
AI agents
security
self-hosting
+1
GitLab's CVSS 10.0 File-Read Flaw: The Self-Hosted Patch Playbook for a 24-Hour Probe Window
·Dora Noda·9 min

GitLab's CVSS 10.0 File-Read Flaw: The Self-Hosted Patch Playbook for a 24-Hour Probe Window

CVE-2026-85706 lets unauthenticated attackers read any file off a self-managed GitLab server — and honeypots saw probes within 24 hours of disclosure. The four-step playbook: inventory, patch, forensic triage, and secret rotation.

security
self-hosting
cybersecurity
compliance
Coolify's Second Critical RCE of 2026: How a Dockerfile Path Became a Shell (CVE-2026-34038)
·Dora Noda·11 min

Coolify's Second Critical RCE of 2026: How a Dockerfile Path Became a Shell (CVE-2026-34038)

Coolify's CVE-2026-34038 lets any user with application write access run shell commands on the host and pull secrets out through deployment logs — the sixth deploy-field injection in seven months, and a case study in single-daemon blast radius.

cybersecurity
self-hosting
PaaS
infrastructure
The EU CRA's 24-Hour Clock Is Now Running: What the First Week of Mandatory Vulnerability Reporting Demands of a Self-Hosted PaaS Vendor
·Dora Noda·11 min

The EU CRA's 24-Hour Clock Is Now Running: What the First Week of Mandatory Vulnerability Reporting Demands of a Self-Hosted PaaS Vendor

Since September 11, 2026, software vendors selling into the EU must report actively exploited vulnerabilities within 24 hours through ENISA's Single Reporting Platform. Here is the three-stage clock, what the first week of coverage revealed, and the readiness checklist for a self-hosted PaaS vendor.

cybersecurity
compliance
regulation
self-hosting
GitHub's September 25 Runner Deadline: What the Version Floor Actually Fixes (and the Build-Fleet Holes It Leaves Open)
·Dora Noda·10 min

GitHub's September 25 Runner Deadline: What the Version Floor Actually Fixes (and the Build-Fleet Holes It Leaves Open)

GitHub starts enforcing self-hosted runner versions on September 25. Here is exactly what changes, why the last three CI supply-chain attacks would not have been stopped by a version floor, and the checklist to run before Friday.

cybersecurity
self-hosting
developer tools
PaaS
2 Billion Installs, Valid Signatures: What the Shai-Hulud Keyv Wave Means for Anyone Who Builds Untrusted Code
·Dora Noda·13 min

2 Billion Installs, Valid Signatures: What the Shai-Hulud Keyv Wave Means for Anyone Who Builds Untrusted Code

The August 2026 keyv wave spread a self-propagating npm worm to 400+ packages and 2 billion installs — with valid Sigstore provenance on every poisoned release. Here is what that proves about build-pipeline trust, and the nine build-layer controls that contain the next wave.

cybersecurity
PaaS
self-hosting
infrastructure
Showing 10–18 of 99 posts