
Your Read-Only Tool Is the Sandbox Escape: What Claude Code's /proc/self/environ API-Key Leak Teaches About Agent Deploy Pipelines
Microsoft researchers hid instructions in a GitHub issue comment, steered Claude Code's Action to its unsandboxed Read tool, and walked out with a live API key. Here is the full four-step chain plus a 7-point audit for your own agent deploy pipeline.

CVE-2026-61560: How an Unauthenticated MCP Default Turned a File-Upload Tool Into Full GitLab Account Takeover
A CVSS 9.8 flaw in @zereight/mcp-gitlab chains an unauthenticated SSE transport, an unsanitized file path, and a credential in process memory into full GitLab account takeover. The exploit chain, why the default was the real bug, and a six-item hardening checklist for every MCP server you self-host.

My Server Started Mining Monero: What a 606-Point Cryptojacking Postmortem Teaches About Hardening Self-Hosted PaaS Nodes
A Hetzner box mined Monero for ten days before anyone noticed — here is the kill chain link by link, and the node-hardening checklist (key-only SSH, egress policy, resource alerts) a self-hosted PaaS should ship by default.

Rubrik Gave AI Agents the Keys to the Recovery Vault: What a Backup Vendor's Governed MCP Server Teaches Infrastructure Tool Design
Rubrik's September 2026 MCP server gives customer AI agents governed access to backup and recovery state — RBAC parity, blast-radius-gated restores, and auditable tool calls. Here is the five-rule checklist its design implies for any infrastructure MCP surface.

Your Agent's Firewall Can't Read SQL. Deno's Claw Patrol Can.
Deno's open-source Claw Patrol terminates agent TCP connections and parses HTTP, Postgres, SSH, and Kubernetes on the wire, so policy sees the query instead of just the connection. How it works, what it costs, and where it belongs on a self-hosted platform.

Daytona's Core Went Private: What a Frozen Sandbox Repo Teaches About Who Owns Your Agent Isolation Layer
Daytona froze its open-source sandbox repo in June 2026, four months after a $24M Series A. What the freeze costs teams pinned to v0.190.0, how MinIO CE ran the same playbook, and a priced look at staying, renting, or owning your agent isolation layer.

Vercel's April Breach Was a Defaults Bug, Not Just a Hack: The Case for Sensitive-by-Default Secrets
Vercel's April 2026 breach exposed every customer environment variable not explicitly marked sensitive. Why the opt-in flag was the real vulnerability, how write-only secrets already solve it in production, and a five-property checklist for secrets handling that stays safe when developers forget.

CrowdSec 1.8 Adds Bot Detection to Its Open-Source WAF: What Fingerprinting Plus Proof-of-Work Changes at a Self-Hosted Edge
CrowdSec 1.8 adds fingerprint-plus-proof-of-work bot detection to its open-source WAF and a Kubernetes datasource that lets one instance read pod logs from the API server. How the challenge scores bots, what it changes versus fail2ban and Anubis, and a six-item adoption checklist for your ingress.

GitHub's Egress Firewall Won't Cover Your Self-Hosted Runners — Here's the Blueprint That Will
GitHub's 2026 roadmap adds a root-proof egress firewall for hosted runners only. Replicate that guarantee on self-hosted ARC runners with ephemeral pods, default-deny egress, Cilium DNS allowlists, and SHA-pinned actions.