Skip to main content

99 posts tagged with "Cybersecurity"

Cybersecurity threats and defenses

View all tags

CVE-2026-42533: The 15-Year-Old Core-NGINX Heap Overflow Your Gateway API Migration Didn't Escape
·Dora Noda·10 min

CVE-2026-42533: The 15-Year-Old Core-NGINX Heap Overflow Your Gateway API Migration Didn't Escape

F5's July 2026 disclosure of CVE-2026-42533 — a CVSS 9.2 heap overflow in core NGINX's map directive — reaches Gateway Fabric, the F5 Ingress Controller, and every product embedding the NGINX engine. Here is the patch matrix, the config that makes you exploitable, and the upgrade order.

cybersecurity
self-hosting
PaaS
infrastructure
+1
The EU's 24-Hour Vulnerability Clock Is Now Law: What the Cyber Resilience Act Means for a Self-Hosted PaaS Sold Commercially
·Dora Noda·13 min

The EU's 24-Hour Vulnerability Clock Is Now Law: What the Cyber Resilience Act Means for a Self-Hosted PaaS Sold Commercially

On September 11, 2026, the CRA's 24-hour vulnerability reporting clock became law, with fines up to €15M. What manufacturer status, SBOM duties, and the five-year support window mean for a company selling an open-source self-hosted PaaS — and the five things to stand up now.

cybersecurity
regulatory compliance
self-hosting
PaaS
Falco's Prempti Is a Policy Layer for AI Coding Agents, Not Kernel Security: What It Catches and Misses
·Dora Noda·13 min

Falco's Prempti Is a Policy Layer for AI Coding Agents, Not Kernel Security: What It Catches and Misses

Falco's Prempti judges an AI coding agent's tool calls before they execute — but it never sees a syscall. A scenario-by-scenario map of what hook-level policy, eBPF monitoring, and microVM sandboxes each catch and miss on the deploy-from-chat path.

cybersecurity
AI agents
Model Context Protocol
self-hosting
15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild
·Dora Noda·11 min

15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild

In September 2025 the npm package postmark-mcp shipped fifteen clean releases, then added a one-line BCC backdoor in v1.0.16 — the first malicious MCP server caught in the wild. What the incident proves about version-history trust, plus a concrete checklist for teams installing third-party MCP servers and platforms distributing their own.

Model Context Protocol
AI agents
security
cybersecurity
Microsoft Agent 365 Goes GA and Starts Auto-Discovering the MCP Servers Nobody Registered
·Dora Noda·11 min

Microsoft Agent 365 Goes GA and Starts Auto-Discovering the MCP Servers Nobody Registered

Microsoft's Agent 365 platform went GA on May 1, 2026 with Shadow AI Discovery that surfaces unmanaged MCP servers through Defender and Intune. Here are the five governance controls it ships — and what a self-hosted PaaS must build itself, since Microsoft's discovery cannot see its fleet.

AI agents
Model Context Protocol
cybersecurity
self-hosting
The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch
·Dora Noda·9 min

The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch

Moltbook leaked 1.5 million agent API tokens within 72 hours of an all-AI-coded launch because Row Level Security was never enabled. A concrete failure-chain postmortem plus the secure-by-default provisioning contract every agent-facing platform should enforce.

AI agents
cybersecurity
engineering
PaaS
The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted
·Dora Noda·11 min

The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted

Between March and June 2026, Axios, node-ipc, Red Hat's npm namespace, and the Mastra framework were all compromised — each defeating a different defense. A concrete accounting of all four attacks and the five build-layer controls that survive them: frozen lockfiles, disabled install scripts, DNS-aware egress sandboxing, honest provenance, and per-build SBOMs.

security
cybersecurity
developer tools
self-hosting
+1
Your npm Token Is the Next Supply-Chain Incident: A Tokenless Publishing Playbook for Git-Push Pipelines
·Dora Noda·10 min

Your npm Token Is the Next Supply-Chain Incident: A Tokenless Publishing Playbook for Git-Push Pipelines

npm's OIDC trusted publishing replaces the long-lived NPM_TOKEN with per-run workload identity and automatic provenance. A six-step migration checklist with version floors and failure modes, the 2026 enforcement timeline through January 2027, and what the pattern means for a self-hosted build pipeline.

security
self-hosting
PaaS
tutorial
+1
Six Minutes, 84 Malicious Versions: What the TanStack npm Compromise Teaches Every Build Pipeline
·Dora Noda·12 min

Six Minutes, 84 Malicious Versions: What the TanStack npm Compromise Teaches Every Build Pipeline

On May 11, 2026, attackers published 84 malicious versions across 42 TanStack npm packages in six minutes without touching a maintainer credential. How the pull_request_target, cache-poisoning, and OIDC-extraction chain worked, and the build-pipeline checklist every self-hosted PaaS should verify.

cybersecurity
self-hosting
PaaS
Showing 28–36 of 99 posts