Skip to main content

99 posts tagged with "Cybersecurity"

Cybersecurity threats and defenses

View all tags

Four Root Exploits in Ten Weeks: What GhostLock Says About Kernel Patching for a Self-Hosted PaaS
·Dora Noda·9 min

Four Root Exploits in Ten Weeks: What GhostLock Says About Kernel Patching for a Self-Hosted PaaS

GhostLock lets any logged-in user become root in five seconds — and it's the fourth independently discovered kernel or hypervisor escape disclosed in ten weeks. Here's the patch-cadence argument for treating kernel CVEs as a same-day operational primitive on a self-hosted fleet.

self-hosting
PaaS
security
infrastructure
+1
Coolify Fixed 11 Critical CVEs in January. The Same Root Cause Struck Again in July
·Dora Noda·9 min

Coolify Fixed 11 Critical CVEs in January. The Same Root Cause Struck Again in July

Coolify patched 11 critical CVEs at CVSS 9.4-10.0 in January 2026, then shipped a fix for the same root-cause bug class in July. Here's what the repeat says about single-daemon PaaS architecture versus RBAC-scoped, Kubernetes-native control planes.

security
PaaS
self-hosting
infrastructure
+1
10,000 MCP Servers and Counting: Why Deploy-From-Chat's Real Bottleneck Is Discovery, Not Capability
·Dora Noda·9 min

10,000 MCP Servers and Counting: Why Deploy-From-Chat's Real Bottleneck Is Discovery, Not Capability

The official MCP Registry now lists nearly 10,000 servers and MCP SDKs hit 97 million monthly downloads. Here's why that scale makes discovery and trust the real bottleneck for a deploy-from-chat MCP server — and what actually closes the gap.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Microsoft's Poisoned MCP Tool Descriptions: When an Approved Tool's Metadata Silently Changes to Leak Data, Not Its Code
·Dora Noda·11 min

Microsoft's Poisoned MCP Tool Descriptions: When an Approved Tool's Metadata Silently Changes to Leak Data, Not Its Code

Microsoft's June 2026 guidance shows an MCP tool's approved name and summary can stay frozen while its description silently changes to smuggle a hidden instruction. Here's the attack, three real precedents, and the checklist a deploy-from-chat MCP server needs to catch it.

Model Context Protocol
AI agents
cybersecurity
self-hosting
+1
ingress-nginx's EOL Didn't Stop CVE-2026-3288: What Patching a Dead Project Means for Your Routing Layer
·Dora Noda·10 min

ingress-nginx's EOL Didn't Stop CVE-2026-3288: What Patching a Dead Project Means for Your Routing Layer

ingress-nginx's official end of life didn't stop three RCE patches from landing in its final weeks and months after — here's the sourced timeline, a fleet-wide audit you can run today, and why the blast radius is worse on a self-hosted PaaS.

cybersecurity
self-hosting
PaaS
infrastructure
JADEPUFFER Ran a Full Ransomware Kill Chain With No Human Involved — What That Means for Agents That Deploy Your App
·Dora Noda·9 min

JADEPUFFER Ran a Full Ransomware Kill Chain With No Human Involved — What That Means for Agents That Deploy Your App

An AI agent ran an entire ransomware attack end to end with no human directing a single step. Here's what that kill chain means for any platform whose own agent can deploy or restart your infrastructure.

cybersecurity
AI agents
Model Context Protocol
self-hosting
+1
60% of MCP Servers Have Security Issues: The Checklist Before You Expose Deploy/Rollback to an Agent
·Dora Noda·10 min

60% of MCP Servers Have Security Issues: The Checklist Before You Expose Deploy/Rollback to an Agent

A July 2026 census scanned 9,695 MCP servers and found 5,832 with security issues. Here's the breakdown and the concrete checklist a deploy-from-chat PaaS needs to clear before letting an agent touch production.

Model Context Protocol
cybersecurity
AI agents
self-hosting
+1
Semantic Kernel's Prompt-Injection RCE: The Agent-Tool Audit Every Deploy/Rollback MCP Server Needs
·Dora Noda·9 min

Semantic Kernel's Prompt-Injection RCE: The Agent-Tool Audit Every Deploy/Rollback MCP Server Needs

Two Semantic Kernel CVEs turned a single prompt into remote code execution — a four-point audit shows what the same failure pattern means for any MCP server exposing deploy and rollback as agent tools.

Model Context Protocol
AI agents
cybersecurity
self-hosting
+1
Agentjacking: How a Fake Sentry Error Hijacked AI Coding Agents 85% of the Time
·Dora Noda·11 min

Agentjacking: How a Fake Sentry Error Hijacked AI Coding Agents 85% of the Time

Researchers hijacked Claude Code, Cursor, and Codex 85% of the time using nothing but a public Sentry DSN — here's how it works, and what a deploy-capable agent's MCP tools need to do differently.

Model Context Protocol
AI agents
cybersecurity
self-hosting
+1
Showing 55–63 of 99 posts