531 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Pinterest Runs 66,000 MCP Tool Calls a Month: What Its Registry-and-Approval Blueprint Means for a Deploy-Tools MCP Server
Pinterest's production MCP fleet handles 66,000 tool calls a month behind a central registry and human approval gates. Here is the blueprint, and how it maps onto deploy, rollback, and logs tools for a self-hosted PaaS.

Railway Edge Rules vs a Gateway You Own: What Each Rule Costs to Replicate
Railway's Edge Rules put allow, block, challenge, redirect, and cache policy in a vendor console with no CLI. A rule-by-rule mapping of what each one costs to rebuild on a gateway you own — plus the migration checklist for policy that lives outside Git.

Render Now Mints Short-Lived OIDC Tokens for Anthropic and OpenAI: The Beginning of the End for LLM API Keys in Env Vars
Render's July 2026 changelog lets services authenticate to Anthropic and OpenAI with short-lived OIDC tokens instead of pasted API keys. How the federation works, the setup on each side, and the native equivalent on self-hosted Kubernetes.

Caddy Rotates Your ECH Keys Now: What It Takes to Hide Every Tenant's SNI Behind Shared IPs
Caddy 2.11.1 rotates Encrypted Client Hello keys automatically. Here is what it takes to hide every tenant's SNI behind shared IPs — the config, the DNS plumbing, and the gaps that remain.

The Agent-Sandbox Market Crystallized Into Three Architectures. Here's the Bar for Building Your Own.
E2B, Modal, and Daytona each lead a different sandbox architecture — Firecracker microVMs, gVisor, hardened containers. A workload-conditional verdict on which wins where, the four-boundary isolation bar none of them ships by default, and the honest starting point for sandboxes on owned hardware.

45-Day Certificates Are Here: What Let's Encrypt's Shrinking Validity Window Demands From Your Renewal Automation
Let's Encrypt now issues 45-day certificates, and 64-day defaults land in February 2027. Here is the full timeline, the renewal-window math, and a checklist to harden ACME automation before the manual-fix window disappears.

The MCP Roadmap's Five Priorities, Ranked by What They Cost a Self-Hosted Team
The August 2026 MCP roadmap names five priorities for the next spec release. Here is what each one means for teams running their own MCP servers, ranked by urgency, with an adoption sequence for owned infrastructure.

Obidos Went Open Source: The Self-Hosted Secrets-Sharing App Between Your Password Manager and Vault
Obidos, a commercial secrets-sharing product sold since 2024, went open source in August 2026. Here is how its sharing-first model compares to Vault and Bitwarden for a small platform team, plus the hardening checklist to close before trusting it.

pedit COW: A Packet-Editor Bug Is the Fifth Linux Kernel Escape in Ten Weeks — and It Lives in Code Your CNI Already Loads
CVE-2026-46331 (pedit COW) is the fifth independent Linux kernel escape disclosed in ten weeks — and it lives in traffic-control code your CNI loads on every node. What the five-escape window means for self-hosted Kubernetes fleets, and the patch checklist that closes it.