Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

One in Five MCP Access Policies Is Broken or Missing: The Audit to Run Before Agents Touch Your Deploy Pipeline
·Dora Noda·12 min

One in Five MCP Access Policies Is Broken or Missing: The Audit to Run Before Agents Touch Your Deploy Pipeline

One in five MCP access policies is broken or missing, Splunk's MCP server leaked tokens in cleartext until v1.0.3, and the July 2026 spec rebuilt authorization from scratch. What it means for deploy tools exposed to agents, and the ten-check audit to run first.

Model Context Protocol
AI agents
security
self-hosting
MCP's July 2026 Authorization Hardening: How RFC 9207 Issuer Checks Protect Agents That Hold Deploy Keys
·Dora Noda·11 min

MCP's July 2026 Authorization Hardening: How RFC 9207 Issuer Checks Protect Agents That Hold Deploy Keys

The MCP 2026-07-28 specification closes the authorization-server mix-up attack with mandatory RFC 9207 issuer validation and issuer-bound credentials. Here is how the attack steals an agent's deploy credentials, and the server-side checklist for infrastructure MCP servers.

Model Context Protocol
security
AI agents
self-hosting
Renovate as a Kubernetes CRD: Patching Build Images Without a Hosted Bot Account
·Dora Noda·10 min

Renovate as a Kubernetes CRD: Patching Build Images Without a Hosted Bot Account

Mogenius's Renovate Operator runs dependency updates as a Kubernetes-native controller. Here is a worked design for patching a self-hosted PaaS's build images with it, plus the quota, credential, and blast-radius guardrails that keep automation safe.

self-hosting
Kubernetes
PaaS
security
Claude Cowork Broke Containment Twice in July: VM Root on Windows, Host Files on Mac
·Dora Noda·13 min

Claude Cowork Broke Containment Twice in July: VM Root on Windows, Host Files on Mac

In July 2026, Claude Cowork broke containment twice — a root chain on Windows and a kernel-to-host escape on Mac. This teardown walks both attack chains and maps the isolation tiers and hardening checklist your own agent sandboxes need.

AI agents
security
self-hosting
Kubernetes
Ingress-NGINX Is Retired: Your Gateway API Migration Playbook for the Rest of 2026
·Dora Noda·11 min

Ingress-NGINX Is Retired: Your Gateway API Migration Playbook for the Rest of 2026

Ingress-nginx stopped receiving security patches in March 2026. A migration playbook for self-hosted teams: the five translation traps, which annotations survive the move to Gateway API, and a TLS cutover checklist.

Kubernetes
migration
guide
self-hosting
+1
The MCPA Is Here: What a 120-Minute, 5-Domain MCP Exam Says About Production MCP Operations
·Dora Noda·8 min

The MCPA Is Here: What a 120-Minute, 5-Domain MCP Exam Says About Production MCP Operations

The Agentic AI Foundation's new MCPA exam puts half its weight on tool execution and security. A read of what that syllabus reveals about where MCP breaks in production, plus a five-domain checklist for hardening your own MCP server.

AI agents
Model Context Protocol
security
governance
MCPwn: How nginx-ui's Unauthenticated MCP Endpoint Handed Attackers Full nginx Takeover — and the Checklist That Would Have Stopped It
·Dora Noda·10 min

MCPwn: How nginx-ui's Unauthenticated MCP Endpoint Handed Attackers Full nginx Takeover — and the Checklist That Would Have Stopped It

nginx-ui shipped MCP support with one endpoint missing authentication, exposing 12 tools — including config writes with automatic reload — to anyone on the network. CVE-2026-33032 scored 9.8 and was exploited in the wild; here is how the takeover worked and a seven-item checklist for any panel adding agent access.

security
Model Context Protocol
AI agents
self-hosting
Proxly Puts ngrok on Your Own Domain — but Your Laptop Is Still the Server
·Dora Noda·10 min

Proxly Puts ngrok on Your Own Domain — but Your Laptop Is Still the Server

Proxly is a self-hosted ngrok alternative that exposes localhost on subdomains of your own domain through a VPS relay and wildcard DNS. How its WebSocket relay works, what it costs against ngrok's paid tiers, and why a tunnel still isn't a deployment.

self-hosting
developer tools
PaaS
security
Railway's Guardrails, Rebuilt in Kubernetes: Two Admission Policies That Keep Internal Services Off the Public Internet
·Dora Noda·8 min

Railway's Guardrails, Rebuilt in Kubernetes: Two Admission Policies That Keep Internal Services Off the Public Internet

Railway's April 2026 Guardrails stop non-admins from exposing internal services via public domains or TCP proxies. Here is how to enforce the same two policies on a self-hosted Kubernetes platform with ValidatingAdmissionPolicy and Kyverno.

Kubernetes
PaaS
self-hosting
security
+1
Showing 136–144 of 532 posts