532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Your Changelog Tool Got an MCP Server Before Your PaaS Did: What ReleasePad's Agent-Operated Publishing Means for Deploy APIs
ReleasePad's September 2026 MCP server lets coding agents publish changelogs from a conversation, while most PaaS vendors still ship no agent interface. Why Railway's OAuth-based MCP server is the reference design, and the five-item governance checklist every deploy API needs before agents touch production.

Your Ingress Is Now Your MCP Bouncer: What Traefik Hub's MCP Gateway Actually Enforces
Traefik Hub's MCP Gateway turns the ingress controller many self-hosted shops already run into the policy point for agent tool calls — OAuth discovery, JWT identity, task-based authorization, and session affinity in one middleware. A concrete breakdown of the five enforcement mechanics, a worked authorization example, and what gateway-mediated MCP means for standalone servers.

Vercel's April Breach Was a Defaults Bug, Not Just a Hack: The Case for Sensitive-by-Default Secrets
Vercel's April 2026 breach exposed every customer environment variable not explicitly marked sensitive. Why the opt-in flag was the real vulnerability, how write-only secrets already solve it in production, and a five-property checklist for secrets handling that stays safe when developers forget.

Your Agent Knows Your API Keys: Credential Brokering With Infisical's Agent Vault
AI agents that can read API keys can be prompt-injected into repeating them. Infisical's open-source Agent Vault brokers credentials at an egress proxy so secrets never enter the context window — here is the mechanism, the alternatives, and the build checklist.

Authorizer Puts Agents on the Org Chart: A2A Token Exchange, OAuth-2.1 MCP, and Secretless Kubernetes Identity
Authorizer 2.4 gives AI agents first-class identities: RFC 8693 delegation with nested actor chains, an MCP server behind OAuth 2.1 with audience-bound tokens, and secretless Kubernetes workload auth — a credential model where agents hold scoped delegations instead of god-keys.

Your AI Agent Can Now Restart Prod Postgres From Chat: What the Coolify–AnythingLLM MCP Bridge Costs in Audit and Rollback
An open-source MCP server lets an AI agent deploy, restart, and roll back Coolify apps from an AnythingLLM chat window. A threat-model teardown of what agent-driven deploys cost in scope, attribution, and reversibility — and the five-item checklist any agent-facing deploy server must pass.

CrowdSec 1.8 Adds Bot Detection to Its Open-Source WAF: What Fingerprinting Plus Proof-of-Work Changes at a Self-Hosted Edge
CrowdSec 1.8 adds fingerprint-plus-proof-of-work bot detection to its open-source WAF and a Kubernetes datasource that lets one instance read pod logs from the API server. How the challenge scores bots, what it changes versus fail2ban and Anubis, and a six-item adoption checklist for your ingress.

DMCA Takedowns Land on the Platform, Not the Tenant: The Notice-and-Takedown Runbook a Self-Hosted PaaS Needs Before the First Complaint
The moment tenants serve content from your domains, abuse notices land on your desk — and safe-harbor protection depends on machinery built before the first one. A concrete DMCA and DSA runbook for self-hosted PaaS operators: designated agent, repeat-infringer policy, per-tenant suspension, and shared-domain defense.
Building Agents That Don't Break Themselves: Fly.io's Sprite Safety Patterns and the Deploy-from-Chat Risk Model
Fly.io's June 2026 Sprite safety patterns — splitting the agent loop from execution, per-run credentials, and checkpoint restores — map directly onto what a deploy platform needs before agents can ship code: scoped credentials, audit logs, and guaranteed rollback.