532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Don't Hand-Write an MCP Server: Project Your REST API Through a Gateway
Hand-writing an MCP server means maintaining a second governed interface. What projecting your REST API through a gateway gives you for free — OpenAPI-derived tools, OAuth 2.1 auth, rate limits — and the write-scoping, approval, and rollback semantics a deploy API still has to build itself.

AI-Assisted Commits Leak Secrets at Twice the Baseline Rate — Why Your PaaS Should Scan Every Push
GitGuardian counted 28.65 million new hardcoded secrets on public GitHub in 2025, with AI-assisted commits leaking at 3.2% against a 1.5% baseline. Why a default-on push-time scan catches what Vault, OpenBao, and Infisical never see, and what the gate should look like.

Hardening an Infrastructure MCP Server: TLS, Scoped Credentials, and Rate Limits Before an Agent Touches Production
An MCP server that can redeploy production is a deploy pipeline with natural-language input. A seven-control hardening checklist — TLS, per-tool scopes, short-lived credentials, schema validation, rate limits, and audit logging — mapped to the three attacks that actually happen.

MCP Retires Dynamic Client Registration: The OAuth Migration Your Self-Hosted Server Has Twelve Months to Finish
The final MCP spec deprecates Dynamic Client Registration in favor of Client ID Metadata Documents, with removal eligible after July 2027. Here is the ordered checklist for migrating a self-hosted MCP server, plus the two companion hardenings to ship in the same window.

One Missing Middleware Call, 2,689 Exposed Servers: What nginx-ui's MCPwn (CVE-2026-33032) Teaches Anyone Shipping an MCP Server
nginx-ui shipped an MCP endpoint without its AuthRequired check — a CVSS 9.8 that left roughly 2,689 servers open to unauthenticated takeover. The full MCPwn timeline, the two-route bug, and a seven-item audit checklist for anyone shipping an MCP server.

SmolVM Packs a MicroVM Into a Single Binary That Boots in Under 200ms — What It Changes for a Firecracker-Only Agent Sandbox
SmolVM boots any OCI image as a hardware-isolated microVM from a single binary in under 200ms, with pack and branch primitives Firecracker never shipped. Here is how it compares head-to-head and what to verify before adding it to a self-hosted agent-sandbox stack.

Tailscale Went Seat-Based: What Self-Hosting Your Admin VPN With NetBird or Headscale Actually Costs
Tailscale's 2026 move to 8 to 18 dollar per-seat pricing turned the admin VPN into a headcount tax. What a self-hosted NetBird or Headscale control plane costs in infrastructure and ops hours, the exact seat counts where each crosses over, and when to just pay the SaaS bill.

Toward a World Where Builds Don't Exist: What Railway's VM-Powered Thesis Gives Up in Provenance
Railway wants a world where builds don't exist and your app is just live. But the build produces the digest, SBOM, provenance, and rollback artifact that incident response and the EU's new reporting rules depend on — here is the full inventory of what disappears with it.

cert-manager vs Gardener vs certctl: What Tenant TLS Really Costs at 10, 100, and 1,000 Custom Domains
A head-to-head comparison of cert-manager, Gardener cert-management, and certctl for per-tenant custom-domain TLS, with the rate-limit math and renewal checklist for fleets from 10 to 1,000 domains.