532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Daytona's Repo Is Frozen — Will the Fork Survive? What Three Open-Source Relicenses Teach About Betting on Nightona
Daytona froze its public repo at v0.190.0 in June 2026 and moved development private. Community fork Nightona carries the AGPL tree forward, but the HashiCorp, Redis, and Elasticsearch precedents say forks survive only with funded maintainers, neutral governance, and API compat — Nightona scores half a point out of three.

Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails
Across 409,000 approve-or-deny decisions, human reviewers missed a third of malicious AI agent commands — and the credential-stealing ones slipped through three times as often as the obviously destructive ones. The numbers argue for sandboxes, scoped credentials, and policy engines ahead of the approve button.

TLS for a Bare IP: What Let's Encrypt's Free IP-Address Certificates Change for Self-Hosted Deploys
Let's Encrypt's free IP-address certificates went generally available in January 2026: six-day, ACME-automated TLS for a bare IPv4 or IPv6 address. Where they fit in a self-hosted PaaS — node bootstrap before DNS, fallback vhosts, IP-addressed infrastructure — the exact recipe for getting one, and the limits that keep tenant traffic on real domains.

Lint the Dockerfile Before You Build It: What hadolint, dockle, and Docker Scout Catch That a Green Build Never Will
A green docker build waves through unpinned base tags, root users, baked-in secrets, and known CVEs. How hadolint at PR time, dockle at build time, and Docker Scout at deploy time each catch a failure class the others cannot see — with gate configs you can copy.

15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild
In September 2025 the npm package postmark-mcp shipped fifteen clean releases, then added a one-line BCC backdoor in v1.0.16 — the first malicious MCP server caught in the wild. What the incident proves about version-history trust, plus a concrete checklist for teams installing third-party MCP servers and platforms distributing their own.

MCP Won the Protocol War — the Lock-In Just Moved Up a Layer: A Self-Hoster's Field Test
MCP became the universal agent interface — and the lock-in moved into security policies, drift detection, and Skills libraries. A hands-on field test shows which moats self-hosting defeats and which one follows you home.

10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools
Pinterest runs 66,000+ MCP tool calls a month through domain-specific servers behind a central registry. How the registry-plus-fleet pattern solves discovery and access control — and what it means for the deploy tools agents drive.

The Worst Three Months in npm History: What Your Build Layer Needs When the Registry Can't Be Trusted
Between March and June 2026, Axios, node-ipc, Red Hat's npm namespace, and the Mastra framework were all compromised — each defeating a different defense. A concrete accounting of all four attacks and the five build-layer controls that survive them: frozen lockfiles, disabled install scripts, DNS-aware egress sandboxing, honest provenance, and per-build SBOMs.

Nvidia Runs OpenBao in Production: The Vault Fork's Enterprise Moment, and How to Wire It Into Kubernetes
NVIDIA runs its serverless GPU platform's secrets on OpenBao, eight vendors now sell commercial support, and v2.6 added per-namespace sealing — why the Vault fork is now safe to bet a self-hosted platform on, and how to wire it into Kubernetes with the External Secrets Operator.