532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Hard Multi-Tenancy for Agent Workloads: What Apple's Kata plus VirtualClusters Recipe Costs
Apple's KubeCon recipe pairs per-tenant virtual control planes with Kata microVMs so untrusted agent code never shares a kernel with production tenants. The bill: about a second of cold start and 30-100 MB per sandbox, plus one small control plane per tenant.

Heroku Killed 12 TLS Ciphers: The Legacy-Client Audit Your Self-Hosted PaaS Needs Too
Heroku removed 12 legacy TLS cipher suites and enabled TLS 1.3 with HTTP/2 on August 24, 2026. Here is which clients break, a reproducible openssl/sslyze/testssl.sh audit for your own domains, and the cert-manager plus Gateway API baseline to match it.

Your Coding Agent Needs a Sandbox, Not a StatefulSet: gVisor vs Kata Under Kubernetes' New Sandbox Controller
Kubernetes SIG Apps shipped an upstream Sandbox controller for running untrusted agent code. A practical decision guide: what it replaces, whether gVisor or Kata fits your tenants, and what warm pools cost in idle capacity.

10,000 MCP Servers and No Human Wiring Them Up: What Server Cards and Stateless Operation Mean for Agents That Deploy Your Apps
MCP passed 10,000 public servers and is going stateless and self-describing, so agents will soon reach your deploy tools with no human wiring anything up. Here is the three-tier tool surface — observe freely, gate mutation, deny destruction — that survives contact with autonomous callers.

Railway Cloud Agents Promote Your Dev VM Straight to Prod: What Skipping the Build Actually Costs
Railway's Cloud Agents Beta promotes the agent's lived-in VM straight to production via a VM daemon, skipping git push and CI as too slow. A five-row ledger of what the build step was quietly doing — drift, secrets, approvals, rollback, provenance — and how to keep the fast loop without shipping a mutable machine.

Your Sandbox Is Not a Home: Where Vibe-Coded Apps Actually Live After Day One
Every 2026 guide to shipping vibe-coded apps ends at 'deploy behind a sandbox' — without saying where the app lives long-term. The missing fifth stage: a permanent git-backed home with a redeploy loop, the sandbox-vs-home checklist, and the cost crossover between execution meters and flat hardware.

SmolVM vs. Firecracker: Which MicroVM Should Actually Isolate Your AI Agent's Code?
SmolVM's sub-200ms boot challenges Firecracker's two-year default. A measured comparison of boot time, memory density, and what actually isolates untrusted agent code from the host kernel across SmolVM, Firecracker, OpenSandbox, and Docker Sandboxes.

Run a Claude Fable Security Scan with Bex Security
Run a Claude Fable security scan with Claude Code and Bex Security. The exact command, the model row that actually runs, and the sandbox policy Bex enforces around Claude.

Coolify's 11 Critical CVEs and 52,890 Exposed Dashboards: What a Single Root Daemon's Blast Radius Actually Looks Like
Coolify disclosed 11 critical CVEs in January 2026 — five rated CVSS 10.0 — with 52,890 dashboards exposed online. Eight months later, here is what changed, what didn't, and why blast radius per CVE is the number that should drive self-hosted PaaS architecture choices.