Skip to main content

532 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

Two Sender Identities, $149K Gone: Inside DBXen's ERC-2771 Accounting Exploit
·Dora Noda·9 min

Two Sender Identities, $149K Gone: Inside DBXen's ERC-2771 Accounting Exploit

A transaction-level reconstruction of the DBXen ERC-2771 sender mismatch that drained roughly $149K, plus the invariants that would have stopped it.

Ethereum
BNB Chain
DeFi
smart-contracts
+1
Inside the $285M Drift Protocol Heist: Six Months of Trust, 12 Minutes to Start the Drain
·Dora Noda·13 min

Inside the $285M Drift Protocol Heist: Six Months of Trust, 12 Minutes to Start the Drain

The $285M Drift Protocol heist began with six months of trust-building. See the verified attack chain, conflicting figures, and controls that could have stopped it.

Solana
DeFi
security
cybersecurity
+1
AI-Linked Crypto Scams Extract 4.5× More Per Operation. Build a Defense That Doesn’t Depend on Spotting a Deepfake
·Dora Noda·10 min

AI-Linked Crypto Scams Extract 4.5× More Per Operation. Build a Defense That Doesn’t Depend on Spotting a Deepfake

AI-linked crypto scams extracted 4.5 times more revenue per operation in 2025. Here is a practical control map for stopping deepfake, identity, and payment fraud without betting everything on detection.

crypto
AI
security
An Agent Can Run Your Home Lab. That Doesn't Make It a Fleet Control Plane.
·Dora Noda·10 min

An Agent Can Run Your Home Lab. That Doesn't Make It a Fleet Control Plane.

A concrete boundary between an MCP agent operating a Coolify home lab and a declarative Cluster API fleet, with practical signals for when the architecture needs to change.

AI
infrastructure
engineering
security
Coolify Critical CVEs: The PaaS Isolation Lesson
·Dora Noda·10 min

Coolify Critical CVEs: The PaaS Isolation Lesson

Critical Coolify advisories show how authorization failures and deployment input can reach privileged infrastructure—and which layered controls can narrow the blast radius.

security
self-hosting
PaaS
Kubernetes
Gateway API 1.6 Gives Agent Sandboxes a Named Egress Target—Not an Egress Policy
·Dora Noda·10 min

Gateway API 1.6 Gives Agent Sandboxes a Named Egress Target—Not an Egress Policy

Gateway API 1.6's experimental XBackend can make an AI API destination reviewable. Here is the complete control stack required to turn that declaration into safe sandbox egress.

AI agents
self-hosting
PaaS
Kubernetes
+1
Hetzner DNS Makes `ttl` Mandatory: Audit the One ACME Call That Can Break Renewal
·Dora Noda·9 min

Hetzner DNS Makes `ttl` Mandatory: Audit the One ACME Call That Can Break Renewal

Hetzner Cloud DNS will require an explicit TTL on one RRSet action after September 30, 2026. Identify whether your ACME path uses it, patch the request correctly, and rehearse a safe renewal.

cloud infrastructure
Kubernetes
self-hosting
security
CVE-2026-35469: Audit SPDY Exposure in Your Self-Hosted Kubernetes Fleet
·Dora Noda·8 min

CVE-2026-35469: Audit SPDY Exposure in Your Self-Hosted Kubernetes Fleet

CVE-2026-35469 affects a SPDY dependency, not a single Kubernetes version. Use this practical audit to identify reachable parsers, verify vendor fixes, and roll self-hosted nodes safely.

Kubernetes
security
self-hosting
infrastructure
MCP Governance for Deploy APIs: A Playground-to-Production Control Plane
·Dora Noda·10 min

MCP Governance for Deploy APIs: A Playground-to-Production Control Plane

A practical Playground-to-production lifecycle for MCP deploy tools, with catalog review, policy-gateway controls, audience-bound tokens, approvals, and audit trails.

AI agents
Model Context Protocol
security
infrastructure
Showing 235–243 of 532 posts