532 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

Two Sender Identities, $149K Gone: Inside DBXen's ERC-2771 Accounting Exploit
A transaction-level reconstruction of the DBXen ERC-2771 sender mismatch that drained roughly $149K, plus the invariants that would have stopped it.

Inside the $285M Drift Protocol Heist: Six Months of Trust, 12 Minutes to Start the Drain
The $285M Drift Protocol heist began with six months of trust-building. See the verified attack chain, conflicting figures, and controls that could have stopped it.

AI-Linked Crypto Scams Extract 4.5× More Per Operation. Build a Defense That Doesn’t Depend on Spotting a Deepfake
AI-linked crypto scams extracted 4.5 times more revenue per operation in 2025. Here is a practical control map for stopping deepfake, identity, and payment fraud without betting everything on detection.

An Agent Can Run Your Home Lab. That Doesn't Make It a Fleet Control Plane.
A concrete boundary between an MCP agent operating a Coolify home lab and a declarative Cluster API fleet, with practical signals for when the architecture needs to change.

Coolify Critical CVEs: The PaaS Isolation Lesson
Critical Coolify advisories show how authorization failures and deployment input can reach privileged infrastructure—and which layered controls can narrow the blast radius.

Gateway API 1.6 Gives Agent Sandboxes a Named Egress Target—Not an Egress Policy
Gateway API 1.6's experimental XBackend can make an AI API destination reviewable. Here is the complete control stack required to turn that declaration into safe sandbox egress.

Hetzner DNS Makes `ttl` Mandatory: Audit the One ACME Call That Can Break Renewal
Hetzner Cloud DNS will require an explicit TTL on one RRSet action after September 30, 2026. Identify whether your ACME path uses it, patch the request correctly, and rehearse a safe renewal.

CVE-2026-35469: Audit SPDY Exposure in Your Self-Hosted Kubernetes Fleet
CVE-2026-35469 affects a SPDY dependency, not a single Kubernetes version. Use this practical audit to identify reachable parsers, verify vendor fixes, and roll self-hosted nodes safely.

MCP Governance for Deploy APIs: A Playground-to-Production Control Plane
A practical Playground-to-production lifecycle for MCP deploy tools, with catalog review, policy-gateway controls, audience-bound tokens, approvals, and audit trails.