Skip to main content

531 posts tagged with "Security"

Cybersecurity, smart contract audits, and best practices

View all tags

Read the Platform security guide

15,465 MCP Servers, 0 Governance: What OX Security's Census Means for Your Deploy Tools
·Dora Noda·8 min

15,465 MCP Servers, 0 Governance: What OX Security's Census Means for Your Deploy Tools

OX Security mapped 15,465 MCP servers and found agents reaching China, Russia, home networks, and six abandoned domains buyable for $4. The four findings with exact numbers, the Always-Allow attack chain, and a control matrix for governing deploy agents' tools.

Model Context Protocol
AI agents
security
self-hosting
+1
Read-Only by Default: The 5-Rung Agent Permissioning Ladder Every Deploy Platform Should Copy
·Dora Noda·10 min

Read-Only by Default: The 5-Rung Agent Permissioning Ladder Every Deploy Platform Should Copy

Qovery's agent stack splits deploys from ops and ships its MCP server read-only — with a CLI allowlist and Rego policy tokens above and below. How the five-rung ladder works, where agent-side enforcement breaks, and the checklist for deploy-from-chat on machines you own.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
SSH3 in 2026: QUIC Shell Access Grew Up, but Its Own Forks Say Don't Ship It Yet
·Dora Noda·11 min

SSH3 in 2026: QUIC Shell Access Grew Up, but Its Own Forks Say Don't Ship It Yet

SSH3 re-implements SSH on QUIC, TLS 1.3, and HTTP/3 with 3-round-trip setup, roaming sessions, and UDP forwarding — but unaudited code and a renamed spec mean 2026's honest posture is a bastion-side trial, not a cutover. Here is the adoption map.

self-hosting
security
engineering
guide
Twelve Rogue Certificates for 1.1.1.1: CAA + accounturi Pinning for Tenant Custom Domains
·Dora Noda·10 min

Twelve Rogue Certificates for 1.1.1.1: CAA + accounturi Pinning for Tenant Custom Domains

A CA issued twelve unauthorized certificates for 1.1.1.1 over nineteen months before anyone noticed. The three-line CAA record set that pins a custom domain to one ACME account, the threat model each line covers, and the renewal gotchas to clear before the March 2027 mandate.

self-hosting
PaaS
security
infrastructure
One API Key vs 7,000 Tools: Where a Self-Hosted PaaS's MCP Server Should Land
·Dora Noda·11 min

One API Key vs 7,000 Tools: Where a Self-Hosted PaaS's MCP Server Should Land

A homelab MCP bridge runs your infrastructure behind one API token; Arcade's engine vaults per-user OAuth behind 7,000 tools. The head-to-head operator math at three team sizes, and where a self-hosted PaaS should land between them.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
One Config Field, 12,000 Exposed Boxes: What Flowise's CustomMCP RCE Teaches Anyone Exposing Agent Tools
·Dora Noda·10 min

One Config Field, 12,000 Exposed Boxes: What Flowise's CustomMCP RCE Teaches Anyone Exposing Agent Tools

Flowise's CustomMCP node turned a config string into remote code execution on 12,000+ internet-exposed instances. The anatomy of CVE-2025-59528, the sibling CVEs proving it is a pattern, and a six-rule checklist for anyone running an MCP or agent-tool surface.

security
AI agents
Model Context Protocol
self-hosting
GitLab's CVSS 10.0 File-Read Flaw: The Self-Hosted Patch Playbook for a 24-Hour Probe Window
·Dora Noda·9 min

GitLab's CVSS 10.0 File-Read Flaw: The Self-Hosted Patch Playbook for a 24-Hour Probe Window

CVE-2026-85706 lets unauthenticated attackers read any file off a self-managed GitLab server — and honeypots saw probes within 24 hours of disclosure. The four-step playbook: inventory, patch, forensic triage, and secret rotation.

security
self-hosting
cybersecurity
compliance
Shipping a Deploy-Authority MCP Server on Golf: What the Framework Owns and What You Still Build
·Dora Noda·10 min

Shipping a Deploy-Authority MCP Server on Golf: What the Framework Owns and What You Still Build

Golf, a production MCP server framework on FastMCP 4.0, owns auth, telemetry, and transport so you write only agent logic. Here is the exact framework-vs-platform split for an MCP server that deploys to production — plus the credential scoping, deploy API, and audit log no framework builds for you.

AI agents
Model Context Protocol
self-hosting
PaaS
+1
Kubernetes v1.37 Puts No-Exec Volumes in the Pod Spec: What a PaaS Can Delete From OPA
·Dora Noda·10 min

Kubernetes v1.37 Puts No-Exec Volumes in the Pod Spec: What a PaaS Can Delete From OPA

Kubernetes v1.37 adds noexec bind-mount flags and emptyDir permission modes to the Pod spec. Here is what moves from OPA policy to kernel enforcement, what stays in the policy engine, and the five rollout gotchas.

self-hosting
PaaS
Kubernetes
security
Showing 46–54 of 531 posts