531 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

What the MCP 2026-07-28 Spec Broke: Your Server's Auth Fix Checklist
The MCP 2026-07-28 spec turned every remote server into a formal OAuth 2.1 resource server, and working servers now fail closed. Here is the six-item fix checklist: metadata endpoint, 401 pointer, audience enforcement, issuer validation, and the DCR-to-CIMD plan.

12,520 Exposed MCP Servers: A 7-Point Auth Checklist for Shipping a Deploy-Capable MCP Server
Censys found 12,520 MCP servers on the public internet and independent studies put 40% of remote servers at no authentication at all. Here is the seven-default auth checklist that keeps a deploy-capable MCP server out of the next scan.

Mooring: a Security-First PaaS in One Binary — and What Breaks When You Need a Second Server
Mooring packs a secure-by-default PaaS into one 12 MB binary — no Swarm, no Kubernetes. This capability-by-capability comparison with Coolify, Dokploy, and Cluster API fleets shows exactly what breaks when one server stops being enough.

Railway Skips the Post-Merge Rebuild: Promote the Exact Preview Image to Production With BuildKit Digests
Railway's Skipped Builds deploys the already-tested PR image to production instead of rebuilding after merge. A self-hosted version of the same trick: commit-to-digest provenance, BuildKit cache policy, and digest-pinned deploys.

Render Killed the Pasted AWS Key. Your Self-Hosted PaaS Is Now on the Clock.
Render's July 2026 OIDC releases made keyless auth to AWS, Anthropic, and OpenAI a GA platform feature. Here's the trust-chain machinery behind it and the two concrete paths — cluster-issuer federation or SPIFFE/SPIRE — for matching it on machines you own.

Keyless Signing Won: What Rekor v2 and cosign v3 Mean for Verifying Every Image at Admission
Rekor v2, cosign v3, and Open Component Model's breaking 2026 releases made keyless signing the default. What identity-based provenance means for verifying every container image at admission — and where the guarantees stop.
Sprites Meet MCP: How Fly.io Built Agent-Safe Sandboxed Deployment Environments
Fly.io's Sprites now speak MCP: agents get persistent Firecracker microVMs with 300ms checkpoints through sprites.dev/mcp. Here is the six-primitive checklist for agent-safe sandboxes, how E2B, Daytona, Modal, and Vercel compare, and what it takes to build the same on owned hardware.

Java 27 Is GA: G1 Everywhere, Quantum-Safe TLS, and Goodbye Intel Macs — Your Buildpack TODO List
Java 27 turned on G1, compact object headers, and hybrid post-quantum TLS by default while ending Intel Mac maintenance. Here is what each change means for a self-hosted PaaS Java buildpack, with container memory math and a build-fleet checklist.

MCP Memory Servers: What Persistent Memory-as-a-Tool Means for a Deploy Agent That Forgets Every Session
MCP memory servers give deploy agents persistent memory any client can share — last good deploys, environment preferences, and incident fixes recalled by retrieval instead of replayed history. The catch: multi-tenant isolation and poisoned-memory attacks that turn one bad fact into a standing prompt injection.