Skip to main content
Watch: Claude Opus 5.5 Built an Entire 3D World

SECURITY

73 items

68 posts, 3 tools, 2 guides

Blog
NVIDIA OpenShell Makes Agent Sandboxes a Policy Layer

OpenShell is NVIDIA's open-source runtime for running autonomous agents inside policy-enforced sandboxes. The interesting part is not another wrapper around a model. It is the move from prompt rules to infrastructure rules.

Blog
Cloudflare Page Shield ML Caught 4 Storefront Malware Campaigns Static Scanners Missed

Cloudflare's client-side security ML surfaced four malicious JavaScript operations across online stores: affiliate hijacking, clickless commission theft, a repurposed search-hijacker turned storefront backdoor, and a paid-mobile cloaker. None of them had a signature, and most were invisible to VirusTotal and URLScan.

Blog
Cloudflare Adaptive Intelligence: Bot Scores That Retrain Weekly Instead of Quarterly

Cloudflare's new bot detection engine drops the keep-everyone-out wall for a continuously retraining model, disposable rules, and a memory of past attacks. The first component ships today as a toggle in Bot Management, and the design is an inversion of how every bot product has worked until now.

Blog
Ray CVE-2025-62593: Botnet Beat the Patch, CISA Gives Feds 3 Days

The RondoDox botnet started exploiting Ray CVE-2025-62593 two days before the CVE was public, and CISA gave federal agencies just three days to remediate. Here is how to check whether your Ray cluster or dev machine is exposed and what to harden first.

Blog
arrayref 0.3.10 Ran a Remote Payload at Build Time

On August 20, 2026, compromised arrayref 0.3.10 pulled in a proc-macro1 typosquat whose build script fetched a remote binary. Coding agents that cargo update on yank warnings walk into this.

Blog
Cloudflare Gateway Can Now Detect MCP Traffic on the Wire: Shadow MCP Gets a Network Boundary

Cloudflare Gateway now classifies MCP traffic by protocol headers instead of hostname heuristics, ships a shadow-MCP dashboard, and lets admins block any MCP connection that does not arrive through an approved portal. The 2026-07-28 stateless spec is what made it possible.

Blog
Skill Files Are the New Supply Chain Attack Surface

Adversarial skill files - folders of instructions agents load dynamically - exploit a mainstream enterprise coding agent in 95.5 to 96.1 percent of runs, while the agent recognizes danger 1.99 percent of the time. The skill folder is now a measured attack surface, and the defense is admission engineering, not better prompts.

Blog
Anthropic Now Watermarks All Claude Output: Text Watermarks and C2PA for Files

Anthropic confirms that every Claude model released after August 2, 2026 embeds a machine-readable watermark in generated text and attaches C2PA provenance metadata to generated files, across the API, Claude Code, Cowork, and Tag. Detection tooling for third parties is coming, but details are not published yet.

Blog
Cloudflare DDoS Report H1 2026: 1 Tbps Attacks Soared as DNS Floods Became the Leading Vector

Cloudflare mitigated 935 network-layer attacks above 1 Tbps in H1 2026, a +519% quarter-over-quarter jump, while DNS floods grew from 25.7% to 40.0% of network-layer attacks. Here is what the numbers say about how attacks are changing and what it means for anyone running public infrastructure.

Blog
Encrypted Chain-of-Thought Is Not Private: New Paper Decodes Reasoning Traces From Anthropic, OpenAI, and Google APIs

A new arXiv paper shows the encrypted reasoning blocks that Anthropic, OpenAI, and Google return to API clients can be replayed into weaker models from the same provider and transcribed verbatim. The authors decoded 315,320 blocks from public repositories and recovered 367 PII artifacts and 182 credentials.

Blog
Stop Means Stop: New Paper Finds Agent Approval Gates and Cancellation Leak in Six Frameworks

A new arXiv paper probes six widely used open-source agent frameworks and finds the barrier semantics of approval gates, cancellation, and timeouts hold on none of them. A sibling branch can execute while the user is rejecting another one, and replay can double-execute. The fix is a verified external gate called SoundGate.

Blog
Vercel Sandbox Gets a Real Network Boundary: Why Egress Control Is the Missing Half of Agent Security

Vercel Sandbox now polices all outbound traffic on the host, outside the microVM, with SNI-based domain policies, CIDR rules, host-level credential injection, and a deny-all default. Here is why a network boundary is the half of agent isolation that VM escapes missed.

Blog
Cloudflare Ships Behavioral Trust for the Agentic Internet: 206M Events, 73K Zones

Cloudflare's Web Integrity team published the framework behind its agent traffic posture: continuous behavioral trust instead of point-in-time bot scoring, Precursor telemetry from 206 million evaluation events a day across 73,438 zones, and a verified-bot taxonomy where agents earn access by declaring themselves honestly.

Blog
GitHub Malware Advisories Now Cover Eight Package Ecosystems

Dependabot's malware detection expands from npm to PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer by ingesting OpenSSF's malicious-packages data into the GitHub Advisory Database.

Blog
Cloudflare's Agent Access Model: Zero Trust for Task-Scoped Agent Runs

On August 5 Cloudflare published the Agent Access Model: a reference architecture where credentials are short-lived and task-scoped, enforcement lives in the harness and network instead of the prompt, and a Trust Ratchet only narrows an agent's capabilities. The cleanest spec yet for least privilege at agent speed.

Blog
Cloudflare OS: The Open Source Agent Workspace That Treats Apps Like Files

On August 5 Cloudflare open sourced Cloudflare OS, the agent workspace it has run internally since May: capability-based Gatekeepers instead of ambient MCP access, apps as private per-user instances, and approvals that simulate outcomes so agents never stall. A concrete blueprint for the company-wide agent platform.

Blog
The RipGrep Musl Segfault That Led to a One-Line Linux Kernel Patch

A ripgrep musl binary crashing during very-large searches turned out to be a suspected Linux 7.0 kernel race - a thread's own store vanishing mid-function. The reporter's instrumentation pinned it, and a kernel-hardening maintainer posted a one-line fix candidate for testing.

Blog
AgentS4D: 66% of All Coding Agent Runs Were Unsafe Yet Still Completed

A new arXiv benchmark ran 6,560 sandboxed runs across Claude Code, Codex, OpenClaw, and Hermes with five LLMs. 68% of runs triggered unsafe signals, and 66% of all runs were unsafe yet still passed completion checks. Task completion does not prove an agent ran safely.

Blog
GitHub Actions Self-Repository Syntax: Reference Your Own Actions at the Running Commit

GitHub Actions added a $/ prefix that resolves a same-repository action or reusable workflow at the exact commit being run, with no checkout. It fixes the pinning trap that made enterprise SHA-pinning policies hard to satisfy for a repo's own actions.

Blog
OpenAI Disrupts a Cambodia Scam Network That Ran on ChatGPT

OpenAI took down a Cambodia-based operation that used ChatGPT for personas, translations, forged documents, and admin work. It is the clearest picture yet of how LLMs slot into organized fraud.

Page 1 of 4Next
AI Development Stack

Get Smarter About AI Dev

New tutorials, open-source projects, and deep dives on coding agents - delivered weekly.

One email per weekReal code, not theoryFree forever