Skip to main content
Watch: Claude Opus 5.5 Built an Entire 3D World

SECURITY

73 items

68 posts, 3 tools, 2 guides

Blog
OpenAI Open-Sourced Codex Security: What HN Thinks

OpenAI released the Codex Security CLI and TypeScript SDK as open source on GitHub. The Promptfoo team behind it, the 2.1k-star reception, and what the HN community says about cost, guardrails, and local model support.

Blog
AI Coding Agent Security Models Compared 2026: Permissions, Sandboxing, and Threat Models for Every Major Tool

How Claude Code, Cursor, Codex, GitHub Copilot, Aider, and Windsurf handle permissions, sandboxing, credential protection, and prompt injection. A structured comparison for engineering teams evaluating agent security.

Blog
US Prosecutors Charge Traveler Over GrapheneOS Phone Wipe During Airport Search

A federal case in Atlanta is testing whether using a privacy-focused mobile OS can be treated as destruction of evidence. The GrapheneOS duress PIN feature erased a traveler's phone during a CBP interrogation - and prosecutors are charging him for it.

Blog
Android May Soon Restrict On-Device ADB - What Developers Need to Know

A Google ADB maintainer proposed restricting on-device ADB connections to loopback, which would break Shizuku, libadb-android, Termux workflows, and an entire ecosystem of open-source power-user apps.

Blog
A Security Camera Shipped a GitHub Admin Token in Its Login Page

A security researcher found a GitHub personal access token with admin privileges to hundreds of repos baked into Hanwha Vision camera firmware. The cause: a Vite build leaking process.env into production.

Blog
HalluSquatting Makes AI Coding Agents a Supply-Chain Problem

A July 2026 paper shows how hallucinated repository and skill names can become promptware delivery paths. The practical fix is boring: search before fetch, verify names, and sandbox every install.

Blog
Securing AI Coding Agents: A Practical Threat Model for 2026

Prompt injection, sandbox escapes, and hallucinated dependencies are now documented, patched, CVE-numbered realities. Here is the threat model for agent-written code and the defenses worth adopting this week, ranked by effort.

Blog
TP-Link Kasa Cameras Leaked Home GPS Coordinates for Six Years

Security researcher discovers TP-Link Kasa cameras exposed precise home coordinates via unauthenticated UDP - a vulnerability publicly documented since 2020 but only patched in 2026.

Blog
Langflow CVE-2026-55255: The First AI Agent Framework on CISA's Must-Patch List

CISA added the first AI agent building platform to its Known Exploited Vulnerabilities catalog. What the Langflow IDOR vulnerability means for agent security and how to check if you're exposed.

Blog
AI Voice Fraud Needs Three Seconds of Your Voice

Voice cloning now requires just 3 seconds of audio to impersonate someone. With $893M in reported losses, detection has failed - here's what might actually work.

Blog
xAI Open-Sources Grok Build After Data Exfiltration Scandal

Days after getting caught uploading entire codebases to xAI servers, Grok Build is now open source on GitHub. The HN community isn't convinced it's enough.

Blog
Cursor 0day: Why a 7-Month-Old Vulnerability Is Still Unpatched

Security researchers disclosed a Cursor vulnerability that auto-executes malicious git.exe files from repos - after waiting 7 months with no fix. Here's what developers need to know.

Blog
Clawk: Disposable Linux VMs for Coding Agents Without Cloud Bills

Open-source tool gives Claude Code, Codex, and other agents their own isolated Linux VM on your machine - network firewall included, no cloud account required.

Blog
GhostLock: A 15-Year Linux Kernel Vulnerability That Affects Every Distribution

A use-after-free bug in the Linux kernel's real-time mutex implementation has existed since 2011. Researchers earned $92,337 from Google's kernelCTF for discovering and exploiting it.

Blog
What xAI's Grok Build CLI Actually Sends Home: A Wire-Level Analysis

A security researcher intercepted Grok Build's network traffic and found it uploads entire repositories - including .env files with secrets - to xAI servers. Here's what the data shows.

Blog
Ghost Font: Text That Humans Can Read But AI Cannot

A new experimental technology encodes messages in video using motion-based steganography, exploiting how AI models process video as individual frames rather than continuous motion.

Blog
GitLost: How Researchers Tricked GitHub's AI Agent Into Leaking Private Repos

Security researchers discovered a prompt injection vulnerability in GitHub's Agentic Workflows that allows attackers to extract private repository contents through public issues.

Blog
Decoding the Hidden Bash Script on a Uniqlo T-Shirt

Someone found an obfuscated bash script on a Uniqlo x Akamai t-shirt and decoded it. Here's what they found - and what HN thinks about whether it was AI-generated.

Blog
Flipper Zero Shifts to Community-Driven Development

Flipper Devices announces their firmware hit 1.0 stability and outlines a new community contribution model - while HN debates whether 'done' software is actually a good thing.

Blog
Claude Code Is Steganographically Marking Requests

A developer reverse-engineered Claude Code and found hidden markers that classify users by timezone, domain, and API keywords - using unicode apostrophe swaps and date format changes.

PreviousPage 2 of 4Next
AI Development Stack

Get Smarter About AI Dev

New tutorials, open-source projects, and deep dives on coding agents - delivered weekly.

One email per weekReal code, not theoryFree forever