Skip to main content
Watch: Claude Opus 5.5 Built an Entire 3D World

SECURITY

73 items

68 posts, 3 tools, 2 guides

Blog
GLM 5.2 Outperforms Claude Code on Semgrep's IDOR Vulnerability Benchmarks

Semgrep's security research team benchmarked LLMs on IDOR vulnerability detection. The open-weight GLM 5.2 beat Claude Code by 7 points at roughly one-sixth the cost.

Blog
OpenAI's June API Updates Are Really a Control-Plane Upgrade

OpenAI's June 2026 API changelog looks like scattered platform plumbing. Read together, moderation scores, workload identity, Admin APIs, prompt-cache retention, container billing, and Secure MCP Tunnel are the pieces teams need to run agents with real controls.

Blog
Perplexity Bumblebee: Developer Guide to the Open Source Supply Chain Scanner

Bumblebee is Perplexity's open source scanner for detecting compromised packages, extensions, and MCP configs on developer machines. A read-only Go binary that checks npm, PyPI, Go modules, and 10+ ecosystems against exposure catalogs - without running any install scripts. Here is how to set it up and use it.

Blog
Arcade AI Agent Authorization: A Developer Guide

Arcade just raised $60M to become the secure action layer for production AI agents. Here is what their MCP runtime actually does, how it differs from rolling your own OAuth, and when to use it.

Blog
Vulnerability Reports Are Not Special Anymore

Filippo Valsorda argues that LLMs have ended the era of treating security researchers with kid gloves. When anyone can discover vulnerabilities with an AI, the old coordinated disclosure model breaks down.

Blog
Agent Identity Is the Missing Security Layer for AI Workflows

The Linux Foundation's Agent Name Service proposal points at a real gap in AI agent infrastructure: agents need verifiable identity, scoped capabilities, revocation, and audit trails before they can safely act across tools.

Blog
Agent Sandbox Architecture: How to Choose the Right Runtime Boundary

AI agents are getting their own computers. Here is how to choose a sandbox architecture: filesystem isolation, network policy, secrets boundaries, snapshots, and when shell access is overkill.

Blog
Cybersecurity Skills for AI Agents Are Becoming Runtime Infrastructure

A GitHub-trending library of Anthropic cybersecurity skills points at the next agent security layer: framework-mapped playbooks that need provenance, tests, and abuse boundaries before they become trusted runtime tools.

Blog
OpenAI Daybreak Shows the AppSec Bottleneck Is Patching, Not Finding

OpenAI's Daybreak and Patch the Planet point at the real agentic AppSec shift: security agents only matter when they produce validated, reviewable patches maintainers can actually merge.

Blog
Claude Code Permissions: settings.json Allow, Deny, Ask

Configure Claude Code permissions in settings.json: allow, deny, and ask rules, scope precedence, tool specifiers, and the headless flags you need for CI.

Blog
Mastra npm Supply Chain Attack: 140+ AI Framework Packages Backdoored

On June 17, 2026, attackers hijacked a dormant Mastra contributor account and pushed malicious versions of 140+ packages. The payload steals crypto wallets, browser data, and cloud credentials. Here is what happened, how to check your lockfile, and what to do if you installed an affected version.

Blog
AI Infrastructure Agents Need Spend Guardrails

The viral DN42 AWS bill story is funny until you realize the missing primitive: infrastructure agents need hard cloud-spend guardrails before they touch real accounts.

Tool
E2B

Open-source cloud sandboxes for AI agents. Isolated environments that start in under 200ms, run code in Python, JavaScript, and more, and persist sessions up to 24 hours.

Blog
The One-Cent Attack: Prompt Injection Through Bank Transfer Memos

Security researchers showed a €0.02 bank transfer could compromise a banking AI assistant. Here is the exact attack chain - and what every developer building agents needs to do differently.

Blog
Fable 5 Broke Enterprise ZDR Agreements: What Dev Teams Must Do Now

Anthropic's Claude Fable 5 mandates 30-day data retention on every platform, overriding existing Zero Data Retention contracts for enterprise API customers. Here is what compliance teams and developers need to audit before their next deployment.

Blog
June 10, 2026: The Day the AI Dev Tool Market Showed Its Whole Hand

Pricing deadlines, infrastructure funding, a banking prompt injection case, and a 4x speed breakthrough - June 10 was one of the densest single days the AI dev tool market has ever produced.

Blog
Agent Config Files Are Executable Supply Chain

A Hacker News thread on config files that run code points at the next AI coding risk: agent hooks, skills, and editor rules need review like executable dependencies.

Blog
Security Agents Need Repro Harnesses, Not More Scan Prompts

Anthropic's open-source vulnerability harness shows where AI security work is going: reproducible exploit loops, separate verification agents, and patch receipts.

Blog
The Agent Security Checklist I Use Before Connecting Tools

Before an AI agent gets tools, files, APIs, MCP servers, or deployment access, decide what it can read, write, call, log, and roll back.

Blog
AI Security Scanners Move the Bottleneck to Triage

Anthropic's Project Glasswing update is a useful signal for developer teams: AI can find vulnerability candidates faster than humans can verify, disclose, patch, and ship them.

PreviousPage 3 of 4Next
AI Development Stack

Get Smarter About AI Dev

New tutorials, open-source projects, and deep dives on coding agents - delivered weekly.

One email per weekReal code, not theoryFree forever