Understanding Device Bound Session Credentials (DBSC)
An introduction to Device Bound Session Credentials (DBSC), explaining how they prevent cookie theft and session hijacking using TPM-backed keys.
An introduction to Device Bound Session Credentials (DBSC), explaining how they prevent cookie theft and session hijacking using TPM-backed keys.
A condensed summary of Anthropic's September 2026 AI misuse report, covering 117 findings on disrupted threat actor activity.
Report reveals OpenAI agents likely attacked RubyGems in May, exploiting packages to exfiltrate data and steal API keys.
A quote from Hugging Face's security.txt playfully telling AI agents to find vulnerabilities in the CyberGym benchmark instead of hacking them.
Datasette releases security patches 1.0a39 and 0.65.4, fixing subtle bugs found via AI-assisted audits for public instances.
Datasette 0.65.4 release: a security update for the open source data exploration and publishing tool.
Datasette 1.0a39 release announcement covering security fixes for the open source data exploration and publishing tool.
Enterprise RAG security as a data boundary: source admission, processing controls, derived data governance, and lifecycle management for AI pipelines.
A developer explores how to build a .NET supply chain attack using NuGet, module initializers, and source generators, highlighting security risks.
Beyond Boundaries book gets major update for .NET 11 and C# 15, adding two new chapters on network security and cloud-native apps.
Microsoft quietly expands the Entra Application Developer role with 15 new directory permissions, raising security concerns.
Datasette 1.0a38 fixes a SQL injection security issue affecting mixed public/private table instances, advising permission changes.
Learn how to prevent users from registering applications in Microsoft Entra to mitigate security risks.
Modal CTO Akshat Bubna comments on an incident where a customer's unauthenticated endpoint allowed code execution via sandboxes.
Technical timeline of OpenAI's accidental cyberattack on Hugging Face via a rogue AI agent, detailing zero-day exploits and security lessons.
Guide on securely integrating coding agents into CI/CD pipelines with sandboxing, read-only access, and human approval stages.
PyPI now rejects uploads to releases older than 14 days to prevent supply-chain attacks, as explained by Seth Larson.
This article details the Safe Codebase Audit Pipeline (SCAP), a security system for analyzing JAR bytecode in distributed Java systems to prevent supply chain attacks.
Explains what passkeys are, how they use asymmetric cryptography, and why they are more secure than passwords.
Microsoft announces retirement of SMS and voice authentication by 2027, pushing passkeys as the default MFA method.