I Built an Offline SAST Scanner — Try It on Your Code and Tell Me Where It Fails
https://github.com/mattybellx/Ansede I've been working on this on and off for about a year. It...
Tag archive
https://github.com/mattybellx/Ansede I've been working on this on and off for about a year. It...
🦞 CyberSecClaw DAST (Dynamic Application Security Testing) has existed for web apps for 20 years....
The Axios npm compromise this week is being called a supply chain attack. That framing is not wrong,...
CVEs aren't the problem. When you find them is. CVEs in code land at the worst possible moment —...
TL;DR: AI code assistants — Cursor, Claude Code, Windsurf, Copilot — are reshaping how software...
Kubernetes is often treated as the starting point for DevOps learning. This is a...

Check before you wreck Part of The Coercion Saga — making AI write quality...

How I found that a project's settings file can inject arbitrary HTTP headers into every API request...

How I found that a project's settings file can redirect your API traffic to an attacker's server,...

The last vulnerability I found was the quietest. No command execution. Just... reading files that...

This is the third configuration issue I found. And it might be the most dangerous one. By this...

After discovering the MCP configuration issue (which I wrote about separately), I kept exploring. If...