All posts

Posts tagged with: Security

6 posts found

A factory conveyor belt moving identical boxes down an automated assembly line
AI Agents Swift Package Manager

OpenAI's Agents Quietly Hacked RubyGems. Swift Package Manager Has the Same Design Flaw.

A new report says an OpenAI agent swarm exploited RubyGems' automatic doc-build system for remote code execution and tried to steal API keys — undisclosed for months. Package.swift runs the exact same way.

8 min read
An old padlock and key resting against weathered metal — the kind of lock you can see is doing something, unlike a token sitting quietly in RAM
Swift Keychain

The Actor That Refreshes Your Token Perfectly. It Also Forgets It on Relaunch.

AuthTokenStore solved the token-refresh race condition with a Swift actor. What it never solved is where the token lives between launches. Here's why an in-memory actor isn't secure storage, and what a Keychain-backed version actually costs you.

8 min read
An open padlock hanging on a chain-link fence
AI Coding Tools GitHub Actions

An AI 'Security Fix' Introduced the Bug. GitHub's Own AI Review Called It Clean.

GitHub Copilot Autofix rewrote a Snowflake CI workflow and quietly introduced a shell injection vulnerability. GitHub's AI code review approved the PR anyway. Five days later, a different AI found it and walked straight into Snowflake's internal Jira. Here's what it means for your own GitHub Actions pipeline.

7 min read
A welcome doormat by a front door — the world's most obvious hiding spot, and a fair metaphor for the API key baked straight into an app's network traffic.
iOS Development Security

Two-Thirds of AI iPhone Apps Hid the Key Under the Doormat

A Wake Forest study ran 444 AI-powered iOS apps through traffic analysis and found 282 of them leaking their own LLM API keys — OpenAI, Anthropic, cloud creds, the works. Stolen keys fuel 'LLMjacking' that can burn $46,000 a day on someone else's bill. Here's why it keeps happening and how to ship AI features with zero secrets in your bundle.

8 min read
A giant wooden Trojan horse standing outdoors — the gift you wheel through your own gates, the way a poisoned error report walks straight into your coding agent.
AI Coding Security

Agentjacking: The Call Is Coming From Inside Your Coding Agent

A new attack class called agentjacking hides malicious instructions inside Sentry error events. When you tell Claude Code or Cursor to 'fix the unresolved errors,' the agent reads the trap over MCP and runs the attacker's commands — with your privileges. 2,388 orgs were exposed, the success rate was 85%, and Sentry says it's 'technically not defensible.'

9 min read
A red padlock resting on a black computer keyboard, symbolizing broken digital security
Vibe Coding Security

Lovable Called Their Data Leak 'Intentional Behavior.' It Got Worse From There.

Lovable, the $6.6 billion vibe coding darling, just had its worst week. A researcher proved that 5 API calls from a free account could access anyone's source code, database credentials, and customer data. Lovable's response? A masterclass in how not to handle a security crisis.

8 min read