CVE-2026-71847: CVE-2026-71847: Use-After-Free in Ruby JSON Gem ResumableParser
CVE-2026-71847: Use-After-Free in Ruby JSON Gem ResumableParser Vulnerability ID: CVE-2026-71847 …
AI tools, cybersecurity and development news aggregated from top sources — saved permanently with unique URLs.
CVE-2026-71847: CVE-2026-71847: Use-After-Free in Ruby JSON Gem ResumableParser
CVE-2026-71847: Use-After-Free in Ruby JSON Gem ResumableParser Vulnerability ID: CVE-2026-71847 …
Designing Identity Guardrails: Input Validation vs. Risk Scoring
When building user onboarding flows, developers often face a critical architectural decision: where …
repo-guard v0.1.1: Firewall de políticas ejecutables para agentes de código — rutas, contenidos y comandos (MCP + CLI + hooks)
repo-guard v0.1.1 Firewall de políticas ejecutables para agentes de código — rutas, contenidos y c…
Supply Chain Risk in Open Model Weights
For most of the last decade, downloading a model checkpoint and loading it was equivalent to downloa…
Reply to mads_hansen: L1.9 screening (renamed from firewall), labeled corpus, MITRE ATT&CK versioning
Fair point @mads_hansen — calling L1.9 a firewall overstates what static rules can deliver. Renamin…
Reply to topstar_ai: Sentinel score, Ed25519, and external reputation factors
Thanks @topstar_ai for the kind words on the Ed25519 article. The Sentinel review score (0-10) is c…
Secrets Management for DevOps AI Agents: Credentials Without Leaks
💡 Originally published on devtocash.com — where this guide stays updated. I write hands-on DevOps/SR…
Model Extraction and Distillation Attacks
“Stealing a model through its API” describes two attacks that share nothing but a name. One recovers…
Replies to ATC feedback: canonicalization, key rotation, and the verifier contract
This is a public reply to feedback on the ATC (Agent Trust Card) posts. The dev.to API does not supp…
Replies to security architecture feedback: layered defense, runtime enforcement, and tool-surface governance
Thanks to everyone who left detailed feedback on the MarketNow security posts. The dev.to API does n…
Replies to community feedback on L1.9, L3, and the cross-agent trust stack
Thanks to everyone who left feedback on the MarketNow posts. The dev.to API does not support comment…
Data Exfiltration via Markdown Images and Links
A chat interface that renders markdown has, by default, an outbound HTTP channel that fires without …