How to Detect Cross-Tenant Data Leakage in MCP Servers and Multi-Tenant SaaS
The Hidden Security Gap in Multi-Tenant MCP Servers When you build a multi-tenant SaaS application…
AI tools, cybersecurity and development news aggregated from top sources — saved permanently with unique URLs.
How to Detect Cross-Tenant Data Leakage in MCP Servers and Multi-Tenant SaaS
The Hidden Security Gap in Multi-Tenant MCP Servers When you build a multi-tenant SaaS application…
GHSA-2RP4-X2J7-QMCC: GHSA-2RP4-X2J7-QMCC: Stored Cross-Site Scripting via Draft Names in Craft CMS Control Panel
GHSA-2RP4-X2J7-QMCC: Stored Cross-Site Scripting via Draft Names in Craft CMS Control Panel Vulne…
Canaries, Not Faith: Auditing Where Your Coding Agent Actually Writes
When people discuss AI agents escaping their boundaries, the mental image is usually dramatic: a jai…
What a Malicious Ollama Model Can Actually Do to Your Host, and How to Sandbox /api/pull
A malicious Ollama model is not a virus you double click, but it is untrusted input handed to a C pa…
Put a Capability Broker Between Your Agent and Its Tools
Agent incidents rarely look like a movie villain. They look like a helpful assistant combining two p…
Don't Trust-Execute AI-Generated Code: A Sandbox Harness for Evaluating Coding Models Safely
In my last post I shared a reproducible harness for comparing free hosted coding models against a lo…
Capturing Your First Web Request with Wireshark on Windows
A live packet capture in Wireshark, filtered down to a single request and response, so you can see e…
Break Your Agent on Purpose: A Failure-Injection Sandbox for Tool Boundaries
Last week a post on DEV asked a question I can't stop thinking about: we keep handing AI agents more…
Sandbox First: A Safer Local Harness for Evaluating Free Coding Models on Your Own Codebase
In my last post I walked through a reproducible baseline for comparing free LLM coding models agains…
Canary Tests for AI Coding Agents: A Sandbox Harness You Can Run Yourself
Last week I watched an AI coding agent, given a routine refactor task, cheerfully read a .env file i…
Attack Your Agent's Tool Boundaries Before Someone Else Does: A Repeatable Test Harness
A few months ago I wrote about regression-testing prompts before shipping them. The responses that s…
Before You Give a Coding Agent Shell Access, Test Where Its Boundaries Actually Are
A lot of us are now running coding agents that can read files, write files, and execute shell comman…