⤷ Title: Three advisories in five days, one thing in common: transport
════════════════════════
𐀪 Author: Yusuf Enes TATAR
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:48:48 GMT
════════════════════════
⌗ Tags: #application_security #model_context_protocol #cybersecurity #mcp_server #ai_security
════════════════════════
𐀪 Author: Yusuf Enes TATAR
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:48:48 GMT
════════════════════════
⌗ Tags: #application_security #model_context_protocol #cybersecurity #mcp_server #ai_security
Medium
Three advisories in five days, one thing in common: transport
On September 11, 2026, a GitHub-reviewed advisory was published for the PyPI package mysql-mcp-server: its SSE transport validated neither…
⤷ Title: The Security Gap Nobody Talks About When They Deploy AI Agents
════════════════════════
𐀪 Author: Saumya Kasthuri
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 16:21:14 GMT
════════════════════════
⌗ Tags: #agentic_ai #llm #application_security #artificial_intelligence #ai_security
════════════════════════
𐀪 Author: Saumya Kasthuri
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 16:21:14 GMT
════════════════════════
⌗ Tags: #agentic_ai #llm #application_security #artificial_intelligence #ai_security
Medium
The Security Gap Nobody Talks About When They Deploy AI Agents
How a comment buried in a Git repository can instruct your AI to exfiltrate data — and why your existing security tools won’t catch it
⤷ Title: The Secure Code Review Challenge — Solution #5: Notekeeper (Insecure Deserialization)
════════════════════════
𐀪 Author: Mohamed AboElKheir
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 21:19:18 GMT
════════════════════════
⌗ Tags: #software_development #code_review #cybersecurity #application_security
════════════════════════
𐀪 Author: Mohamed AboElKheir
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 21:19:18 GMT
════════════════════════
⌗ Tags: #software_development #code_review #cybersecurity #application_security
Medium
The Secure Code Review Challenge — Solution #5: Notekeeper (Insecure Deserialization)
📢 The solution to Challenge #5: Notekeeper is live. Watch the video walkthrough here, or read the full write-up on GitHub.
⤷ Title: Application Security Explained: How Modern Apps Protect Users from Login to Database
════════════════════════
𐀪 Author: Shravan Srinivas
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 02:24:09 GMT
════════════════════════
⌗ Tags: #application_security
════════════════════════
𐀪 Author: Shravan Srinivas
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 02:24:09 GMT
════════════════════════
⌗ Tags: #application_security
Medium
Application Security Explained: How Modern Apps Protect Users from Login to Database
Assisted using AI
⤷ Title: TanStack Supply Chain Attack Exposes the Hidden Risk of Compromised Developer Credentials
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 14:04:48 GMT
════════════════════════
⌗ Tags: #devsecops #application_security #supply_chain_security #software_security #tanstack
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 14:04:48 GMT
════════════════════════
⌗ Tags: #devsecops #application_security #supply_chain_security #software_security #tanstack
Medium
TanStack Supply Chain Attack Exposes the Hidden Risk of Compromised Developer Credentials
Software supply chain attacks are becoming more concerning because compromising one software component can create consequences far beyond…
⤷ Title: vm2’s Sandbox Just Failed for the Third Time This Week.
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
Medium
vm2’s Sandbox Just Failed for the Third Time This Week. A Million Weekly Downloads Are Still Running It
Three separate CVSS 10.0 sandbox escapes landed days apart — in a library that was declared dead once already
⤷ Title: Case Study: Verifying Security Fixes Instead of Trusting Them
════════════════════════
𐀪 Author: David Baxter
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 19:08:58 GMT
════════════════════════
⌗ Tags: #software_engineering #devsecops #application_security #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: David Baxter
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 19:08:58 GMT
════════════════════════
⌗ Tags: #software_engineering #devsecops #application_security #cybersecurity #penetration_testing
Medium
Case Study: Verifying Security Fixes Instead of Trusting Them
A CyBax Solutions engagement summary
⤷ Title: How does a SAST scanner decide which line of code to flag?
════════════════════════
𐀪 Author: Codeunderfire
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 00:19:53 GMT
════════════════════════
⌗ Tags: #software_engineering #devsecops #static_analysis #secure_coding #application_security
════════════════════════
𐀪 Author: Codeunderfire
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 00:19:53 GMT
════════════════════════
⌗ Tags: #software_engineering #devsecops #static_analysis #secure_coding #application_security
Medium
How does a SAST scanner decide which line of code to flag?
A SAST scanner parses source code into a syntax tree, follows how values move through it, and flags the exact line where a tainted input…
⤷ Title: Your Trace Baggage Is an Outbound Data Channel
════════════════════════
𐀪 Author: Arjun Garg
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 03:36:13 GMT
════════════════════════
⌗ Tags: #distributed_systems #devops #application_security #opentelemetry #observability
════════════════════════
𐀪 Author: Arjun Garg
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 03:36:13 GMT
════════════════════════
⌗ Tags: #distributed_systems #devops #application_security #opentelemetry #observability
Medium
Your Trace Baggage Is an Outbound Data Channel
OpenTelemetry baggage is useful precisely because it travels. That is also what makes it a trust-boundary problem.
⤷ Title: I Changed One Parameter… and Broke a B2B Booking System
════════════════════════
𐀪 Author: Mohtadi Romene
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 09:26:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #web_security #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Mohtadi Romene
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 09:26:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #web_security #penetration_testing #bug_bounty
Medium
I Changed One Parameter… and Broke a B2B Booking System
Introduction