Skip to content

Search

ESC

← All tags

Posts

9 min

AgentID: Sign in with Google, Except the User Is an AI Agent

AgentMail's AgentID lets AI agents sign in to apps as their own inbox over plain OpenID Connect, and tells registered apps which human owns each agent.

Read
10 min

WebMCP Hands-On: A Search Tool for Browser Agents

I gave this blog a WebMCP search tool to see what Chrome's agent API takes in practice: the code, the Chrome 153 quirks, who calls it, and why WebKit says no.

Read
20 min

HTTP/2 Bomb: Remote Memory-Exhaustion DoS (CVE-2026-49975)

A single HTTP/2 connection from a home laptop can pin tens of gigabytes of server RAM in seconds. How the AI-discovered HTTP/2 Bomb works and how to defend.

Read
23 min

CVE-2026-44578: Next.js WebSocket SSRF

High-severity (CVSS 8.6) SSRF in the Next.js WebSocket upgrade handler lets unauthenticated attackers proxy GETs to internal services on port 80.

Read
9 min

TanStack npm Supply Chain Attack: Detect, Fix, and Recover

On May 11, 2026, attackers published 84 malicious versions across 42 @tanstack/* npm packages. Here is how to detect compromise and recover safely.

Read
5 min

LiteLLM Supply Chain Attack: How to Check If You're Affected

Malicious LiteLLM versions were published to PyPI on March 24, 2026. Here's what happened, how to check if you're affected, and what to do.

Read