Vulnerabilities, hardening and incident write-ups.
6 posts
AgentMail's AgentID lets AI agents sign in to apps as their own inbox over plain OpenID Connect, and tells registered apps which human owns each agent.
I gave this blog a WebMCP search tool to see what Chrome's agent API takes in practice: the code, the Chrome 153 quirks, who calls it, and why WebKit says no.
A single HTTP/2 connection from a home laptop can pin tens of gigabytes of server RAM in seconds. How the AI-discovered HTTP/2 Bomb works and how to defend.
High-severity (CVSS 8.6) SSRF in the Next.js WebSocket upgrade handler lets unauthenticated attackers proxy GETs to internal services on port 80.
On May 11, 2026, attackers published 84 malicious versions across 42 @tanstack/* npm packages. Here is how to detect compromise and recover safely.
Malicious LiteLLM versions were published to PyPI on March 24, 2026. Here's what happened, how to check if you're affected, and what to do.