Install
Security & Privacy Engineering
AppSec, threat modeling, SBOMs, secrets, SAST/DAST, authN/Z, and privacy by design.
- 4 Subtopics
- 14 Tracked terms
- Last 30 days Feed window
Inside Security & Privacy Engineering
What this topic collects on
An article joins this feed when it matches these terms. Each one is also a search of its own.
Related topics
- Languages & Runtimes
- Editors, IDEs & Developer Experience
- Frontend Web
- Backend & APIs
- Data, Databases & Streaming
- DevOps, CI/CD & Platform Engineering
- Testing & Quality
- Architecture & Patterns
- AI/ML Engineering & LLMOps
- Collaboration & Project Management
- Open Source & Licensing
- Careers, Learning & Events
Latest in Security & Privacy Engineering
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
2+ day, 11+ hour ago (728+ words) Researchers at cybersecurity startup AIR found and reported the flaw, which they are calling Plugin4Shell, to the vendors concerned, and most of them have now released a patch for it, the researchers wrote in a blog post on Thursday. It’s “a…...
Why software supply-chain management matters more in the AI era
32+ min ago (598+ words) AI did not invent software supply-chain risk. It accelerated how fast untrusted code, models, and packages enter your build graph—often with weaker review than a human-written dependency. You still need the boring control plane: where packages resolve from, who…...
An AI Coding App Was Silently Uploading Your Entire Git History: Inside the ZCode Incident
1+ hour, 4+ min ago (854+ words) If you use an AI coding assistant, you already accept that it sees the code in your current task. What you probably do not expect is for the app to package your entire repository, including every commit you have ever…...
I Built a Self-Hosted AI Engineering Team That Won't Push Code Without My Approval
17+ hour, 24+ min ago (262+ words) Coding agents are good at writing code and bad at knowing when they're wrong. I've watched an agent confidently ship a broken change, add a dependency that was published 20 hours ago, or quietly leak a secret into a commit message....
Most supply chain security tools react. They scan your `package-lock.json` or `go.sum`, fl
20+ hour, 26+ min ago (295+ words) Most supply chain security tools react. They scan your package-lock.json or go.sum, flag known vulnerabilities, and let you decide whether to upgrade. By the time Snyk or Dependabot alerts you, the dependency is already in your codebase. If…...
The Codebase Told Me It Was Sensitive. They Shipped It Publicly Anyway.
19+ hour, 10+ min ago (30+ words) Sometimes the most convincing proof that a leak matters isn’t your own argument — it’s the target’s own code …...
Plugin4Shell: Your AI Coding Agent's "Pinned" Dependency Was Never Actually Pinned
1+ day, 8+ hour ago (458+ words) You pin a plugin to a commit SHA because you did the review, you trust that exact code, and you never want it to silently change. That's the entire point of pinning. Last week, security researchers at AIR proved that…...
Your AI Coding Agent Can Be Attacked by the Repository It Opens
1+ day, 13+ hour ago (785+ words) Don't run code from a repository you don't trust. But AI coding agents are creating a slightly different security problem. Sometimes, you don't need to manually run the malicious code. Your coding agent may interact with the repository for you....
WebAuthn Passkey Recovery: Fallbacks and Backup Codes in Node.js
1+ day, 21+ hour ago (301+ words) Stay up to date with AI tools, model releases, and developer workflows that matter. Weekly. Free. One click to leave. Phishing-resistant authentication only works if the recovery path is also phishing-resistant, or at minimum does not reintroduce a phishable secret…...
Vibe coding names a mood. The job is Language Modeler.
1+ day, 17+ hour ago (329+ words) This started as a comment under Giorgi Kobaidze's "Vibe Coding Isn't the Problem. Calling It... Tagged with ai, programming, softwareengineering, discuss....