sufield/stave
Stave finds compound attack paths that single-resource scanners miss. AWS security findings from configuration snapshots - no credentials required.
Stave finds compound attack paths that single-resource scanners miss. AWS security findings from configuration snapshots - no credentials required.
Our blog grew from 84 posts to 1,360 in a day. Then I read one live page instead of the source, counted tags, and found two elements on 500 of them. Both halves of the code were correct. Their sum was not, and no...
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application...
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of...
From the floor of HumanX, Ryan welcomes Songyee Yoon, managing partner at Principal Venture Partners (PVP), to chat about AI development outside the US, from the need to adapt models to local languages and culture to...
Browser extension that protects you from phishing and malicious websites.
"Should we use AppSheet or Apps Script?" is the wrong question - and I've watched teams waste weeks arguing it. They're not competitors. AppSheet delivers a UI; Apps Script runs logic. Most production setups I build...
Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies...
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
How attackers took twenty thousand Instagram accounts by asking Meta's AI politely, and why that failure is about to become common. ...
An IP list of bad actors targeting public infra like website, ssh endpoints, etc.
A peek into building my shopping assistant app with Streamlit and Python. Yesterday I ran into a couple of interesting tracebacks (NameError during TTS audio generation and API key config). Debugging is 80% of a...
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password...
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]
Your semantic layer is a risk mitigation strategy. Not risk in the abstract, compliance-framework sense, but the practical, operational risk that quietly drains organizations every day.. ...
OpenFGA SDK for Java - https://central.sonatype.com/artifact/dev.openfga/openfga-sdk
Understanding Java Virtual Threads: Lightweight Concurrency in Modern Java Java 21 introduced one of the most significant changes to the platform's concurrency model in years: virtual threads , delivered as part of...
CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM) , that updates and replaces...
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
Ryan welcomes WPEngine CTO Ramadass Prabakar to the show to chat about what happens-and what we should do-when agents start acting like humans online, how our internet is evolving to serve both human and agentic...
Enterprise-ready zero-trust access platform built on WireGuard®.
As we have seen, models are conceptually quite simple: a list of input messages goes in and the model predicts the next token repeatedly to form the output message. It can't reach the internet or your database or...
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted...
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix...
Introducing new Stack Internal capabilities as part of our upcoming platform experience. Our latest release turns your existing foundation of knowledge into enterprise memory that your people, teams, and AI agents...
A blocklist file for blocking ads, trackers and malware domains.
Introdução Esse cluster é diferente dos outros três: ele não previne um tipo de bug, ele sustenta a capacidade de manter os outros nove princípios ao longo do tempo. A segunda lei de Lehman, a Lei da Complexidade...
View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a...
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent...
The tools themselves are new and their capabilities are in constant flux. If your kitchen knife kept changing shape, weight, and edge, you'd have to relearn it every time; that's a hard tool to build trust in. But it...
Phoenix is a suite of configurations & advanced modifications for Mozilla Firefox, designed to put the user first - with a focus on privacy, security, freedom, & usability.
Introdução A restrição já está posta pelo artigo: a Lei da Mudança Contínua de Lehman (1974) - todo sistema em uso real será solicitado a mudar, indefinidamente, e a única pergunta em aberto é se essa mudança sai...
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation...
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
Ryan is joined by Asaf Savich, Komodor's AI Engineering Group Manager, to discuss why modern reliability work requires navigating massive cross-service context, what good context engineering actually likes when AI is...
Open-source guardrails between AI agents and FHIR clinical data - PHI redaction, immutable audit, step-up auth, tenant isolation. MCP server + OpenAI/Gemini adapters. A healthclaw.io project.
Introdução Como já dito anteriormente: A restrição: quando o comportamento de uma função depende de estado invisível no momento da leitura (uma variável global, um efeito colateral escondido atrás de uma "consulta"...
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems...
In this No Dumb Questions, Stack's Director of Data Science Michael Foree teaches Phoebe about AI context, context engineering, and what she can do to become a better context engineer. ...
List of Fresh DNS resolvers updates every 1 hour
Every dashboard project I have taken on was described to me as a front end problem. Charts, filters, a date range picker, maybe a CSV export. Then you open the codebase and find out the charts were never the problem....
View CSAF Summary Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The following versions...
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]
Ryan welcomes VoidZero's Evan You and Cloudflare's Dane Knecht back to the show to discuss Cloudflare's recent acquisition of VoidZero and what it means for JavaScript development, how partnerships like theirs can...
An OAuth2 and OpenID Connect Debugger
Lucide, Tabler Icons, and Phosphor are three of the most recommended open-source icon libraries, and they come up together in almost every "which icon set should I use" thread. All three are permissively licensed...
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756...
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
Live from Snowflake Summit, Ryan talks with Snowflake's Head of Developer Experience Umesh Unnikrishnan about the industry-wide shift from "vibe coding" for quick prototypes to agentic engineering for enterprise...
Browser extension and iOS app that spoofs your gps, geolocation & timezone, and auto-syncs to your VPN. Firefox, Chrome, Edge, Brave & Safari.
A message landed in my inbox a few months back. New scope, same title. Frontend, backend, and QA, folded into one role, because the team now had AI to cover the rest. I had shipped backend work for years. The...
View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The...
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code...
At MS Build, Ryan is joined by Cassidy Williams, Senior Director of Developer Advocacy at GitHub and former Stack Overflow Podcast host, to discuss how agentic coding is shifting dev work towards higher-level...
This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_URL, https://freedium.cfd/Medium_URL
A note before you read: I'm a Scrum Master, not a titled Product Owner. What follows is my own product thinking, applied to a domain I know well from sitting close to subscription billing systems in my day-to-day...
CI Fortify - Advice for isolating vital systems CI Fortify - Advice for isolating vital systems (PDF) CISA and the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), in collaboration with...
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones...
Recorded at Microsoft Build, Ryan welcomes Sarah Bird, Microsoft's Chief Product Officer for Responsible AI, about how we can build and use AI responsibly with the NIST approach, why most irresponsible AI comes from...
View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has...
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]
Live from Microsoft Build, Ryan is joined by Jay Parikh, Microsoft's VP of AI Core, for a conversation on what enterprises need to build, deploy, and run AI agents at scale with demonstrable ROI; how Microsoft built...
View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are...
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
Ryan is joined by Rosemary Wang, Developer Advocate at IBM, to explore what infrastructure-as-code looks like once AI starts writing and deploying it. ...
View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for...
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
Ryan welcomes Saahil Jain, CTO of You.com, to discuss why building agents with a 2024 mindset is a mistake as modern models improve at long-horizon tasks, why heavy orchestration layers can hurt model performance...
View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted...
Signature-based detection has always known what it was looking for. Machine learning and autonomous agents are changing the question entirely, shifting from "does this match a known pattern?" to "does this actually...
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The...
Ryan welcomes Benny Chen, co-founder of Fireworks AI, to the show to explore what actually makes an AI application good or not, how to balance qualitative signals with quantitative metrics when evaluating AI, and how...
View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870...
Vivek Raghunathan, SVP of engineering at Snowflake, joins Leaders of Code at Snowflake Summit to break down the five-stage framework his org used to go from "let chaos reign" to a repeatable, org-wide system for AI...
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected...
Ryan sits down with Frank Portman, CTO at Yobi, to talk about why next-token prediction, though great for language, isn't the right inductive bias for forecasting human behavior. They discuss how Yobi builds a...
CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners...
If you want your values to spread throughout the industry, the best thing you can possibly do is succeed and make others want to imitate you. ...
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following...
Ryan sits down with Anish Agarwal, CEO and co-founder of Traversal, to chat about why AI coding agents have made writing code easier but running it safely in production harder, why production failures are really...
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected...
Read original for full source context.
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)...
Once again, we're asking for your help to take the temperature of software development. ...
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions...
Ryan is joined by Jeffrey Hightower, VP of Places Data at Microsoft, and Amy Rose, CTO of the Overture Maps Foundation, to chat about their partnership in bringing spatial data to the next generation of Microsoft...
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is...
Designing contract-bound AI agents for high-stakes execution. ...
View CSAF Summary Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely....
Ryan welcomes Cricket Liu, DNS expert and Chief Evangelist at Infoblox, to the show to talk all things DNS. They cover the evolution of one of the oldest DNS server implementations, BIND, and what the future holds...
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an...
Engineering teams have upgraded their tools. Have they upgraded how they work? ...
View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are...
Recorded live at the AI Agent Conference, Ryan sits down with Apollo GraphQL CEO Matt DeBergalis to discuss how enterprises can leverage GraphQL and MCP as a structured semantic architecture to feed clean data to...
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor...
Read original for full source context.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider...
Read original for full source context.
Capacity is one of the hardest problems because it sits at the knotty, gnarled-up intersection of so many other hard problems. ...
Ryan welcomes Trisha Gee, a Java champion and developer productivity advocate, to explore how AI is transforming the role of IDEs and the broader developer experience; the relevance of traditional tools, muscle...
On this episode of Leaders of Code, Eric Anderson, director of engineering at Intuit, joins Stack Overflow engineering director Ben Matthews to talk about what happens to software teams when AI makes code generation...
If your coding agent has questions, Stack Overflow for Agents has answers, now in beta. ...
Ryan welcomes Bryan Clark, director of product for Lakebase at Databricks, to discuss what happens when AI agents become the primary creators and users of databases; why agents are "sloppy" about cleaning up...
AI reliability issues stem from three separate architectural challenges that keep getting lumped into the same category. Prompt engineering alone can't fix them. But the sourcing and verification frameworks media...
Ryan welcomes back Tanya Janca, now part of the OWASP Top 10 team, to discuss what changed in the latest OWASP Top 10 release, how the list shifted from "outdated components" to a broader software supply chain focus...
Let's take a moment to shout out all the articles we're seen posted so far and encourage folks reading to reach out about your own. ...
In this two-for-one special recorded at HumanX, Ryan is joined by Dataiku's Florian Douetteau to chat about the governance, orchestration, and data requirements for serious agentic systems and 1Password's Nancy Wang...
If AI is the new power tool for developers, is there still value in artisanal craft when anyone can be a builder? ...