// Topic

Security

Security2026.07.075 min

OpenSSH 10.4 Hardens The Quiet Path

OpenSSH 10.4 is not a flashy remote-access release. It is the kind operators should notice anyway: stricter sandbox failure behavior, tighter rekey handling, SFTP and SCP security fixes, and a cautious post-quantum signature experiment.

Tundrabit
Security2026.05.314 min

VPN Cookies Became Keys

Palo Alto's exploited GlobalProtect bug is a reminder that convenience cookies on edge VPNs are not just session helpers. In the wrong configuration, they become perimeter keys.

Tundrabit
AI2026.05.305 min

MCP Tools Need Risk Labels

MCP tool annotations are becoming the vocabulary agents need for safer tool use, but labels only help when clients pair them with real policy, identity, and runtime controls.

Tundrabit
AI2026.05.293 min

Open Source Gets A Clearinghouse

IBM and Red Hat's Project Lightwell points to a new phase of open source security: AI can find more bugs, but enterprises now need a coordinated system for verified fixes.

Tundrabit
Security2026.05.254 min

Deleted Keys Still Work

Aikido measured Google API keys authenticating for up to 23 minutes after deletion. That turns credential revocation from a button into a timed incident-response window.

Tundrabit
Security2026.05.254 min

The npm Trust Signal Broke

Mini Shai-Hulud turned trusted publishing, CI cache reuse, and developer credentials into one continuous attack path. The fix is not less automation. It is stricter boundaries around the automation we already rely on.

Tundrabit
End of list