security

Tag

Cards List
#security

@dps: I’ve seen a couple of posts about this so wanted to demystify. Today, every Muse user gets a free computer in the cloud…

X AI KOLs Following ↗ · 3h ago Cached

Muse users now have access to a free secure virtual computer in the cloud, offering full transparency and control similar to a personal Linux system while ensuring safety from threats.

0 favorites 0 likes
#security

GitHub has not removed malicious imitation software after 3 weeks

Hacker News Top ↗ · 4h ago Cached

An author reported malicious imitation software containing malware on GitHub, but GitHub failed to remove it for three weeks despite multiple reports, only taking action after the incident gained attention on Hacker News.

0 favorites 0 likes
#security

Forging 1024-bit RSA signatures in nearly SNFS time

Lobsters Hottest ↗ · 5h ago Cached

This paper presents a method for forging 1024-bit RSA signatures with complexity close to the Special Number Field Sieve algorithm, highlighting a potential security risk in widely used cryptographic systems.

0 favorites 0 likes
#security

Giving a database agent read-only that the database enforces, not a regex over the SQL

Reddit r/AI_Agents ↗ · 5h ago

The author shares lessons learned from adding a natural-language-to-SQL assistant to an open-source database client, focusing on challenges with local models like schema selection and the need for database-enforced read-only access to prevent semantically incorrect queries.

0 favorites 0 likes
#security

nobody talks about this: a cloud agent needs a copy of your logins just to exist

Reddit r/AI_Agents ↗ · 7h ago

The article discusses the security issue with cloud agents requiring login credentials and advocates for a local agent approach on macOS that runs in the user's browser, allowing monitoring and control despite trade-offs like needing the machine to be awake.

0 favorites 0 likes
#security

There's a new way to break RSA that's faster than anything we've seen before

Ars Technica ↗ · 9h ago Cached

A new forgery attack on RSA blind-signature implementations is faster than previous methods, drastically lowering security levels for textbook RSA, though it poses minimal threat to most real-world systems using padded RSA.

0 favorites 0 likes
#security

How do you handle API keys when an AI agent needs access to multiple external services?

Reddit r/AI_Agents ↗ · 12h ago

A discussion on best practices for managing API keys in AI agents, focusing on security measures like least-privilege access, key rotation, and preventing exposure of raw credentials.

0 favorites 0 likes
#security

GitHub added local sandboxing to Copilot. Does this make you more comfortable letting agents run unattended?

Reddit r/AI_Agents ↗ · 16h ago

GitHub has added local sandboxing to Copilot to limit potential damage from coding agents, but the update raises questions about whether it sufficiently addresses trust for unattended operation.

0 favorites 0 likes
#security

@Miles_Brundage: Important new report:

X AI KOLs Timeline ↗ · 19h ago Cached

Geoffrey Irving highlights the NDIST report on formal methods for security, noting that the scale-up problem has shifted to market coordination among hardware and software makers.

0 favorites 0 likes
#security

VSCode's SSH Agent Is Bananas

Hacker News Top ↗ · 23h ago Cached

The article discusses security concerns with VSCode's SSH agent, comparing it to Emacs' Tramp and highlighting risks in development environments.

0 favorites 0 likes
#security

@dabit3: Agents that escape locally get access to your whole machine, while ones that escape in the cloud essentially get only a…

X AI KOLs Timeline ↗ · 23h ago Cached

The tweet highlights why cloud agents are inevitable by contrasting local and cloud environments, where local agent escapes provide full machine access, while cloud escapes only grant access to empty tenants.

0 favorites 0 likes
#security

Prompting your agent to "be careful with links" does nothing

Reddit r/AI_Agents ↗ · yesterday

An AI agent was tested with a phishing link and followed it without suspicion. The article details four practical security checks to prevent such threats, emphasizing tool-layer implementation for robust agent safety.

0 favorites 0 likes
#security

Sandboxing with minimal effort

Lobsters Hottest ↗ · yesterday Cached

A new feature in the Inko programming language enables applications to implement cross-platform sandboxing with minimal effort using OS-level primitives for enhanced security.

0 favorites 0 likes
#security

GitHub Actions leaking secrets when Miri output is cached

Lobsters Hottest ↗ · yesterday Cached

Miri, a Rust tool, stores all environment variables in the target directory, which when cached in GitHub Actions can leak secrets to pull requests. The Rust team has implemented a fix to only preserve specific variables and advises users to check their CI setups for vulnerabilities.

0 favorites 0 likes
#security

Obscura: VPN that can't log your activity

Hacker News Top ↗ · 2d ago Cached

Obscura VPN is a privacy-focused VPN service designed to prevent activity logging by separating user identity and browsing history through a two-party protocol.

0 favorites 0 likes
#security

Meta’s New Muse AI Agent Read My Private Messages. I Never Asked It To

Reddit r/artificial ↗ · 2d ago

Meta's new AI agent, Muse, was reported to have accessed users' private messages without their consent, raising privacy and security concerns.

0 favorites 0 likes
#security

Are AI agents ready for the enterprise?

Reddit r/AI_Agents ↗ · 2d ago

The article explores whether AI agents are ready for enterprise use, highlighting the critical need for security and predictability in their deployment to prevent unauthorized actions.

0 favorites 0 likes
#security

WordPress: Unauthenticated path traversal leading to conditional RCE

Hacker News Top ↗ · 2d ago Cached

This article reports on a critical security vulnerability in WordPress that allows unauthenticated path traversal leading to conditional remote code execution, with setup instructions from the development repository.

0 favorites 0 likes
#security

Your agent just found an API key in your repo. What happens next?

Reddit r/AI_Agents ↗ · 2d ago

A coding agent unexpectedly used an available API key from a repository, leading to higher costs, which underscores the importance of credential scoping in AI agent deployments to prevent unauthorized access and cost overruns.

0 favorites 0 likes
#security

Show HN: Drop – a rootless Linux sandbox with gVisor support

Hacker News Top ↗ · 2d ago Cached

Drop is a rootless Linux sandbox tool that isolates programs and coding agents using user namespaces and optional gVisor integration, providing secure environments without container setup overhead.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback