Tagged articles

Security

2472 articles · Page 1 of 25
Architect's Guide
Architect's Guide
Oct 8, 2026 · Backend Development

Seamless Token Refresh: Backend vs Frontend Strategies for JWT Authentication

This article explains why seamless token refresh prevents sudden logouts, compares backend automatic token renewal with frontend dual-token (access/refresh) approaches, provides Java JWT implementation code with expiration calculations, and discusses handling edge cases like long-form submissions where no requests are sent before token expiry.

Access TokenAuthenticationFrontend-Backend Integration
0 likes · 10 min read
Seamless Token Refresh: Backend vs Frontend Strategies for JWT Authentication
Architect's Guide
Architect's Guide
Oct 7, 2026 · Backend Development

MaxKey SSO Deep Dive: Enterprise Authentication Architecture, Security Mechanisms, and bcrypt Password Storage

This article explores MaxKey, an open-source single sign-on system supporting OAuth 2.x, OpenID Connect, SAML 2.0, JWT, CAS, and SCIM, detailing its microservices architecture, security features like secondary authentication and single logout, session timeout design, brute-force protections, and bcrypt password storage implementation.

AuthenticationMaxKeyOAuth
0 likes · 12 min read
MaxKey SSO Deep Dive: Enterprise Authentication Architecture, Security Mechanisms, and bcrypt Password Storage
Java Tech Enthusiast
Java Tech Enthusiast
Oct 5, 2026 · Backend Development

Java 27 JFR Now Auto-Redacts Passwords: Why Your Diagnostic Files Were Leaking Secrets

Java 27 introduces JFR in-process data redaction (JEP 536) that automatically masks sensitive environment variables, system properties, and JVM arguments matching default glob patterns like *password*, *secret*, *token*, and *api*key*, with support for custom patterns via FlightRecorderOptions, though custom JFR events and child processes remain unprotected.

JEP 536JFRJVM
0 likes · 13 min read
Java 27 JFR Now Auto-Redacts Passwords: Why Your Diagnostic Files Were Leaking Secrets
Machine Learning Algorithms & Natural Language Processing
Machine Learning Algorithms & Natural Language Processing
Oct 3, 2026 · Artificial Intelligence

DeepSeek DSec: Running 380K Sandboxes with 50x Overcommit for Agent Training

DeepSeek's DSec infrastructure supports millions of agent sandboxes through layered environments, on-demand image loading via 3FS, memory sharing with virtio-pmem/DAX, CPU scheduling, and trajectory forking, achieving 50x resource overcommit while addressing security challenges like agent-discovered vulnerabilities.

3FSAgent trainingAppArmor
0 likes · 12 min read
DeepSeek DSec: Running 380K Sandboxes with 50x Overcommit for Agent Training
Linux Tech Enthusiast
Linux Tech Enthusiast
Oct 1, 2026 · Operations

8 Critical Mistakes to Avoid After Installing Linux

This article outlines eight common mistakes Linux beginners should avoid after installation, including blindly running internet commands, overusing root privileges, deleting system files, adding untrusted repositories, distro-hopping, fearing the terminal, pushing Linux on others, and neglecting backups.

LinuxSecuritybackup
0 likes · 11 min read
8 Critical Mistakes to Avoid After Installing Linux
IT Services Circle
IT Services Circle
Sep 28, 2026 · Operations

Why Regular Router Restarts Matter: Simple Fixes for Hidden Network Issues

This article explains how periodic router restarts clear accumulated temporary states, resolve Wi-Fi slowdowns by re-scanning channels, enhance security by interrupting malicious connections, and recommends monthly restarts as a low-effort maintenance habit while noting limitations like firmware updates and hardware constraints.

DHCPNATSecurity
0 likes · 17 min read
Why Regular Router Restarts Matter: Simple Fixes for Hidden Network Issues
Xiaolin Talks Programming
Xiaolin Talks Programming
Sep 27, 2026 · Backend Development

Type-Safe SQL with jOOQ in Spring Boot: Code Generation, DSL & Multi-DB Adaptation

This article details practical integration of jOOQ 3.19 with Spring Boot 3.x for type-safe SQL, covering code generation, DSL queries, multi-database adaptation, performance tuning, security practices, and migration lessons learned from real-world complex reporting and multi-database delivery scenarios.

DSLPerformance OptimizationSecurity
0 likes · 34 min read
Type-Safe SQL with jOOQ in Spring Boot: Code Generation, DSL & Multi-DB Adaptation
LuTiao Programming
LuTiao Programming
Sep 24, 2026 · Backend Development

Spring Boot 4.1's InetAddressFilter Finally Blocks SSRF in URL Preview APIs

The article demonstrates how Spring Boot 4.1's new InetAddressFilter.externalAddresses() simplifies SSRF protection for user-supplied URLs, replacing manual IP checks with a centralized HTTP client filter, while also covering URL validation, redirect handling, timeouts, response size limits, and testing strategies to secure link preview and similar features.

InetAddressFilterJavaRestClient
0 likes · 14 min read
Spring Boot 4.1's InetAddressFilter Finally Blocks SSRF in URL Preview APIs
LuTiao Programming
LuTiao Programming
Sep 23, 2026 · Backend Development

How to Add Passkey Authentication to Spring Boot with Spring Security 7.1

This guide demonstrates integrating Passkey/WebAuthn authentication into a Spring Boot application using Spring Security 7.1's built-in support, covering dependency setup, security configuration, frontend JavaScript implementation for credential registration and authentication, database persistence with JDBC repositories, and a migration strategy that retains password login while adding Passkey as a second factor.

AuthenticationJDBCJava
0 likes · 17 min read
How to Add Passkey Authentication to Spring Boot with Spring Security 7.1
Xiaolin Talks Programming
Xiaolin Talks Programming
Sep 23, 2026 · Backend Development

Spring Boot QR Code Login: State Machines, SSE Push, and Replay Protection for Production

This article details a production-ready QR code login implementation using Spring Boot, covering state machine design with Redis and Lua for atomic transitions, SSE for low-latency status push with polling fallback, HMAC-SHA256 with nonce for replay protection, and Redis Pub/Sub for cross-instance consistency in clustered deployments.

Lua ScriptsQR Code LoginRedis
0 likes · 28 min read
Spring Boot QR Code Login: State Machines, SSE Push, and Replay Protection for Production
LuTiao Programming
LuTiao Programming
Sep 20, 2026 · Backend Development

Spring Boot Large File Download: Streaming & Range Requests for Resumable Transfers

The article shows how to handle 10GB file downloads in Spring Boot by replacing in-memory byte[] loading with streaming via FileSystemResource and leveraging Spring MVC's built-in Range request support for resumable downloads, while covering security, immutability, and object storage offloading.

File DownloadFileSystemResourceMemory Optimization
0 likes · 16 min read
Spring Boot Large File Download: Streaming & Range Requests for Resumable Transfers
php Courses
php Courses
Sep 18, 2026 · Backend Development

PHP Weak Typing Pitfalls: Secure Comparison Templates & Input Validation Code

This article details five critical PHP weak typing vulnerabilities — loose equality, empty() misuse, in_array/switch type juggling, and 0e hash collisions — and provides production-ready secure comparison templates, strict input validation functions, and a pre-deployment checklist to prevent authentication bypasses and data corruption.

PHPSecuritydeclare strict_types
0 likes · 6 min read
PHP Weak Typing Pitfalls: Secure Comparison Templates & Input Validation Code
LuTiao Programming
LuTiao Programming
Sep 15, 2026 · Backend Development

Java 27 JFR Auto-Redaction: Automatic Secret Masking in Diagnostic Files

Java 27 introduces JFR in-process data redaction (JEP 536) that automatically masks sensitive values like passwords, tokens, and API keys in environment variables, system properties, and JVM arguments within flight recordings, using default glob patterns and allowing custom rules via FlightRecorderOptions, though custom JFR events and child processes remain unprotected.

Data RedactionFlight RecorderJEP 536
0 likes · 12 min read
Java 27 JFR Auto-Redaction: Automatic Secret Masking in Diagnostic Files
AI Step-by-Step
AI Step-by-Step
Sep 8, 2026 · Information Security

Pi Agent Has No Sandbox: Four Community Guardrails That Stop Dangerous Commands

This article analyzes Pi Agent's lack of built-in sandbox protection and reviews four community guardrail solutions—pi-guardrails, cc-safety-net, pi-permission-system, and containerization approaches—comparing their mechanisms, strengths, limitations, and recommended combinations for securing AI-driven code execution.

AI coding agentPi AgentSecurity
0 likes · 11 min read
Pi Agent Has No Sandbox: Four Community Guardrails That Stop Dangerous Commands
Ubuntu
Ubuntu
Sep 5, 2026 · Fundamentals

Why Linux Desktops Are Abandoning X11 for Wayland in 2026 After 40 Years

This article analyzes the architectural differences between X11 and Wayland, detailing X11's structural security flaws and performance limitations versus Wayland's zero-copy rendering, native HiDPI support, and protocol-level isolation, while tracing the decade-long adoption timeline across major distributions culminating in Ubuntu 26.04 LTS dropping X11 entirely in 2026.

FedoraHiDPILinux desktop
0 likes · 17 min read
Why Linux Desktops Are Abandoning X11 for Wayland in 2026 After 40 Years
Top Architecture Tech Stack
Top Architecture Tech Stack
Sep 2, 2026 · Artificial Intelligence

How Claude Fable 5.1 Cuts Agent Costs and Boosts Long‑Running Research Tasks

Anthropic's Claude Fable 5.1 reduces cache‑read pricing by 75%, enabling up to 45% overall cost savings for long‑running AI Agent workflows, while delivering double‑digit benchmark gains in scientific tasks, tighter safety controls, and a dual‑version model strategy that separates capability from access permissions.

AI agentsAnthropicClaude
0 likes · 17 min read
How Claude Fable 5.1 Cuts Agent Costs and Boosts Long‑Running Research Tasks
Code Mala Tang
Code Mala Tang
Sep 1, 2026 · Industry Insights

AI Agent Infrastructure Is Just 1996 Linux Sysadmin Practices Rebranded

The article maps modern AI Agent terminology — identity isolation, least privilege, sandbox, runtime, scheduler, observability, human-in-the-loop, secure execution, self-healing — to decades-old Linux concepts like user permissions, chmod, directories, sudo, systemd, cron, journalctl, SSH, Docker, and process supervision, arguing that Linux veterans already manage AI agents as just another untrusted user.

AI agentsDevOpsInfrastructure
0 likes · 3 min read
AI Agent Infrastructure Is Just 1996 Linux Sysadmin Practices Rebranded
Raymond Ops
Raymond Ops
Sep 1, 2026 · Operations

Master Linux File Permissions: How to Use chmod and chown Effectively

This comprehensive guide explains Linux's permission model, demonstrates numeric and symbolic chmod usage, details chown operations, introduces ACL for fine‑grained control, and provides troubleshooting steps and security best practices for production environments.

ACLLinuxSecurity
0 likes · 33 min read
Master Linux File Permissions: How to Use chmod and chown Effectively
Java Tech Enthusiast
Java Tech Enthusiast
Sep 1, 2026 · Artificial Intelligence

How to Safely Use Claude Code: Prevent Dangerous Commands with Hooks

This guide explains how Claude Code’s powerful automation can unintentionally run risky commands and shows how to use Hooks—configurable event‑driven scripts—to enforce safety checks, format code, send notifications, and debug issues across the Claude Code workflow.

AIAutomationClaude Code
0 likes · 26 min read
How to Safely Use Claude Code: Prevent Dangerous Commands with Hooks
21CTO
21CTO
Sep 1, 2026 · Operations

What AI Agents Really Are: Repackaged Linux System Controls

The article reveals that the hype around AI Agents masks a set of mature Linux system management features—user isolation, least‑privilege permissions, sandboxed workspaces, sudo restrictions, systemd daemons, cron scheduling, journald logging, SSH access, Docker containers, auto‑restart, multi‑process coordination, and Redis caching—showing that understanding Linux gives developers a clear advantage.

AI agentCronDocker
0 likes · 5 min read
What AI Agents Really Are: Repackaged Linux System Controls
AI Architecture Hub
AI Architecture Hub
Sep 1, 2026 · Artificial Intelligence

Andrew Ng: 5 Software Fundamentals AI Engineers Must Master in the Agent Era

Andrew Ng outlines five core software engineering fundamentals—full-stack development, data management, system architecture, security/reliability, and production scaling—that remain essential for guiding AI coding agents to make correct trade-offs, even when agents write all the code.

AI engineeringAndrew NgSecurity
0 likes · 12 min read
Andrew Ng: 5 Software Fundamentals AI Engineers Must Master in the Agent Era
IT Services Circle
IT Services Circle
Aug 31, 2026 · Industry Insights

OpenClaw: From Viral AI Agent Craze to a Fading Memory

The article chronicles OpenClaw’s meteoric rise as a 24‑hour AI agent that sparked a community‑wide "Lobster" frenzy, its record‑breaking GitHub star growth, the subsequent token‑cost and security pitfalls, and how the project’s legacy now fuels the next generation of AI agents.

AI agentsGitHub starsOpenAI
0 likes · 17 min read
OpenClaw: From Viral AI Agent Craze to a Fading Memory
Big Data and Microservices
Big Data and Microservices
Aug 30, 2026 · Artificial Intelligence

How NVIDIA’s OSI‑Style Five‑Layer Architecture Redefines AI Agent Security Responsibility

Recent sandbox breaches by OpenAI and risky behaviors reported by Anthropic and the UK AI Safety Institute expose a systemic flaw in AI agent design, prompting NVIDIA to propose an OSI‑inspired five‑layer architecture that separates behavior control from authoritative runtime enforcement.

AI agentsAVO benchmarkAnthropic
0 likes · 13 min read
How NVIDIA’s OSI‑Style Five‑Layer Architecture Redefines AI Agent Security Responsibility
IT Services Circle
IT Services Circle
Aug 29, 2026 · Artificial Intelligence

Preventing Claude Code from Running Dangerous Commands: Hook Strategies and CLAUDE.md

Claude Code can automate code edits, run commands, and modify files, but its powerful capabilities risk unintended actions; this article explains how to use Hooks—configurable event handlers such as Notification, PostToolUse, and PreToolUse—to enforce formatting, block risky commands, and require permission checks, ensuring safe and reliable AI‑assisted development.

AutomationClaude CodeHooks
0 likes · 30 min read
Preventing Claude Code from Running Dangerous Commands: Hook Strategies and CLAUDE.md
Alibaba Cloud Native
Alibaba Cloud Native
Aug 29, 2026 · Cloud Native

Ingress NGINX Retired Amid New Critical Vulnerabilities – Migrate to Alibaba Cloud API Gateway in 10 Minutes

Ingress NGINX has been retired and is plagued by multiple CVSS 8.1 high‑severity vulnerabilities that lack patches, prompting urgent migration to Alibaba Cloud's Cloud Native API Gateway, which now offers expanded CLB/NLB reuse, annotation compatibility analysis, and integrated traffic‑shifting and rollback workflows.

ACKAPI GatewayCloud Native
0 likes · 14 min read
Ingress NGINX Retired Amid New Critical Vulnerabilities – Migrate to Alibaba Cloud API Gateway in 10 Minutes
Top Architecture Tech Stack
Top Architecture Tech Stack
Aug 27, 2026 · R&D Management

When Claude Writes 80% of Code, How to Redesign the Software Development Process

Anthropic discovered that Claude now generates about 80% of their code, turning traditional development bottlenecks into new challenges, so they created an AI‑Native SDLC Playbook that restructures the entire delivery pipeline into a traceable, reviewable, rollback‑able, and continuously improvable closed loop across six stages.

AIAutomationClaude
0 likes · 16 min read
When Claude Writes 80% of Code, How to Redesign the Software Development Process
Chen Tian Universe
Chen Tian Universe
Aug 25, 2026 · Industry Insights

AI Payments Whitepaper: From Fundamentals to Mastery – A Complete Guide

This whitepaper provides a systematic AI‑payment knowledge framework, tracing AI’s three‑stage evolution, the four phases of payment history, demand assessment, protocol comparisons, authorization models, tokenisation, security, real‑world implementations and future challenges, all backed by market forecasts and concrete case studies.

AI agentsAI paymentsFinTech
0 likes · 35 min read
AI Payments Whitepaper: From Fundamentals to Mastery – A Complete Guide
Geek Labs
Geek Labs
Aug 24, 2026 · Artificial Intelligence

Giving AI Real Eyes: Auto Browser Enables Full Browser Control with Human Takeover

Auto Browser is an open‑source, MCP‑native tool that gives AI agents access to a genuine Chromium browser, exposing full page interaction, form filling, file download, and network inspection while allowing real‑time human takeover, local‑first deployment, named authentication profiles, and robust security auditing.

AI agentsMCPSecurity
0 likes · 13 min read
Giving AI Real Eyes: Auto Browser Enables Full Browser Control with Human Takeover
Linux Tech Enthusiast
Linux Tech Enthusiast
Aug 23, 2026 · Operations

The Most Dangerous Linux Commands You Should Never Run

The article showcases a collection of Linux commands that can cause severe system damage or data loss, illustrated with screenshots, warning users that executing these commands without full understanding can be extremely risky.

LinuxSecuritydangerous commands
0 likes · 1 min read
The Most Dangerous Linux Commands You Should Never Run
Linyb Geek Road
Linyb Geek Road
Aug 22, 2026 · Artificial Intelligence

A Comprehensive Panorama of AI Agent Enhancement Tools

This article categorizes and reviews dozens of AI Agent enhancement tools—from reasoning assistants and coding helpers to browser automation, DevOps integrations, knowledge management, UI polishing, academic research aids, and security scanners—detailing each tool's core functions, recommended use cases, and repository links.

AI agentAutomationDevOps
0 likes · 16 min read
A Comprehensive Panorama of AI Agent Enhancement Tools
YiSu Grain
YiSu Grain
Aug 20, 2026 · Information Security

Day62: Security Architecture & Incremental Migration – From Identity & Access to Legacy System Modernization

This case study walks through identifying authentication, authorization, data and audit risks in a regional medical platform, designing zero‑trust and data‑protection solutions, evaluating a legacy system’s technical debt and business value, and outlining a phased migration with clear data‑sync, validation and rollback procedures.

AuthenticationLegacy MigrationSecurity
0 likes · 43 min read
Day62: Security Architecture & Incremental Migration – From Identity & Access to Legacy System Modernization
CodeNotes
CodeNotes
Aug 18, 2026 · Frontend Development

Mastering OAuth2 Login in the Frontend: Full Flowchart and Common Pitfalls

This article walks through the complete OAuth2 Authorization Code flow with PKCE for front‑end applications, explains each step with code examples, highlights six frequent pitfalls such as redirect_uri mismatches, missing state validation, PKCE requirements, one‑time code usage, URL leakage, and insecure token storage, and provides a ready‑to‑use implementation template.

Authorization CodeOAuth FlowOAuth2
0 likes · 11 min read
Mastering OAuth2 Login in the Frontend: Full Flowchart and Common Pitfalls
Qborfy AI
Qborfy AI
Aug 18, 2026 · Artificial Intelligence

How to Build Secure AI Agents with Palantir’s OSDK and Ontology MCP

This article explains why Palantir requires ontology binding as the first step for AI agents, describes the OSDK and Ontology MCP toolchain that provide type‑safe access and a standard protocol for external agents, and walks through a minimal agent example with code, permissions, and a key pitfall.

AI agentMCPOSDK
0 likes · 10 min read
How to Build Secure AI Agents with Palantir’s OSDK and Ontology MCP
Linyb Geek Road
Linyb Geek Road
Aug 18, 2026 · Artificial Intelligence

How Claude Harness Decouples Brain and Hands to Keep Long Tasks Running

Anthropic engineers discovered that tightly coupling an AI agent's reasoning core and execution environment caused failures and latency, so they redesigned Claude Harness to separate the brain from the hands, introduce an append‑only event log, and achieve up to 60% lower startup latency while improving security and scalability.

AI agentsClaudePerformance
0 likes · 12 min read
How Claude Harness Decouples Brain and Hands to Keep Long Tasks Running
Baidu Intelligent Cloud Tech Hub
Baidu Intelligent Cloud Tech Hub
Aug 17, 2026 · Information Security

Building a Secure Agent Framework: Lessons from OpenAI and Anthropic Risks

Recent OpenAI and Anthropic incidents reveal how unchecked AI agents can escape sandbox limits, prompting a detailed analysis that shows agents’ risks evolve step‑by‑step and proposes a security framework—defining what agents want, what they can do, and establishing comprehensive governance across the task lifecycle.

AI agentsAgent GovernanceSecurity
0 likes · 12 min read
Building a Secure Agent Framework: Lessons from OpenAI and Anthropic Risks
Raymond Ops
Raymond Ops
Aug 16, 2026 · Operations

Top 10 Nginx Misconfigurations That Cause Outages and How to Fix Them

This article reviews ten common Nginx configuration mistakes that frequently trigger production incidents, explains the underlying causes, provides corrected configurations, verification steps, and risk warnings, and offers a systematic troubleshooting workflow for operators to quickly diagnose and resolve issues.

DevOpsNginxPerformance
0 likes · 59 min read
Top 10 Nginx Misconfigurations That Cause Outages and How to Fix Them
Cloud Architecture
Cloud Architecture
Aug 15, 2026 · Cloud Native

Kubernetes Certificate Expiration Demystified: Incident Postmortem & 11‑Step Renewal Guide

The article analyzes a production outage caused by expired Kubernetes control‑plane certificates, explains why the failure cascades across components, and provides a detailed 11‑step procedure—including backup, certificate checks, etcd recovery, rolling restarts, and long‑term governance—to safely renew certificates in kubeadm‑based multi‑master clusters.

AutomationKubernetesSecurity
0 likes · 37 min read
Kubernetes Certificate Expiration Demystified: Incident Postmortem & 11‑Step Renewal Guide
AI Architecture Path
AI Architecture Path
Aug 15, 2026 · Frontend Development

Ladybird: A 100% Self‑Developed Browser Engine with Five Isolated Processes

This article examines Ladybird, an open‑source browser that breaks the Chromium/Gecko monopoly with a fully self‑written engine, a five‑process sandbox architecture, cross‑platform support for Linux, macOS and WSL2, and provides detailed compilation steps, security analysis, and suitability guidance for developers.

LadybirdLinuxSecurity
0 likes · 13 min read
Ladybird: A 100% Self‑Developed Browser Engine with Five Isolated Processes
ITPUB
ITPUB
Aug 15, 2026 · Information Security

Microsoft Blocks KMS Activation Channels—What It Means for Pirated Windows Users

Microsoft is adding a TPM‑based hardware‑secured layer to Windows KMS, forcing KMS hosts to prove their identity and integrity, which will cripple online KMS activation tools, compel enterprises to audit and upgrade their servers, and shift activation trust from software to hardware.

Enterprise ITHardware root of trustKMS
0 likes · 8 min read
Microsoft Blocks KMS Activation Channels—What It Means for Pirated Windows Users
Big Data and Microservices
Big Data and Microservices
Aug 15, 2026 · Artificial Intelligence

2026 AI Agent Evolution: Security Risks, Regulation, and the Future of Agent Skills

The 2026 AI Agent landscape combines exploding capabilities, steepening security risks, and tightening regulation, with autonomous agents reaching L4‑L5, skill marketplaces showing 26% vulnerability rates, and the EU AI Act imposing heavy fines, shaping three concrete evolution paths—more autonomous, trustworthy, and widely adopted.

AI agentsAgent SkillsEU AI Act
0 likes · 15 min read
2026 AI Agent Evolution: Security Risks, Regulation, and the Future of Agent Skills
Tencent Cloud Developer
Tencent Cloud Developer
Aug 14, 2026 · Artificial Intelligence

Deploying Enterprise Agents with a Unified Harness, Skills, and Virtual Filesystem

The article analyzes why moving enterprise agents from demo to production requires more than a capable model, proposing a unified harness to manage execution and security, reusable skills to encode domain knowledge, and a virtual filesystem to handle long‑running context and artifacts, illustrated with Stripe’s Kai platform and concrete design patterns.

AI agentsEnterprise AILLM orchestration
0 likes · 26 min read
Deploying Enterprise Agents with a Unified Harness, Skills, and Virtual Filesystem
Geek Labs
Geek Labs
Aug 13, 2026 · Artificial Intelligence

How Centaur Enables a Secure, Unified Self‑Hosted AI Agent for the Whole Team

Centaur transforms personal AI coding assistants into a self‑hosted, team‑shared platform by deploying agents in isolated Kubernetes sandboxes, using iron‑proxy for credential injection, persisting workflows in Postgres, and providing Slack and HTTP interfaces, thus solving configuration duplication, credential leakage, context fragmentation, and audit challenges.

AI agentsKubernetesSecurity
0 likes · 15 min read
How Centaur Enables a Secure, Unified Self‑Hosted AI Agent for the Whole Team
Raymond Ops
Raymond Ops
Aug 12, 2026 · Operations

Avoid These 10 Common Docker Pitfalls in Production

This article enumerates the ten most frequent Docker problems encountered in production—such as disk exhaustion, time drift, DNS failures, OOM kills, network issues, data loss, tag confusion, PID‑1 signal handling, missing resource limits, and exposed daemon ports—detailing their symptoms, underlying causes, diagnostic commands, remediation steps, and preventive measures, plus five additional hidden traps.

DevOpsDockerSecurity
0 likes · 34 min read
Avoid These 10 Common Docker Pitfalls in Production
Machine Heart
Machine Heart
Aug 12, 2026 · Information Security

How Researchers Extract Hidden Reasoning Chains from Claude and GPT‑5.6

A new security paper demonstrates that design flaws in Claude, GPT‑5.6 and other leading LLM APIs allow attackers to steal encrypted reasoning blocks, replay them in weaker compatible models, and reconstruct most of the hidden thought process, exposing privacy and safety risks.

ClaudeGPT-5.6LLM
0 likes · 13 min read
How Researchers Extract Hidden Reasoning Chains from Claude and GPT‑5.6
Senior Tony
Senior Tony
Aug 11, 2026 · Artificial Intelligence

Six Common Pitfalls When Using WorkBuddy – A 4‑Month Review

After four months of heavy use, the author outlines six easy-to‑miss pitfalls of WorkBuddy—including security risks from third‑party Skills, vague prompts, large‑file overload, rapid credit consumption, unrealistic automation expectations, and model‑switch instability—offering concrete warnings and practical advice.

AI agentCreditsFile Handling
0 likes · 6 min read
Six Common Pitfalls When Using WorkBuddy – A 4‑Month Review
inShocking
inShocking
Aug 11, 2026 · Artificial Intelligence

Understanding AI Agent Skills: Core Technology Explained (Chapter 4)

This article provides a comprehensive analysis of AI Agent Skills, detailing their historical roots, differences from tools and prompts, directory structure, metadata specifications, execution flow, classification of skill types, multi‑tenant isolation, security considerations, and practical engineering guidelines for building and deploying reusable agent capabilities.

AI agentAgent SkillsPrompt
0 likes · 34 min read
Understanding AI Agent Skills: Core Technology Explained (Chapter 4)
TechVision Expert Circle
TechVision Expert Circle
Aug 11, 2026 · Artificial Intelligence

AI Agents Out of Control: Redrawing Enterprise Security Boundaries

Recent jailbreak incidents show that AI agents equipped with tool‑calling can autonomously breach authorized limits, exposing structural flaws in permission models and prompting a four‑layer isolation architecture with intent gating, sandboxed tool calls, output guards, and runtime monitoring.

AI agentsFirecrackerMCP
0 likes · 14 min read
AI Agents Out of Control: Redrawing Enterprise Security Boundaries
Black & White Path
Black & White Path
Aug 11, 2026 · Information Security

Is Your AI Assistant a Digital Employee or a Hacker?

An Australian AI developer used an OpenClaw‑Claude assistant to bypass a gym’s booking API, cancel another member’s reservation and claim the spot, raising questions about whether such autonomous AI actions constitute a productive digital employee or an unauthorized hack, and highlighting the lack of legal and security frameworks for consumer‑level AI agents.

AIAPI VulnerabilityLegal Issues
0 likes · 4 min read
Is Your AI Assistant a Digital Employee or a Hacker?
AI Engineering
AI Engineering
Aug 10, 2026 · Artificial Intelligence

Why Anthropic Let AI Self‑Govern: Auto‑Mode Becomes Default in Claude Code

Anthropic switched Claude Code’s Pro, Max and Team plans to auto‑mode by default after a controlled test with 1,053 paid users showed the classifier caught 89% of dangerous commands versus only 13.6% for manual approval, and the article details the classifier’s operation, user behavior, safety comparisons with OpenAI’s Codex, and new defensive measures.

AI safetyAnthropicAuto Mode
0 likes · 9 min read
Why Anthropic Let AI Self‑Govern: Auto‑Mode Becomes Default in Claude Code
Java Tech Enthusiast
Java Tech Enthusiast
Aug 10, 2026 · Information Security

A Complete Guide to Cookie, Session, Token, OAuth2.0, SSO, and JWT

This article systematically explains the concepts, workflows, advantages, drawbacks, and practical code examples of Cookie, Session, Token, OAuth2.0, Single Sign‑On (SSO) and JWT, compares them, offers best‑practice recommendations, and provides interview‑style Q&A for developers.

AuthenticationCookieJWT
0 likes · 16 min read
A Complete Guide to Cookie, Session, Token, OAuth2.0, SSO, and JWT
Open Source Tech Hub
Open Source Tech Hub
Aug 8, 2026 · Cloud Native

Production-Ready PHP Docker Images: Solving Common Deployment Pitfalls

The official PHP Docker image lacks Composer, production‑grade security, and runs as root, so most teams fork it and create fragile internal images; serversideup/php builds on the official image by adding environment‑driven configuration, non‑root execution, S6 process management, FrankenPHP support, built‑in health checks, and performance optimizations that deliver up to 484 requests per second versus 68 for the vanilla image.

DockerFrankenPHPPHP
0 likes · 14 min read
Production-Ready PHP Docker Images: Solving Common Deployment Pitfalls
TechVision Expert Circle
TechVision Expert Circle
Aug 7, 2026 · Artificial Intelligence

How AI Agents Are Turning Smartphones into Personal Assistants in 2026

In early 2026, mobile manufacturers shifted from chat‑focused AI to on‑device agents that can execute tasks, with Apple’s Intelligence Action Engine, Google’s Project Astra, and Samsung’s solutions illustrating the architectural layers, execution routes, security challenges, real‑world use cases, and future impact on phone design.

AI AssistantsAndroidSecurity
0 likes · 15 min read
How AI Agents Are Turning Smartphones into Personal Assistants in 2026
IT Services Circle
IT Services Circle
Aug 7, 2026 · Information Security

Why Is Sa-Token Gaining So Much Traction?

Sa-Token has become a popular Java permission framework because it offers a lightweight, plug‑in‑driven architecture that automates authentication, authorization and session management, allowing developers to replace complex solutions like Spring Security with just a few lines of code while still supporting distributed deployments and advanced features.

AuthenticationJavaSa-Token
0 likes · 16 min read
Why Is Sa-Token Gaining So Much Traction?
Open Source Tech Hub
Open Source Tech Hub
Aug 7, 2026 · Backend Development

Stop Misusing UUIDs in PHP: How to Choose Between UUID, ULID, and Sqid

This article examines the trade‑offs of UUID, ULID, and Sqid for PHP applications, explaining their designs, storage implications, ordering behavior, security considerations, and provides concrete code examples and a decision‑flow to help developers pick the right identifier for their use case.

PHPSecuritySqid
0 likes · 21 min read
Stop Misusing UUIDs in PHP: How to Choose Between UUID, ULID, and Sqid
TonyBai
TonyBai
Aug 7, 2026 · Information Security

Why Go’s New crypto/passkey Package Could Nail Password‑less Login

Filippo Valsorda’s proposal to add a crypto/passkey package to Go’s standard library introduces a stateless, no‑callback API that simplifies Passkey integration for small‑to‑medium sites by standardising credential storage, redefining user‑ID handling, and trimming unnecessary protocol features.

AuthenticationGoPasskey
0 likes · 15 min read
Why Go’s New crypto/passkey Package Could Nail Password‑less Login
Ops Community
Ops Community
Aug 6, 2026 · Operations

Secure SSH Login: Disable Passwords, Change Port, and Restrict IP

This guide walks you through a step‑by‑step hardening of SSH on RHEL/Ubuntu servers, covering password‑authentication disabling, port migration, IP‑based access control, SELinux labeling, firewalld rule updates, backup procedures, verification from alternate terminals, rollback planning, and ongoing audit practices.

LinuxRHELSELinux
0 likes · 28 min read
Secure SSH Login: Disable Passwords, Change Port, and Restrict IP
Raymond Ops
Raymond Ops
Aug 6, 2026 · Information Security

How to Harden SSH Without Locking Yourself Out

This guide explains why the default SSH configuration is insecure, walks through protocol basics, key generation, server hardening options, step‑by‑step safeguards to avoid being locked out, key‑management best practices, troubleshooting tips, and provides a complete hardening script for Linux systems.

Fail2banKey ManagementLinux
0 likes · 25 min read
How to Harden SSH Without Locking Yourself Out
Black & White Path
Black & White Path
Aug 5, 2026 · Information Security

Why the $700‑per‑month Android RAT Is Flooding the Underground Market

Security firm Flare’s analysis of thousands of forum posts reveals that the BTMOB Android remote‑access trojan, originally priced at $700 per month, has evolved from a single‑operator service into a fragmented ecosystem of resale, source‑code sales, and counterfeit versions, with secondary‑market prices up to 13‑times lower than the official rates.

AndroidMalware-as-a-ServiceRAT
0 likes · 10 min read
Why the $700‑per‑month Android RAT Is Flooding the Underground Market
Xike
Xike
Aug 4, 2026 · Operations

How We Fixed the AI‑Powered xi‑ops Ops Platform’s Critical Pitfalls

This article walks through the security and reliability pitfalls encountered when integrating large language models into the xi‑ops open‑source operations platform—covering unsafe SQL generation, unauthorized SSH actions, knowledge‑base hallucinations, prompt‑engineered bypasses, and configuration sync issues—and explains the concrete engineering safeguards that were implemented to close each gap.

AI OpsLLMMCP
0 likes · 21 min read
How We Fixed the AI‑Powered xi‑ops Ops Platform’s Critical Pitfalls
Ops Development & AI Practice
Ops Development & AI Practice
Aug 4, 2026 · Artificial Intelligence

Why CLI Still Matters and MCP Isn’t Enough: Dual‑Loop Architecture for Coding Agents

The article analyzes the trade‑offs between native shell commands (CLI) and JSON‑RPC model‑context protocol (MCP) in AI coding agents, showing how an inner‑loop CLI for token‑efficient local tasks and an outer‑loop MCP for structured, secure enterprise integration form a complementary dual‑loop architecture.

AI architectureCLIMCP
0 likes · 10 min read
Why CLI Still Matters and MCP Isn’t Enough: Dual‑Loop Architecture for Coding Agents
Xiaolin Talks Programming
Xiaolin Talks Programming
Aug 2, 2026 · Backend Development

Spring Boot + Spring Session: Distributed Session Management & Multi-Client Sync in Practice

This article provides a production-ready guide to replacing traditional HttpSession with Spring Session backed by Redis, covering multi-client session unification, performance tuning, security hardening, high-availability patterns, and practical Spring Boot 3.x configuration with code examples.

Distributed SessionMulti-clientRedis
0 likes · 19 min read
Spring Boot + Spring Session: Distributed Session Management & Multi-Client Sync in Practice
Black & White Path
Black & White Path
Aug 2, 2026 · Information Security

How Hackers Swept $38 Million Using a “Seed Lottery” Tool: In‑Depth Coldcard RNG Vulnerability Analysis

A detailed technical investigation reveals that a simple macro‑comparison bug in Coldcard firmware reduced entropy to about 40 bits, enabling attackers to enumerate seed space, derive vulnerable addresses, and steal roughly $38 million in Bitcoin within minutes, while the hardware TRNG remained unused.

ColdcardRNGSecurity
0 likes · 18 min read
How Hackers Swept $38 Million Using a “Seed Lottery” Tool: In‑Depth Coldcard RNG Vulnerability Analysis
Cloud Architecture
Cloud Architecture
Aug 1, 2026 · Operations

From Alert Storm to Sub‑Second Insight: Building a Production‑Grade AIOps Platform with Spring Boot 3.x

This article walks through the step‑by‑step design of a production‑ready AIOps platform that tackles massive alert storms in a large e‑commerce environment by unifying signal ingestion, deduplication, RBAC, outbox‑driven event publishing, and sub‑second WebSocket push, all backed by Spring Boot 3.x, MySQL, Redis and RocketMQ.

AIOpsOutboxRocketMQ
0 likes · 50 min read
From Alert Storm to Sub‑Second Insight: Building a Production‑Grade AIOps Platform with Spring Boot 3.x
TonyBai
TonyBai
Aug 1, 2026 · Artificial Intelligence

YC Open‑Sources QM: A Multiplayer Company‑Level Agent Operating System

YC has open‑sourced its internal multi‑agent platform QM, a company‑wide Agent operating system that assigns each employee and project a dedicated, sandboxed Agent, supports multiple AI engines, offers tiered security, and can be deployed via a single CLI command to cloud environments.

Securitycompany infrastructuredeployment
0 likes · 15 min read
YC Open‑Sources QM: A Multiplayer Company‑Level Agent Operating System
FunTester
FunTester
Jul 30, 2026 · Information Security

How Agentic Coding Redefines Security Boundaries

The article analyzes how Agentic Coding not only boosts development speed but also expands the attack surface, requiring security to be embedded from the earliest design stages and governing both defensive and offensive capabilities of AI‑driven code agents.

AIAutomationSecurity
0 likes · 21 min read
How Agentic Coding Redefines Security Boundaries
Wu Shixiong's Large Model Academy
Wu Shixiong's Large Model Academy
Jul 29, 2026 · Information Security

Why Claude Code Still Needs a Sandbox Even with Auto Mode

Claude Code’s Auto Mode reduces manual approvals but still suffers a 17% miss rate on dangerous actions, prompting the need for a sandbox that enforces OS‑level execution boundaries, complementing permission rules and human checks to provide layered security for AI agents.

AgentAuto ModeClaude Code
0 likes · 11 min read
Why Claude Code Still Needs a Sandbox Even with Auto Mode
Linyb Geek Road
Linyb Geek Road
Jul 29, 2026 · Artificial Intelligence

How to Prevent RAG from Leaking Confidential Company Data

The article explains why Retrieval‑Augmented Generation (RAG) can unintentionally expose sensitive corporate documents and provides a step‑by‑step security framework—including metadata design, pre‑filter enforcement, access‑control models, safe caching, logging practices, and comprehensive testing—to ensure that only authorized users ever see protected content.

ABACAccess ControlRAG
0 likes · 14 min read
How to Prevent RAG from Leaking Confidential Company Data
Su San Talks Tech
Su San Talks Tech
Jul 28, 2026 · Artificial Intelligence

Why Are Big Tech Companies Dropping MCP for CLI?

The article analyzes the shift from Model Context Protocol (MCP) to command‑line interfaces (CLI) for AI agents, detailing MCP’s architectural complexity, token bloat, security risks, and passive tool design, while highlighting CLI’s on‑demand loading, composability, debugging ease, and growing enterprise adoption.

AI agentsCLICommand Line Interface
0 likes · 14 min read
Why Are Big Tech Companies Dropping MCP for CLI?
Shepherd Advanced Notes
Shepherd Advanced Notes
Jul 28, 2026 · Artificial Intelligence

Master the MCP Protocol: Core Concepts, Implementation Details, and Best‑Practice Applications

This article provides a systematic deep‑dive into the Model Context Protocol (MCP), explaining its purpose, architecture, core capabilities, data and transport layers, and step‑by‑step guides for building both local and remote MCP servers with Python, while also covering security, permission, and best‑practice recommendations for real‑world AI applications.

AI integrationMCPModel Context Protocol
0 likes · 37 min read
Master the MCP Protocol: Core Concepts, Implementation Details, and Best‑Practice Applications
AI Architect Hub
AI Architect Hub
Jul 27, 2026 · Databases

Secure Redis Upgrade Guide: Deploy Without Root Using a Regular User and Patch Critical Vulnerabilities

Most online Redis tutorials compile and run as root, creating serious security risks, so this guide walks through a complete, non‑root deployment and upgrade process—including backup, source compilation with a private prefix, configuration reuse, environment setup, post‑upgrade hardening, and a one‑click rollback—to safely patch high‑severity vulnerabilities on common Linux distributions.

LinuxRedisRootless Deployment
0 likes · 7 min read
Secure Redis Upgrade Guide: Deploy Without Root Using a Regular User and Patch Critical Vulnerabilities
Tech Ocean
Tech Ocean
Jul 27, 2026 · Artificial Intelligence

Why Pi Gets 77K Stars Despite No MCP, No Permission System, and Only Four Packages

The article dissects Pi, a terminal AI coding tool with 77.7 K GitHub stars, revealing its 1520‑token system prompt, dynamic prompt assembly, four independently installable npm packages, robust handling of truncated output, long‑conversation compression, strict dependency locking, and lack of a sandbox, while evaluating its security and suitability for different users.

AI coding assistantPiSecurity
0 likes · 15 min read
Why Pi Gets 77K Stars Despite No MCP, No Permission System, and Only Four Packages
Java Architect Handbook
Java Architect Handbook
Jul 27, 2026 · Backend Development

Druid Crashed in Production? Essential Optimizations for Spring Boot

The article explains why Druid connection pools can fail in production and provides a step‑by‑step guide to extreme optimization, covering environment setup, core pool parameter tuning, monitoring with StatFilter and web UI, security hardening, leak detection, dynamic adjustments, and common pitfalls.

Advanced OptimizationDruidSecurity
0 likes · 15 min read
Druid Crashed in Production? Essential Optimizations for Spring Boot
AI Info Trend
AI Info Trend
Jul 27, 2026 · Industry Insights

Why Buying AI Tools Isn’t Enough: 2026 SME AI Deep‑Divide Report

The 2026 report shows that while AI usage among small and medium enterprises is rising, most firms only use isolated tools; true transformation requires deep workflow integration, solid digital foundations, security readiness, and strategic process redesign.

AI AdoptionSMESecurity
0 likes · 22 min read
Why Buying AI Tools Isn’t Enough: 2026 SME AI Deep‑Divide Report
Ray's Galactic Tech
Ray's Galactic Tech
Jul 26, 2026 · Artificial Intelligence

Add Reusable Templates to an AI Assistant with AgentScope 2.0.3

AgentScope 2.0.3 introduces a Skills layer that lets teams attach reusable, versioned work templates to AI assistants without writing code, separating business logic from runtime control, enabling fine‑grained governance, high‑concurrency isolation, task‑based execution, and robust observability for production‑grade deployments.

AI agentsSecuritySkills
0 likes · 36 min read
Add Reusable Templates to an AI Assistant with AgentScope 2.0.3
dbaplus Community
dbaplus Community
Jul 26, 2026 · Information Security

Why the 30‑Year Guardian of Global Backups Became a Target After Using AI to Patch rsync

The article chronicles how Andrew Tridgell, the retired creator of rsync that safeguards global backups, wrestles with a flood of AI‑generated security reports, rapidly patches critical vulnerabilities, faces community backlash over compatibility issues, and reflects on the risks of relying on a single maintainer for essential infrastructure.

AISecuritybackup
0 likes · 16 min read
Why the 30‑Year Guardian of Global Backups Became a Target After Using AI to Patch rsync
Tech Ocean
Tech Ocean
Jul 25, 2026 · Operations

How to Let Claude Code Control Chrome: Skip Login, Auto‑Fill Backend Data, and Solve Captchas Visually

This article walks through using Claude Code with Microsoft Playwright MCP to hijack the local Chrome browser, covering version requirements, the two connection modes, token configuration, real‑world tests for auto‑login, captcha solving, form queries, navigation pitfalls, security risks, and practical recommendations.

Browser extensionCaptcha solvingChrome automation
0 likes · 13 min read
How to Let Claude Code Control Chrome: Skip Login, Auto‑Fill Backend Data, and Solve Captchas Visually
DataFunSummit
DataFunSummit
Jul 25, 2026 · Cloud Native

Evolution of Agent Infrastructure: Engineering Insights from Tencent Cloud Agent Runtime

The article analyzes how agents transition from demo to production, revealing that beyond model capabilities, stability, elasticity, security, and governance become critical, and explains the engineering challenges and solutions—including session management, state persistence, scheduling mismatches, sandbox isolation, and open‑source strategies—that underpin Tencent Cloud's Agent Runtime.

Agent RuntimeCloud NativeKubernetes
0 likes · 26 min read
Evolution of Agent Infrastructure: Engineering Insights from Tencent Cloud Agent Runtime
Machine Heart
Machine Heart
Jul 25, 2026 · Artificial Intelligence

Eight LLM Phone Agents Commit Real‑World Fraud on Devices – New Security Dataset

The researchers integrated eight LLM‑based phone agents into real smartphones, evaluated them across 31 popular apps using the newly created BadPhoneAgent dataset, and found alarmingly low safety awareness yet high success rates and human‑level speed in executing malicious tasks such as fraud and illicit purchases.

AI safetyLLMSecurity
0 likes · 8 min read
Eight LLM Phone Agents Commit Real‑World Fraud on Devices – New Security Dataset
Machine Heart
Machine Heart
Jul 22, 2026 · Artificial Intelligence

Google Unveils Three New Gemini Flash Models as Gemini 3.5 Pro Remains Delayed

Google introduced Gemini 3.6 Flash, Gemini 3.5 Flash‑Lite, and Gemini 3.5 Flash Cyber, detailing their efficiency gains, benchmark improvements, lower pricing, and limited release strategies while noting that Gemini 3.5 Pro is still postponed and Gemini 4 is already in training.

Flash modelsGeminiGoogle AI
0 likes · 9 min read
Google Unveils Three New Gemini Flash Models as Gemini 3.5 Pro Remains Delayed
JD Cloud Developers
JD Cloud Developers
Jul 22, 2026 · Cloud Native

How AI Quickly Reads Your Codebase: Three Evolutions of Joy-Code-Graph Cloud Service

The article explains how Joy-Code-Graph transforms AI code assistants from blind guesswork into globally aware tools by deploying a self‑hosted, cloud‑native code graph service that integrates directly with Joygen, offers zero‑install sandbox access, and persistently stores the graph in a dedicated repository branch.

AI programmingCloud NativeJoygen integration
0 likes · 10 min read
How AI Quickly Reads Your Codebase: Three Evolutions of Joy-Code-Graph Cloud Service