Tagged articles

security

2473 articles · Page 2 of 25
Java Tech Workshop
Java Tech Workshop
Jul 22, 2026 · Backend Development

Spring Boot JWT Login Authentication with Seamless Refresh Explained

This article explains how to implement a double‑token JWT authentication scheme in Spring Boot 3.x, using short‑lived AccessTokens for API security and long‑lived RefreshTokens for seamless background renewal, while addressing token revocation, refresh thresholds, blacklist handling, and multi‑device considerations.

AuthenticationBackendJWT
0 likes · 23 min read
Spring Boot JWT Login Authentication with Seamless Refresh Explained
TonyBai
TonyBai
Jul 22, 2026 · Information Security

Storing Passkeys as a Single String and a Draft Go 1.28 crypto/passkey API

Filippo Valsorda proposes a PHC‑style one‑line Passkey record format that reuses WebAuthn authenticator data, eliminates the need for cross‑account Credential ID uniqueness checks, and includes a draft stateless crypto/passkey Go 1.28 API detailing registration and login flows.

API DesignGoPHC string
0 likes · 13 min read
Storing Passkeys as a Single String and a Draft Go 1.28 crypto/passkey API
Network Intelligence Research Center (NIRC)
Network Intelligence Research Center (NIRC)
Jul 21, 2026 · Information Security

AI Programming Era: Uncovering the Trust Crisis Behind Code Assistants

The article analyzes recent security incidents involving AI coding assistants—Claude Code's hidden location detection and the GhostApproval symlink attack—explaining how covert techniques erode trust, blur data‑command boundaries, and expose software‑supply‑chain risks for developers.

AI programmingClaude CodeGhostApproval
0 likes · 9 min read
AI Programming Era: Uncovering the Trust Crisis Behind Code Assistants
Cloud Architecture
Cloud Architecture
Jul 20, 2026 · Cloud Native

Kubernetes Authentication Time Bomb: The Evolution and Production Practices of ServiceAccount Tokens

The article explains how many teams mistakenly think they are using Kubernetes authentication while actually mounting long‑lived Bearer tokens, outlines the risks of legacy ServiceAccount tokens, describes the new projected token mechanism, and provides step‑by‑step guidance for secure production deployment and migration.

AuthenticationKubernetesProjectedVolume
0 likes · 21 min read
Kubernetes Authentication Time Bomb: The Evolution and Production Practices of ServiceAccount Tokens
MaGe Linux Operations
MaGe Linux Operations
Jul 20, 2026 · Operations

How to Quickly Spot Anomalous Requests and Attack Sources Using Nginx Logs

This article presents a step‑by‑step Nginx log‑analysis workflow that helps operators identify slow requests, 5xx spikes, CC attacks, scanners and SQL‑injection attempts by parsing access_log and error_log fields, aggregating by IP, URL, UA and time windows, and then applying rate‑limiting, map‑based blocking, geo‑blocking and firewall rules to mitigate the threats while ensuring proper log rotation and verification.

Nginxlog-analysisperformance
0 likes · 40 min read
How to Quickly Spot Anomalous Requests and Attack Sources Using Nginx Logs
AntTech
AntTech
Jul 18, 2026 · Artificial Intelligence

How Ant Group and 20+ Partners Are Building a Trustworthy Agent Ecosystem with ASL

Ant Group outlines the security challenges of scaling AI agents and describes its native‑security AgentOS platform, the ASL trust protocol, and the Avernet collaboration infrastructure, developed together with more than twenty industry partners to enable trustworthy multi‑agent interactions.

AI agentsASL protocolAgentOS
0 likes · 8 min read
How Ant Group and 20+ Partners Are Building a Trustworthy Agent Ecosystem with ASL
YiSu Grain
YiSu Grain
Jul 17, 2026 · Fundamentals

Day 24: Beyond Speed, Stability, and Security – Defining Quality Requirements with Six Elements

The article explains why vague quality goals like "fast, stable, secure" are insufficient for architecture design and shows how to turn them into measurable quality‑attribute scenarios using six fixed elements—stimulus source, stimulus, environment, artifact, response, and response metric—illustrated with concrete healthcare system examples.

Scenario Analysisavailabilitymodifiability
0 likes · 18 min read
Day 24: Beyond Speed, Stability, and Security – Defining Quality Requirements with Six Elements
Black & White Path
Black & White Path
Jul 16, 2026 · Information Security

Exploiting MySQL JDBC Deserialization: A Step‑by‑Step Analysis

The article walks through setting up a MySQL fake server, crafting a malicious JDBC URL with autoDeserialize and query interceptors, demonstrating how the MySQL JDBC driver automatically deserializes BLOB data via ObjectInputStream, and traces the call chain to show how arbitrary code can be executed during connection initialization.

JDBCMySQLdeserialization
0 likes · 7 min read
Exploiting MySQL JDBC Deserialization: A Step‑by‑Step Analysis
Ops Community
Ops Community
Jul 15, 2026 · Information Security

How to Respond When Your Server Is Brute‑Force Attacked: Practical SSH Hardening Guide

When a public server shows a flood of "Failed password" entries and rising SSH connections, this guide walks you through distinguishing brute‑force attempts from actual compromise, gathering immutable evidence, applying immediate network and host safeguards, hardening OpenSSH configuration, managing keys, deploying fail2ban, and verifying the hardened system without losing access.

Fail2banLinuxMFA
0 likes · 39 min read
How to Respond When Your Server Is Brute‑Force Attacked: Practical SSH Hardening Guide
inShocking
inShocking
Jul 15, 2026 · Artificial Intelligence

Understanding Function Calling: How AI Agents Safely Execute Tools

This article explains why AI agents need function calling, describes the structured tool‑call protocol between LLMs and runtimes, shows how to define and secure function tools, and provides best‑practice code and checklists for production deployments.

Agent RuntimeFunction CallingLLM
0 likes · 21 min read
Understanding Function Calling: How AI Agents Safely Execute Tools
JavaGuide
JavaGuide
Jul 15, 2026 · Artificial Intelligence

Alibaba’s Claude Code Alternative: A Step‑by‑Step Migration to Qoder CLI

After Claude Code accounts were banned and security concerns rose, the author details how to migrate configurations, compare features, set up models, and run real tasks with Qoder CLI, while evaluating its security certifications, multi‑model support, and practical advantages for AI programming.

AI programmingClaude CodeQoder CLI
0 likes · 17 min read
Alibaba’s Claude Code Alternative: A Step‑by‑Step Migration to Qoder CLI
CTO Full-Stack Academy
CTO Full-Stack Academy
Jul 14, 2026 · Artificial Intelligence

200 Essential AI Agent Interview Questions Explained

This article provides a comprehensive, question‑and‑answer guide covering AI Agent fundamentals, core capabilities, workflow patterns, memory architectures, tool integration, planning algorithms, reflection mechanisms, security considerations, multi‑agent collaboration, deployment strategies, and practical engineering trade‑offs, offering concrete examples and best‑practice recommendations for each topic.

AI agentReflectionmemory
0 likes · 71 min read
200 Essential AI Agent Interview Questions Explained
LuTiao Programming
LuTiao Programming
Jul 12, 2026 · Backend Development

Stop Using GPT Just to Write Code—Turn Your Spring Boot Service into an AI‑Callable Tool

Java developers should move beyond using GPT for code generation and instead expose existing Spring Boot services as secure, auditable AI tools, covering permission checks, data desensitization, tool descriptions, system prompts, and comprehensive logging to safely integrate GPT into business workflows.

AI Tool CallingAudit LoggingGPT
0 likes · 17 min read
Stop Using GPT Just to Write Code—Turn Your Spring Boot Service into an AI‑Callable Tool
Geek Labs
Geek Labs
Jul 12, 2026 · Operations

Top Ops & Security Tools: AI Alert Triage, Anti-Detection Browser, and K8s Visualization

The article reviews three open‑source solutions—OpenSRE for AI‑assisted incident investigation, CloakBrowser that patches Chromium to evade fingerprinting, and Radar, a lightweight Kubernetes dashboard that runs without cluster installation—detailing their problems, workflows, commands, and key features.

AIKubernetesbrowser automation
0 likes · 6 min read
Top Ops & Security Tools: AI Alert Triage, Anti-Detection Browser, and K8s Visualization
Black & White Path
Black & White Path
Jul 12, 2026 · Information Security

How the FBI Recovered Deleted Signal Messages from iPhone Notification Logs

Security researcher @RedHatPentester demonstrates that, despite uninstalling Signal, the FBI can extract plaintext messages from iPhone notification cache databases—a forensic flaw stemming from iOS’s write‑optimized storage that retains deleted notification previews, a risk that also affects Android devices.

AndroidSignaldata deletion
0 likes · 7 min read
How the FBI Recovered Deleted Signal Messages from iPhone Notification Logs
IT Learning Made Simple
IT Learning Made Simple
Jul 10, 2026 · Backend Development

Top 10 Architecture Design Mistakes and How to Avoid Them

This guide enumerates the ten most common architecture design mistakes—over‑design, ignoring business needs, single points of failure, premature optimization, chaotic tech stacks, tight coupling, missing monitoring, security oversights, and team capability gaps—explaining their symptoms, costly consequences, and concrete best‑practice remedies, plus checklists to keep your system robust and maintainable.

Backendarchitecturedesign pitfalls
0 likes · 11 min read
Top 10 Architecture Design Mistakes and How to Avoid Them
Ops Community
Ops Community
Jul 8, 2026 · Operations

Quick Nginx Log Analysis Techniques to Spot Abnormal Requests and Attack Sources

This article provides a step‑by‑step guide on using Nginx's custom log_format together with command‑line tools such as awk, grep, sort and jq to identify slow requests, 5xx spikes, CC attacks, scanners and SQL‑injection attempts, and then mitigates them with limit_req, map, geo and iptables rules, while also covering log rotation, monitoring and risk‑aware deployment practices.

DevOpsNginxlog-analysis
0 likes · 37 min read
Quick Nginx Log Analysis Techniques to Spot Abnormal Requests and Attack Sources
Cloud Architecture
Cloud Architecture
Jul 7, 2026 · Databases

MySQL User & Permission Management: From Grant Statements to Production-Grade Security Architecture

This comprehensive guide explains why MySQL permission mistakes happen, walks through the authentication and authorization process, shows how to design multi‑layered user models, role hierarchies, declarative GitOps workflows, Kubernetes integration, and production‑ready automation for secure, auditable, and scalable database access.

GitOpsKubernetesMySQL
0 likes · 42 min read
MySQL User & Permission Management: From Grant Statements to Production-Grade Security Architecture
JavaGuide
JavaGuide
Jul 7, 2026 · Artificial Intelligence

How Does Claude Code Detect the Skills You’ve Been Using for Months?

The article explains the technical differences between CLAUDE.md and Skill files, when to use each, their loading strategies, file structures, front‑matter fields, dynamic context, security considerations, and how Skills interact with Subagents, Plugins and Agent Teams in Claude Code.

AI SkillsAgent ArchitectureClaude Code
0 likes · 19 min read
How Does Claude Code Detect the Skills You’ve Been Using for Months?
Code of Duty
Code of Duty
Jul 5, 2026 · Operations

Beyond Specs: The Hidden Ongoing Costs When Programmers Buy a Server

The article explains that while developers often focus on CPU, memory, and price when purchasing a cloud server, the true long‑term viability depends on renewal fees, bandwidth, disk space, backup, security, and cognitive overhead, all of which affect sustainable maintenance.

backupbandwidthcloud server
0 likes · 9 min read
Beyond Specs: The Hidden Ongoing Costs When Programmers Buy a Server
Cloud Architecture
Cloud Architecture
Jul 4, 2026 · Backend Development

Production-Ready SMS Verification Login System: Security Countermeasures and Engineering

This article presents a comprehensive guide to building a production-grade SMS verification login system, covering threat modeling, multi-layer rate limiting, state management with Redis, asynchronous message handling, multi‑provider routing, token issuance and operational monitoring to ensure security, cost control, and high availability.

OutboxRedisSMS verification
0 likes · 36 min read
Production-Ready SMS Verification Login System: Security Countermeasures and Engineering
AI Architecture Hub
AI Architecture Hub
Jul 4, 2026 · Artificial Intelligence

Why Vertical Domain‑Specific Agents Will Dominate Enterprise AI

The article argues that by 2027 enterprise AI will shift from monolithic, all‑purpose agents to a composition of many small, domain‑specific agents, reducing token waste, cutting costs up to 137×, and solving integration, security, and scalability challenges.

AI agentsAgent OrchestrationComposition
0 likes · 16 min read
Why Vertical Domain‑Specific Agents Will Dominate Enterprise AI
Geek Labs
Geek Labs
Jul 4, 2026 · Artificial Intelligence

Astrid: An OS Built for AI Agents, Not Just Another Framework

Astrid is a Rust‑written operating system for AI agents that replaces traditional Python‑based frameworks by introducing immutable “capsules”—isolated WASM or native processes described in Capsule.toml—allowing interchangeable providers, autonomous agents, secure multi‑model routing, and a five‑layer defense model without needing to fork the code.

AI agentsMicrokernelRust
0 likes · 10 min read
Astrid: An OS Built for AI Agents, Not Just Another Framework
dbaplus Community
dbaplus Community
Jul 4, 2026 · Operations

Harmless‑Looking Linux Commands That Can Cause Massive Damage

The article compiles a series of highly‑rated Zhihu answers that showcase seemingly innocuous Linux commands—such as chmod ‑R 666 *, rm ‑rf --no‑preserve‑root /, and the classic fork bomb :(){ :|&; }; :—and recount real‑world incidents where their execution led to system crashes, data loss, or locked‑out servers.

Linuxbashcommand line
0 likes · 5 min read
Harmless‑Looking Linux Commands That Can Cause Massive Damage
Raymond Ops
Raymond Ops
Jul 3, 2026 · Operations

10 Rookie Ops Mistakes You Must Avoid – A Complete Checklist

This guide walks ops newcomers through the ten most common pitfalls—from accidental rm‑rf deletions and mis‑configured firewalls to unsafe chmod usage—and provides concrete remediation steps, ready‑to‑run shell scripts, best‑practice checklists, and monitoring setups to keep production environments stable and secure.

DevOpsLinuxmonitoring
0 likes · 51 min read
10 Rookie Ops Mistakes You Must Avoid – A Complete Checklist
Raymond Ops
Raymond Ops
Jul 3, 2026 · Operations

Practical Guide to Diagnosing and Fixing NFS Mount Failures

This guide explains the NFS protocol, common mount failures, five root‑cause categories, step‑by‑step installation, configuration, verification, detailed error analysis, real‑world case studies, performance tuning, automation scripts, best‑practice recommendations and monitoring techniques for reliable NFS deployments on Ubuntu 24.04 and Rocky Linux 9.5.

AutomationLinuxMount
0 likes · 52 min read
Practical Guide to Diagnosing and Fixing NFS Mount Failures
Tencent Cloud Developer
Tencent Cloud Developer
Jul 3, 2026 · Artificial Intelligence

Deep Architectural Review of WorkBuddy: The New Paradigm for AI Office Agents

WorkBuddy, launched by Tencent Cloud in March 2026, is a zero‑setup AI agent that turns chat into execution by offering three operation modes, a three‑layer memory system, multi‑model switching, a skill marketplace, multi‑agent collaboration, automated scheduling and a secure sandbox, and its performance is evaluated across code development, stock analysis and content creation scenarios, highlighting both strengths and current limitations.

AI agentAutomationSkill Marketplace
0 likes · 13 min read
Deep Architectural Review of WorkBuddy: The New Paradigm for AI Office Agents
Raymond Ops
Raymond Ops
Jul 2, 2026 · Information Security

Linux Security Hardening in Practice: 20 Essential Configurations Explained

This comprehensive guide walks you through Linux system hardening by outlining default settings, common pitfalls, and a step‑by‑step checklist of 20 critical configurations covering account policies, SSH, firewall, kernel parameters, file permissions, and audit logging, complete with verification commands, rollback procedures, and real‑world case studies.

LinuxSSHaudit
0 likes · 37 min read
Linux Security Hardening in Practice: 20 Essential Configurations Explained
AgentGuide
AgentGuide
Jul 2, 2026 · Artificial Intelligence

What Are the Components and Interaction Flow of MCP in AI Agents? A Complete Guide

The article explains MCP (Model Context Protocol) as a standardized interface for AI agents, detailing its architecture (Host, Client, Server), three core types (Tools, Resources, Prompts), transport options (Stdio and Streamable HTTP), security best practices, and how it differs from function calling.

AI agentFunction CallingMCP
0 likes · 6 min read
What Are the Components and Interaction Flow of MCP in AI Agents? A Complete Guide
IT Services Circle
IT Services Circle
Jul 1, 2026 · Information Security

Why Claude Code Bans Users: Hidden Code Targeting Chinese Users Unveiled

A reverse‑engineered analysis reveals that Claude Code silently tags Chinese users by reading the system timezone and a custom API endpoint, then embeds covert steganographic markers—altered date separators and special Unicode quotes—into each request, allowing Anthropic to identify and block them without extra network traffic.

APIAccount BanningAnthropic
0 likes · 10 min read
Why Claude Code Bans Users: Hidden Code Targeting Chinese Users Unveiled
21CTO
21CTO
Jun 30, 2026 · Artificial Intelligence

OpenClaw vs. Hermes: Unified AI Agent Definition, Divergent Control Mechanisms

The article compares the open‑source AI agent frameworks OpenClaw and Hermes, showing they share a common definition of agents but differ fundamentally in control architecture—OpenClaw centers on a multi‑channel gateway while Hermes prioritizes persistent memory—while also discussing governance, security, and adoption trade‑offs.

AI agentsHermes AgentOpenClaw
0 likes · 13 min read
OpenClaw vs. Hermes: Unified AI Agent Definition, Divergent Control Mechanisms
Shuge Unlimited
Shuge Unlimited
Jun 30, 2026 · Artificial Intelligence

Is gstack’s 118K Stars Earned by Real Engineering or Just Markdown? A Deep Source‑Code Dive

This article dissects the gstack open‑source project—its 117,967 GitHub stars, 170k+ lines of TypeScript, a persistent Chromium daemon, a dual‑engine architecture, six‑layer prompt‑injection defenses, and a sprint‑style workflow—to determine whether its popularity stems from solid engineering or merely a collection of Markdown files.

AI workflowGstackbrowser automation
0 likes · 36 min read
Is gstack’s 118K Stars Earned by Real Engineering or Just Markdown? A Deep Source‑Code Dive
Niu Liu
Niu Liu
Jun 29, 2026 · Big Data

Designing a Real‑Time Data Warehouse Backend with Flink and Paimon for SMBs

The article walks through the architecture and core workflow of a lightweight real‑time data warehouse built on Flink and Paimon, covering service‑layer refactoring, CDC task lifecycle, dual Flink submission modes, metadata synchronization, and layered security measures for small‑to‑medium enterprises.

CDCFlinkPaimon
0 likes · 11 min read
Designing a Real‑Time Data Warehouse Backend with Flink and Paimon for SMBs
Wu Shixiong's Large Model Academy
Wu Shixiong's Large Model Academy
Jun 29, 2026 · Artificial Intelligence

Why Adding an MCP Server to Claude Code Isn’t Just a Simple Plug‑In (Interview Answer Scores 60)

The article explains Claude Code's Model Context Protocol (MCP), how to connect external servers, the hidden costs and trust implications, the tool‑search lazy‑loading mechanism that prevents context overload, and the three security risks you must manage, all illustrated with real‑world examples and a four‑step interview answer.

AI integrationClaude CodeMCP
0 likes · 24 min read
Why Adding an MCP Server to Claude Code Isn’t Just a Simple Plug‑In (Interview Answer Scores 60)
Java Backend Technology
Java Backend Technology
Jun 29, 2026 · Backend Development

When AI Generates Code, How to Eliminate Zombie Dependencies with Maven

The article explains why modern Java projects must treat Maven dependency management as essential, shows how transitive vulnerable dependencies and unused "zombie" libraries bloat builds, and provides concrete Maven‑dependency‑plugin commands to visualize, analyze, and clean the dependency tree, improving security and build speed.

CI/CDJavaMaven
0 likes · 9 min read
When AI Generates Code, How to Eliminate Zombie Dependencies with Maven
Code Mala Tang
Code Mala Tang
Jun 28, 2026 · Artificial Intelligence

Claude Code Hooks: The Overlooked Execution Gate Explained

This article dissects Claude Code Hooks, showing how they differ from CLAUDE.md suggestions, detailing their event system, configuration layers, merging rules, real‑world examples, and a ready‑to‑use hook that protects production files from accidental modification.

AI AutomationClaude CodeHooks
0 likes · 21 min read
Claude Code Hooks: The Overlooked Execution Gate Explained
Linyb Geek Road
Linyb Geek Road
Jun 28, 2026 · Artificial Intelligence

12 Pitfalls I Learned While Building AI Skills Over Six Months

Over the past half‑year the author built dozens of AI Skills, discovering twelve common traps—from over‑relying on prompts and bloated skill sets to vague descriptions, hidden token costs, knowledge placement, security gaps, and the need for proper evaluation—offering concrete guidance to avoid them.

AI SkillsAgentevaluation
0 likes · 11 min read
12 Pitfalls I Learned While Building AI Skills Over Six Months
Old Zhang's AI Learning
Old Zhang's AI Learning
Jun 27, 2026 · Artificial Intelligence

GPT-5.6 Unveiled: Massive Power, Tiered Pricing, and Limited Access

OpenAI's GPT-5.6 arrives with three tiered models (Sol, Terra, Luna), new max and ultra reasoning modes, benchmark breakthroughs in programming, biology, and security, extensive multi‑layer safety guards, a steep pricing structure, and a tightly controlled preview rollout.

AI modelGPT-5.6benchmark
0 likes · 11 min read
GPT-5.6 Unveiled: Massive Power, Tiered Pricing, and Limited Access
Data Party THU
Data Party THU
Jun 26, 2026 · Artificial Intelligence

A Practical Guide to Loop Engineering: 14 Steps to Automate Repetitive Tasks

This article presents a 14‑step, evidence‑based guide for building Loop Engineering systems, explaining when to adopt loops, the five core components (Automations, Worktrees, Skills, Connectors, Sub‑agents), how to construct a minimal, safe loop, and the common failure modes and security risks to watch.

AI AutomationAgentDevOps
0 likes · 10 min read
A Practical Guide to Loop Engineering: 14 Steps to Automate Repetitive Tasks
Shuge Unlimited
Shuge Unlimited
Jun 26, 2026 · Artificial Intelligence

Taming Chaotic AI Agent Skills with skill-mcp: versioning, rollback, and orchestration

The article examines how AI agents accumulate scattered skills, outlines the problems of discoverability, version control, and secure sharing, and shows how the open‑source skill‑mcp project treats each skill as a versioned, permission‑controlled package with three deployment modes, lightweight pipeline orchestration, and built‑in security checks.

AI agentMCPdeployment
0 likes · 16 min read
Taming Chaotic AI Agent Skills with skill-mcp: versioning, rollback, and orchestration
AI Architecture Path
AI Architecture Path
Jun 26, 2026 · Artificial Intelligence

How Omnigent Unified Scheduling Gained 4,000+ Stars in 5 Days for Multi‑Agent Coding

The article analyzes the fragmented workflow of using multiple AI coding agents, introduces Omnigent's meta‑harness that unifies Claude Code, Codex, Cursor and others, details its architecture, core capabilities, installation steps, security controls, known limitations, and compares it with single‑agent setups.

AI agentsClaude CodeCodex
0 likes · 15 min read
How Omnigent Unified Scheduling Gained 4,000+ Stars in 5 Days for Multi‑Agent Coding
Code Mala Tang
Code Mala Tang
Jun 25, 2026 · Artificial Intelligence

30 Core Concepts Every AI Agent Engineer Must Master

Understanding the timeless principles behind AI agents—rather than chasing the latest frameworks—requires mastering 30 core concepts, from the fundamental Think‑Act‑Observe loop and state management to configuration files, workflow caching, sandboxing, and multi‑agent orchestration, enabling predictable, cost‑effective, and secure automation.

AI agentsAgent Architectureprompt engineering
0 likes · 21 min read
30 Core Concepts Every AI Agent Engineer Must Master
AI Agent Super App
AI Agent Super App
Jun 24, 2026 · Operations

Will AI Replace Ops Engineers by 2025? From Automated Troubleshooting to One‑Click Deployments

The article examines how AI is reshaping operations—from instant fault detection and 47‑second incident resolution to natural‑language deployment scripts, predictive capacity planning, continuous security monitoring, and automated knowledge bases—while arguing that engineers will transition from fire‑fighters to system designers.

AIOpsAutomationcapacity planning
0 likes · 15 min read
Will AI Replace Ops Engineers by 2025? From Automated Troubleshooting to One‑Click Deployments
TechVision Expert Circle
TechVision Expert Circle
Jun 24, 2026 · Operations

Avoid the 5 Hidden Pitfalls When Deploying Enterprise AI Agents (Part 2)

The article analyzes five often‑overlooked pitfalls that emerge when scaling enterprise AI agents to production—mis‑chosen orchestration architecture, lack of tool‑level circuit breaking, state‑splitting among multiple agents, absent evaluation frameworks, and unclear security boundaries—offering concrete causes and practical mitigation strategies.

AI agentsCircuit BreakingLangGraph
0 likes · 13 min read
Avoid the 5 Hidden Pitfalls When Deploying Enterprise AI Agents (Part 2)
Raymond Ops
Raymond Ops
Jun 23, 2026 · Information Security

Linux Intrusion Detection and Incident Response: A Practical Guide to Security Event Investigation

This guide walks through building a layered intrusion detection system on Linux, comparing HIDS tools such as AIDE, rkhunter, and auditd, detailing installation, configuration, baseline management, automated response scripts, forensic data collection, monitoring, and best‑practice hardening for effective security event investigation and remediation.

AIDELinuxauditd
0 likes · 48 min read
Linux Intrusion Detection and Incident Response: A Practical Guide to Security Event Investigation
Hacker Afternoon Tea
Hacker Afternoon Tea
Jun 22, 2026 · Cloud Native

Run Multica Self‑Hosted with Three Commands: Safely Launch Three Containers

The article explains how to self‑host Multica using a three‑container Docker Compose setup—PostgreSQL, backend, and frontend—detailing secure defaults, health‑checked service dependencies, advisory‑lock‑based migrations, loopback port bindings, and two launch methods (official images or local builds) that let you start the system with just three commands.

DockerMulticaPostgreSQL
0 likes · 14 min read
Run Multica Self‑Hosted with Three Commands: Safely Launch Three Containers
TonyBai
TonyBai
Jun 21, 2026 · Industry Insights

When AI Triggers ‘Oh Shit’ Moments: Opening the Divine Gate or Falling into a Black‑Box Hell?

A Hacker News thread collected thousands of developers’ shocking AI “Oh Shit” stories—from rescuing a bricked 1990s piano and a frozen Christmas boiler to AI agents deleting production databases, fabricating recoveries, and flooding forums with fake expert comments—highlighting both AI’s miraculous potential and its lurking black‑box risks.

AI agentsDevOpsGenerative AI
0 likes · 11 min read
When AI Triggers ‘Oh Shit’ Moments: Opening the Divine Gate or Falling into a Black‑Box Hell?
IT Services Circle
IT Services Circle
Jun 20, 2026 · Industry Insights

Linus Says AI Is Just a Tool: “Atmosphere Programming” Works for Throwaway Code but Not for 35‑Year Projects

In a candid Open Source Summit interview, Linus Torvalds explains how AI has boosted Linux commit activity by about 20%, helps uncover bugs, yet floods maintainers with duplicate vulnerability reports, prompting new disclosure policies and highlighting the limits of AI for long‑term, heavily maintained software.

AIDeveloper ToolsLinux
0 likes · 32 min read
Linus Says AI Is Just a Tool: “Atmosphere Programming” Works for Throwaway Code but Not for 35‑Year Projects
AI Agent Super App
AI Agent Super App
Jun 20, 2026 · Operations

Complete LNMP Guide: Deploy WordPress and Forums Step‑by‑Step

This guide walks you through installing a full LNMP stack on CentOS or Ubuntu, configuring Nginx, MySQL, and PHP, deploying WordPress with essential plugins and security hardening, and setting up popular forums such as phpBB, Flarum, and Discourse, followed by performance tuning tips.

ForumLNMPMySQL
0 likes · 21 min read
Complete LNMP Guide: Deploy WordPress and Forums Step‑by‑Step
TechVision Expert Circle
TechVision Expert Circle
Jun 19, 2026 · Artificial Intelligence

Avoid the Top 5 Pitfalls When Deploying Enterprise AI Agents (Part 1)

The article shares hard‑won lessons from three enterprise‑grade AI Agent projects, detailing five common pitfalls—over‑reliance on a single agent, insecure direct model calls, latency and cost overruns, hallucinations, and lack of observability—and provides concrete architectural and operational solutions for each.

AI agentsAgent ArchitectureCost Management
0 likes · 10 min read
Avoid the Top 5 Pitfalls When Deploying Enterprise AI Agents (Part 1)
Black & White Path
Black & White Path
Jun 19, 2026 · Information Security

Must‑Know High‑Risk Vulnerabilities in 2026HW

The article compiles a series of screenshots that enumerate the high‑risk vulnerabilities affecting the 2026HW platform, providing readers with a visual reference of each issue as reported by the Computer and Network Security public account.

2026HWVulnerabilityhigh‑risk
0 likes · 1 min read
Must‑Know High‑Risk Vulnerabilities in 2026HW
Coder Trainee
Coder Trainee
Jun 17, 2026 · Artificial Intelligence

AI Agents: Future Outlook and Best Practices (Final Episode)

The final installment reviews the current AI agent ecosystem, forecasts emerging standards such as MCP and A2A, consolidates best‑practice guidelines for development, prompting, tool design, cost control and security, lists common pitfalls with debugging tips, and recaps the twelve‑episode series with a roadmap for further skill advancement.

AI agentscost optimizationdebugging
0 likes · 8 min read
AI Agents: Future Outlook and Best Practices (Final Episode)
Chen Tian Universe
Chen Tian Universe
Jun 17, 2026 · Industry Insights

WeChat Pay’s AI Card: Enabling One Card for Multiple AI Agents

The article walks through the author’s hands‑on experience with WeChat Pay’s new AI‑dedicated virtual card, detailing its isolated balance, per‑transaction confirmation, and how a single card can be shared across multiple AI agents, while comparing alternative multi‑card models and discussing security implications and future directions.

AI agentsAI paymentProduct Design
0 likes · 8 min read
WeChat Pay’s AI Card: Enabling One Card for Multiple AI Agents
Programmer XiaoFu
Programmer XiaoFu
Jun 17, 2026 · Information Security

Why JWT Requires Both Access and Refresh Tokens Instead of a Single Token

The article explains the inherent trade‑off of a single JWT’s expiration time, shows how using short‑lived Access Tokens together with long‑lived Refresh Tokens resolves both security and user‑experience issues, and provides detailed backend and frontend implementation guidance.

Access TokenAuthenticationJWT
0 likes · 11 min read
Why JWT Requires Both Access and Refresh Tokens Instead of a Single Token
Raymond Ops
Raymond Ops
Jun 16, 2026 · Cloud Native

Eliminate Permission Chaos: Kubernetes RBAC Design Standards and Implementation Guide

This guide explains how to design and implement a secure, least‑privilege RBAC model for multi‑team Kubernetes clusters, covering authentication methods, role and binding definitions, concrete YAML examples, CI/CD integration, audit scripts, performance tips, backup and recovery procedures, and common troubleshooting steps.

Access ControlDevOpsKubernetes
0 likes · 35 min read
Eliminate Permission Chaos: Kubernetes RBAC Design Standards and Implementation Guide
Su San Talks Tech
Su San Talks Tech
Jun 16, 2026 · Artificial Intelligence

Mastering Claude Code Hooks and SDK: A Step‑by‑Step Guide

This article explains how Claude Code hooks work, walks through configuring PreToolUse and PostToolUse hooks, shows concrete JSON and Node.js examples for protecting sensitive files, automating type checks, preventing duplicate queries, and demonstrates how the Claude Code SDK can be integrated into larger AI‑driven development workflows.

AI AutomationClaude CodeHooks
0 likes · 20 min read
Mastering Claude Code Hooks and SDK: A Step‑by‑Step Guide
Black & White Path
Black & White Path
Jun 16, 2026 · Information Security

Automated Penetration Testing with Claude AI: A Natural‑Language‑Driven End‑to‑End Attack Chain

This article demonstrates how Claude Desktop, connected to a Model Context Protocol (MCP) server on Kali Linux, can be instructed with plain English to run real Kali tools, perform reconnaissance, exploit vulnerabilities, crack credentials, compromise a WordPress site, and ultimately obtain domain‑admin rights on a Windows Server 2019, while also presenting mitigation measures for each step.

AI AutomationClaude AIKali Linux
0 likes · 23 min read
Automated Penetration Testing with Claude AI: A Natural‑Language‑Driven End‑to‑End Attack Chain
Cloud Architecture
Cloud Architecture
Jun 15, 2026 · Cloud Native

20 Hard‑Core Kubernetes Production Ops Tips to Keep Your Cluster Healthy

This article presents a checklist of 20 concrete Kubernetes production‑operation techniques, covering resource management, deployment safety, traffic isolation, state handling, observability, security, and disaster recovery, to ensure clusters are not only functional but truly ready for reliable production releases.

KubernetesProduction Opsdeployment
0 likes · 35 min read
20 Hard‑Core Kubernetes Production Ops Tips to Keep Your Cluster Healthy
DeepNoMind
DeepNoMind
Jun 15, 2026 · Information Security

How Alibaba’s Trusted Apps Enabled a Phishing Scam via Xianyu QR and Alipay

A victim scanned a Xianyu product‑share QR code that launched a chain through Xianyu, Taobao, and Alipay, loading a fake Xianyu page hosted on Qianwen’s CDN; because all domains were whitelisted, no external‑link warnings appeared, exposing systemic trust‑chain risks in the Alibaba ecosystem.

AlibabaAlipayXianyu
0 likes · 16 min read
How Alibaba’s Trusted Apps Enabled a Phishing Scam via Xianyu QR and Alipay
Coder Trainee
Coder Trainee
Jun 14, 2026 · Artificial Intelligence

Production‑Ready AI Agent Architecture: High Availability, Asynchrony, Caching, Cost & Security

After mastering core AI Agent capabilities, this article shows how to transform a prototype into a production‑grade service by covering a full architecture overview, stateless design, health‑check and graceful shutdown, asynchronous task queues, multi‑level caching, token‑cost optimization, model fallback, input/output filtering, rate limiting, monitoring, and deployment recommendations for different scales.

AI agentCachingasynchronous-processing
0 likes · 15 min read
Production‑Ready AI Agent Architecture: High Availability, Asynchrony, Caching, Cost & Security
21CTO
21CTO
Jun 14, 2026 · Operations

Homebrew 6.0.0 Release: Overhauled Third‑Party Tap Trust, Linux Sandbox, and Faster JSON API

Homebrew 6.0.0 introduces an explicit third‑party Tap trust model, replaces the YAML bottle metadata with a JSON API, adds a Bubblewrap‑based Linux sandbox, brings new commands like brew exec and parallel brew bundle, fixes three critical security bugs, and delivers noticeable performance gains across the toolchain.

HomebrewJSON APILinux Sandbox
0 likes · 9 min read
Homebrew 6.0.0 Release: Overhauled Third‑Party Tap Trust, Linux Sandbox, and Faster JSON API
Alibaba Cloud Developer
Alibaba Cloud Developer
Jun 12, 2026 · Operations

Why Open‑Source LoongSuite Pilot Is Needed as AI Coding Agents Become Core Infrastructure

The article analyzes how AI coding agents like Cursor, Claude Code, and Codex have become essential developer tools, yet suffer from almost zero observability, and explains how the open‑source LoongSuite Pilot provides a unified collection platform, semantic schema, security controls, dashboards, and ROI metrics to turn these agents into manageable infrastructure.

AI coding agentLoongSuite PilotOpenTelemetry
0 likes · 27 min read
Why Open‑Source LoongSuite Pilot Is Needed as AI Coding Agents Become Core Infrastructure
James' Growth Diary
James' Growth Diary
Jun 11, 2026 · Artificial Intelligence

Engineering AI Skills: When to Split, Tables, MCP vs HTTP, 5 Security Rules

The article outlines a practical engineering framework for AI Skills, detailing when to modularize based on line count and workflow separation, how to improve AI readability with tables and scripts, when to choose MCP servers versus simple HTTP calls, and five non‑negotiable security rules to keep Skills reliable and maintainable.

AI SkillsHTTPMCP
0 likes · 19 min read
Engineering AI Skills: When to Split, Tables, MCP vs HTTP, 5 Security Rules
PMTalk Product Manager Community
PMTalk Product Manager Community
Jun 11, 2026 · Product Management

Why Precise Requirement Descriptions Are the New Most Valuable Skill for Product Managers in the VibeCoding Era

The article explains that while AI tools like VibeCoding can quickly generate functional code, the quality and safety of the output depend entirely on a product manager's ability to write precise, context‑rich requirement documents, covering user scenarios, success criteria, failure handling, and security boundaries.

AIContext EngineeringVibeCoding
0 likes · 16 min read
Why Precise Requirement Descriptions Are the New Most Valuable Skill for Product Managers in the VibeCoding Era
Huolala Tech
Huolala Tech
Jun 10, 2026 · Information Security

Designing a Seamless, Secure CLI/SSO Auth System for Agent Skills

This article presents a token‑less, non‑exposed, multi‑user isolated CLI/SSO authentication framework for Agent‑driven Skill calls, detailing the security pain points, layered design of sso‑cli, sso‑sdk, poll‑based SSO, Feishu hook login, and future three‑dimensional access control.

AgentAuthenticationCLI
0 likes · 22 min read
Designing a Seamless, Secure CLI/SSO Auth System for Agent Skills
Tech Freedom Circle
Tech Freedom Circle
Jun 9, 2026 · Artificial Intelligence

Deep Dive into Harness’s Sandbox Infra: How Deep Agents Enable Secure AI Execution

This article provides a detailed technical analysis of Harness’s Sandbox infrastructure, explaining how Deep Agents’ sandbox backend isolates file operations and command execution, the role of the single execute() entry point, security guarantees, lifecycle management, and practical integration steps for Docker, Kubernetes, or commercial sandbox providers.

AIDeep AgentsHarness
0 likes · 39 min read
Deep Dive into Harness’s Sandbox Infra: How Deep Agents Enable Secure AI Execution
Machine Learning Algorithms & Natural Language Processing
Machine Learning Algorithms & Natural Language Processing
Jun 8, 2026 · Artificial Intelligence

Re‑evaluating the Token World of LLM Agents: A Dual‑View Economics Overview

The paper surveys the rapid growth of token consumption in LLM agents, proposes a dual‑view Token Economics framework that treats tokens as production factors, exchange media, and accounting units, and classifies optimization challenges from single‑agent efficiency to ecosystem‑level pricing, security, and future research directions.

AI Resource ManagementLLM Agentscost optimization
0 likes · 10 min read
Re‑evaluating the Token World of LLM Agents: A Dual‑View Economics Overview
Architect Chen
Architect Chen
Jun 8, 2026 · Information Security

Complete Guide to Single Sign-On: Principles, Architecture, and Flow

This article explains Single Sign-On (SSO) fundamentals, detailing its three core components—CAS Server, CAS Client, and Browser—illustrating the overall architecture and walking through the complete authentication flow from accessing a service to ticket validation.

AuthenticationCASSSO
0 likes · 4 min read
Complete Guide to Single Sign-On: Principles, Architecture, and Flow
AI Large-Model Wave and Transformation Guide
AI Large-Model Wave and Transformation Guide
Jun 7, 2026 · Industry Insights

How Palantir Transforms Knowledge Representation into an Enterprise Operating System

The article analyzes Palantir's shift from traditional OWL knowledge representation to a dynamic, secure, and AI‑enabled enterprise operating system, detailing philosophical, architectural, capability, security, AI, and business layers, and highlighting concrete upgrades and real‑world examples.

AIEnterprise OSOntology
0 likes · 12 min read
How Palantir Transforms Knowledge Representation into an Enterprise Operating System
Architect's Tech Stack
Architect's Tech Stack
Jun 7, 2026 · Artificial Intelligence

7 Proven Tricks to Supercharge Claude Code

The author shares seven practical techniques to keep Claude Code effective, including keeping CLAUDE.md concise, using Plan Mode with Shift+Tab, running parallel sessions via git worktree, enforcing validation steps, clearing stale context, restricting dangerous commands in settings, and automating repeatable tasks with a SKILL.md file.

AI coding assistantClaude CodePlan Mode
0 likes · 4 min read
7 Proven Tricks to Supercharge Claude Code
Smart Workplace Lab
Smart Workplace Lab
Jun 7, 2026 · Information Security

How to Secure Cross‑System Agent Calls with a Three‑Step Identity and Permission Routing

The article analyzes the security risks of agents using shared admin accounts for cross‑system calls and presents a three‑step method—identity mapping, dynamic session tokens, and over‑privilege circuit‑breaker—to enforce least‑privilege, reduce response time from days to minutes, and prevent data leakage.

AgentDynamic TokenIdentity Routing
0 likes · 7 min read
How to Secure Cross‑System Agent Calls with a Three‑Step Identity and Permission Routing
Raymond Ops
Raymond Ops
Jun 7, 2026 · Cloud Native

Complete Docker Container Deployment Guide: From Installation to Production Best Practices

This guide walks you through every step of Docker container deployment, covering installation, environment requirements, daemon configuration, Dockerfile best practices, multi‑stage builds, Compose orchestration, security hardening, resource limits, monitoring, troubleshooting, and production‑grade recommendations to ensure reliable, scalable services.

DevOpsDockercompose
0 likes · 41 min read
Complete Docker Container Deployment Guide: From Installation to Production Best Practices
SpringMeng
SpringMeng
Jun 5, 2026 · Artificial Intelligence

Complete 2026 Guide to Codex Best Practices

This comprehensive 2026 guide details Codex best‑practice strategies, covering AGENTS.md configuration, phased workflows, sub‑agent orchestration, memory management, security considerations, common pitfalls, installation steps, and real‑world usage scenarios to help developers maximize AI‑assisted coding efficiency.

AGENTS.mdAI workflowCodex
0 likes · 22 min read
Complete 2026 Guide to Codex Best Practices
AI Step-by-Step
AI Step-by-Step
Jun 5, 2026 · Artificial Intelligence

The Hidden Engine Powering OpenClaw: Inside Pi Agent

OpenClaw’s rapid rise as a personal AI gateway is driven by its core engine Pi Agent, which offers layered execution modes, strict security controls, filesystem‑based personalization, lightweight extensions, and an RL‑based personalization loop for continuous agent improvement.

AI agentsOpenClawPi Agent
0 likes · 5 min read
The Hidden Engine Powering OpenClaw: Inside Pi Agent
LuTiao Programming
LuTiao Programming
Jun 4, 2026 · Backend Development

Why Adding Safety Boundaries to Codex Is Essential Before Letting It Manage a Spring Boot Project

The article argues that AI coding with Codex is no longer about whether it can write code, but about the risks it introduces when it can read, modify, and execute a real Spring Boot codebase, and proposes concrete safety boundaries—read‑only analysis, scoped changes, secret protection, command tiering, worktree isolation, and mandatory explanations—to make AI a trustworthy engineering assistant.

AI codingCodexSpring Boot
0 likes · 16 min read
Why Adding Safety Boundaries to Codex Is Essential Before Letting It Manage a Spring Boot Project
dbaplus Community
dbaplus Community
Jun 4, 2026 · Operations

Why Ops Engineers Still Skip tcpdump? The Command-Line Packet Capture Powerhouse

This hands‑on guide walks you through every practical aspect of using tcpdump—from basic commands and essential filters to saving, reading, advanced flag tricks, performance tuning, security considerations, real‑world case studies, and integration with tools like tshark and Wireshark—so you can capture and analyze network traffic efficiently and safely in production environments.

Linuxbpf-filtersnetwork troubleshooting
0 likes · 22 min read
Why Ops Engineers Still Skip tcpdump? The Command-Line Packet Capture Powerhouse
Code Ape Tech Column
Code Ape Tech Column
Jun 4, 2026 · Artificial Intelligence

The Complete 2026 Guide to Codex Best Practices

An exhaustive 2026 guide walks through Codex best‑practice configuration, staged workflows, debugging tactics, context management, prompt engineering, sub‑agent usage, security safeguards, common pitfalls, typical scenarios, installation steps, and a comparison of Codex’s web, CLI, and IDE forms, all backed by official docs and community insights.

AGENTS.mdAI code generationCodex
0 likes · 25 min read
The Complete 2026 Guide to Codex Best Practices
TechVision Expert Circle
TechVision Expert Circle
Jun 3, 2026 · Industry Insights

The 6 Strategic Mistakes CTOs Make in the AI Era (And How to Avoid Them)

Since late 2024, rapid advances in large language models have reshaped every software engineering step, forcing CTOs to confront deep questions about AI usage, integration depth, and architectural evolution, yet many still fall into six costly strategic pitfalls that only become apparent months later.

AI strategyCTOLarge Language Models
0 likes · 13 min read
The 6 Strategic Mistakes CTOs Make in the AI Era (And How to Avoid Them)
JD Tech Talk
JD Tech Talk
Jun 3, 2026 · Artificial Intelligence

JoySafety: Open-Source Large Model Security Framework Joins Open Atom Foundation

In May 2026 the Open Atom Open Source Foundation announced JoySafety, an Apache‑2.0‑licensed, four‑layer large‑model security framework that delivers sub‑50 ms detection, over 95% attack interception, and supports 1B‑20B parameter models across cloud, edge, and device deployments.

AI safetyApache-2.0Generative AI
0 likes · 4 min read
JoySafety: Open-Source Large Model Security Framework Joins Open Atom Foundation
Raymond Ops
Raymond Ops
Jun 3, 2026 · Information Security

Master Linux Permissions: From 777 Pitfalls to Advanced ACL Controls

This comprehensive guide walks you through the evolution of Linux permission models, demonstrates why careless use of 777 can lead to costly breaches, and provides step‑by‑step instructions for using chmod, ACLs, SELinux, AppArmor, and container security to enforce least‑privilege access.

ACLLinuxSELinux
0 likes · 37 min read
Master Linux Permissions: From 777 Pitfalls to Advanced ACL Controls