Data Safety and Information Security

Data Safety and Information Security

Superbacked — Protect what matters most
Superbacked — Protect what matters most
Whether you are planning for tomorrow or the unthinkable, Superbacked helps the right people recover what matters.
·superbacked.com·
Superbacked — Protect what matters most
Identity for the Pico Engine
Identity for the Pico Engine
Version 1.5 of the Pico Engine finally brings identity into the engine itself: passkeys for humans, and OAuth for external apps and webhooks. Here's the shape of the design, why identity is really three problems and not one, and why I shipped the human and third-party layers before the pico-to-pico layer.
·windley.com·
Identity for the Pico Engine
Pico-to-Pico Identity Arrives
Pico-to-Pico Identity Arrives
Version 1.6 of the Pico Engine ships the pico-to-pico identity layer I promised but hadn't built. Every pico now carries two DIDs: a portable codedid:webvh/code that says who it is, and a private codedid:peer/code for each relationship it forms. This is the piece that lets a pico move between engines and lets two meshes create a relationship without a federation agreement set up in advance.
·windley.com·
Pico-to-Pico Identity Arrives
The Pressure Behind Identity's Diseconomies of Scale
The Pressure Behind Identity's Diseconomies of Scale
Eve Maler argues that identity's apparent diseconomies of scale are really about gnarliness, not size. That gnarliness has a shape I drew for chapter 19 of my forthcoming book: the gap between a growing decision surface and the infrastructure meant to govern it. That gap is authorization pressure, and it explains why identity gets harder even when a team does everything right.
·windley.com·
The Pressure Behind Identity's Diseconomies of Scale
Why Not SPIFFE for Pico Identity?
Why Not SPIFFE for Pico Identity?
A pico is arguably just a workload, so why give it a DID instead of using SPIFFE, the standard workload identifier? The answer comes down to whether the identity is meant to last. SPIFFE derives a workload's identity from what it is and where it runs, so it's re-minted per environment; a pico's identity is long-lived and travels with it.
·windley.com·
Why Not SPIFFE for Pico Identity?
Trust nothing, ship safely: surviving the supply chain attack era by Evil Martians
Trust nothing, ship safely: surviving the supply chain attack era by Evil Martians
Supply chain attacks are no longer theoretical — they're a daily reality. npm packages, including some of the most widely used libraries in the ecosystem, have been weaponized to compromise thousands of developers at once. This talk is about getting ahead of it. Nina Torgunakova will demo Multiocular — the open-source tool built at Evil Martians for reviewing dependency changes — on two real updates: one harmless, one malicious. You'll see what actually separates them once you stop trusting the version number and start looking at the diff. By the end, you'll know how to ask the one question that matters about everything you depend on: why do I trust this?
·evilmartians.com·
Trust nothing, ship safely: surviving the supply chain attack era by Evil Martians
Problem loading page
Problem loading page
Tom Ritter's personal homepage, where he rambles about tech-related topics.
·ritter.vg·
Problem loading page
Mapping AI-enabled cyber threats \ Anthropic
Mapping AI-enabled cyber threats \ Anthropic
We’ve spent the past year investigating how threat actors are weaponizing AI to conduct cyber operations. Today, we’re sharing a new analysis that maps these real-world attacks onto the MITRE ATT&CK framework, a database of tactics and techniques used by cyberattackers.
·anthropic.com·
Mapping AI-enabled cyber threats \ Anthropic
friTap Documentation
friTap Documentation
Comprehensive SSL/TLS traffic analysis and key extraction tool
·fkie-cad.github.io·
friTap Documentation
Prompt Injection: An AI-Targeted Attack
Prompt Injection: An AI-Targeted Attack
For a brief window of time in the mid-2010s, a fairly common joke was to send voice commands to Alexa or other assistant devices over video. Late-night hosts and others would purposefully attempt t…
·hackaday.com·
Prompt Injection: An AI-Targeted Attack
Clone This Repo and I Own Your Machine
Clone This Repo and I Own Your Machine
Indirect prompt injection in agentic coding tools can lead to full system compromise because authorized tools allow LLMs to run shell commands, access files, and make network calls without clear user visibility. An attacker can gain code execution using a completely normal looking repository by chaining trusted setup instructions, routine error handling, and automated agent behavior. The malicious payload does not exist in the repository at all and is instead fetched at runtime from a DNS TXT record, making it invisible to code review, static scanners, and even the agent itself. The result is a reverse shell running as the developer’s own user, exposing credentials, API keys, and allowing persistence, all triggered by the agent attempting to fix a harmless looking setup error.
·0din.ai·
Clone This Repo and I Own Your Machine
On Lazy Secrets Management · @radekmie’s take on IT and stuff
On Lazy Secrets Management · @radekmie’s take on IT and stuff
If you’re lazy like me, consider doing the bare minimum and do not keep plain text secrets in your repo. Here’s a basic workflow that encrypts them with SSH keys.
·radekmie.dev·
On Lazy Secrets Management · @radekmie’s take on IT and stuff
Security Tip: Have You Heard Of Slopsquatting?
Security Tip: Have You Heard Of Slopsquatting?
[Tip #132] Your AI agent hallucinates a package name, confidently installs it, and keeps working - except an attacker registered that exact name, packed with malware. Welcome to slopsquatting.
·securinglaravel.com·
Security Tip: Have You Heard Of Slopsquatting?
How Do You Know When an AI Agent Has Gone Rogue? | Built In
How Do You Know When an AI Agent Has Gone Rogue? | Built In
Discover why traditional guardrails fail to stop AI agent breaches. This deep dive analyzes the 5 stages of agent failure — from prompt injection to memory poisoning — and why execution must remain deterministic.
·builtin.com·
How Do You Know When an AI Agent Has Gone Rogue? | Built In
OpenAPI Security Schemes Explained
OpenAPI Security Schemes Explained
The OpenAPI specification can seem quite complex. It is a large document with many details and edge cases to keep in mind, especially if…
·medium.com·
OpenAPI Security Schemes Explained
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.
·bobdahacker.com·
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
The Fable 5 Export Controls Harm US Cyber Defense
The Fable 5 Export Controls Harm US Cyber Defense
Restricting Fable and Mythos has the same unintended consequence of harming defense while doing nothing to impede attackers. We can't export control our way to cyber resilience.
·lutasecurity.com·
The Fable 5 Export Controls Harm US Cyber Defense
Hacking Google with A.I. for $500,000
Hacking Google with A.I. for $500,000
What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found.
·brutecat.com·
Hacking Google with A.I. for $500,000
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid…
·krebsonsecurity.com·
Who Runs the Ransomware Group ‘The Gentlemen?’