{"articles":[{"slug":"hitl-gates-for-agent-mutations","title":"HITL gates for agent mutations","subtitle":"Verify mutations after tool calls so agents cannot declare early victory","summary":"Human-in-the-loop risk gates for refunds, inventory, and spend: classify mutations, issue system approval ids, and verify with a second read before user-facing success copy.","content_type":"blog_post","language":"en","canonical_url":"https://ansezz.com/blog/hitl-gates-for-agent-mutations/","author":{"name":"Anass Ez-zouaine","url":"https://ansezz.com/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"ansezz","url":"https://ansezz.com/","listing_slug":null,"listing":null},"topics":[{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Engineering","slug":"engineering","url":"https://listedarticles.com/topics/engineering"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Software Engineering","slug":"software-engineering","url":"https://listedarticles.com/topics/software-engineering"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":501,"reading_minutes":2,"published_at":"2026-10-02T00:00:00.000Z","added_at":"2026-10-02T00:12:41.932Z","updated_at":"2026-10-02T00:12:41.932Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/hitl-gates-for-agent-mutations","markdown_url":"https://listedarticles.com/articles/hitl-gates-for-agent-mutations.md","example":false,"citation":"Anass Ez-zouaine, ansezz. \"HITL gates for agent mutations.\" 2 Oct 2026. https://ansezz.com/blog/hitl-gates-for-agent-mutations/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://ansezz.com/blog/hitl-gates-for-agent-mutations/"},"snippet":null,"score":null},{"slug":"what-is-web-bot-auth","title":"What is Web Bot Auth?","subtitle":null,"summary":"Browserbase’s Harsehaj Dhami explains Web Bot Auth: cryptographic HTTP message signatures that let AI agents prove identity, while leaving access and reputation decisions to site owners and registries.","content_type":"blog_post","language":"en","canonical_url":"https://www.browserbase.com/blog/what-is-web-bot-auth","author":{"name":"Harsehaj Dhami","url":"https://www.browserbase.com/blog/what-is-web-bot-auth","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Browserbase","url":"https://www.browserbase.com/","listing_slug":null,"listing":null},"topics":[{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"Engineering","slug":"engineering","url":"https://listedarticles.com/topics/engineering"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":1123,"reading_minutes":5,"published_at":"2026-09-30T00:00:00.000Z","added_at":"2026-09-30T06:13:48.513Z","updated_at":"2026-09-30T06:13:48.513Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/what-is-web-bot-auth","markdown_url":"https://listedarticles.com/articles/what-is-web-bot-auth.md","example":false,"citation":"Harsehaj Dhami, Browserbase. \"What is Web Bot Auth?.\" 30 Sept 2026. https://www.browserbase.com/blog/what-is-web-bot-auth (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://www.browserbase.com/blog/what-is-web-bot-auth"},"snippet":null,"score":null},{"slug":"yet-another-ai-security-oss-externality","title":"Yet Another AI Security OSS Externality","subtitle":null,"summary":"Holden Karau recounts working AI-lab vulnerability reports during Apache Spark releases, and why AI security often externalizes cost onto open-source maintainers who lack resources to verify opaque claims.","content_type":"blog_post","language":"en","canonical_url":"https://blog.holdenkarau.com/2026/09/yet-another-ai-security-oss-externality.html","author":{"name":"Holden Karau","url":"https://blog.holdenkarau.com/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Holden's Blog","url":"https://blog.holdenkarau.com/","listing_slug":null,"listing":null},"topics":[{"name":"AI","slug":"ai","url":"https://listedarticles.com/topics/ai"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":2135,"reading_minutes":9,"published_at":"2026-09-29T00:00:00.000Z","added_at":"2026-09-30T18:15:53.209Z","updated_at":"2026-09-30T18:15:53.209Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/yet-another-ai-security-oss-externality","markdown_url":"https://listedarticles.com/articles/yet-another-ai-security-oss-externality.md","example":false,"citation":"Holden Karau, Holden's Blog. \"Yet Another AI Security OSS Externality.\" 29 Sept 2026. https://blog.holdenkarau.com/2026/09/yet-another-ai-security-oss-externality.html (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://blog.holdenkarau.com/2026/09/yet-another-ai-security-oss-externality.html"},"snippet":null,"score":null},{"slug":"hijacking-the-ps5s-rtmp-stream","title":"Hijacking the PS5's RTMP Stream","subtitle":null,"summary":"How the PS5 Broadcast RTMP pipeline can be intercepted and redirected: reverse-engineering the stream path and what that unlocks.","content_type":"blog_post","language":"en","canonical_url":"https://yashgarg.dev/posts/hijacking-ps5-rtmp-stream/","author":{"name":"Yash Garg","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"yashgarg.dev","url":"https://yashgarg.dev","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Reverse Engineering","slug":"reverse-engineering","url":"https://listedarticles.com/topics/reverse-engineering"},{"name":"Gaming","slug":"gaming","url":"https://listedarticles.com/topics/gaming"},{"name":"Networking","slug":"networking","url":"https://listedarticles.com/topics/networking"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":1016,"reading_minutes":4,"published_at":"2026-09-28T12:00:00.000Z","added_at":"2026-09-28T12:16:33.095Z","updated_at":"2026-09-28T12:16:33.095Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/hijacking-the-ps5s-rtmp-stream","markdown_url":"https://listedarticles.com/articles/hijacking-the-ps5s-rtmp-stream.md","example":false,"citation":"Yash Garg, yashgarg.dev. \"Hijacking the PS5's RTMP Stream.\" 28 Sept 2026. https://yashgarg.dev/posts/hijacking-ps5-rtmp-stream/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://yashgarg.dev/posts/hijacking-ps5-rtmp-stream/"},"snippet":null,"score":null},{"slug":"ex-arrr-sailing-the-0-click-seas","title":"EX-ARRR: Sailing the 0-click Seas","subtitle":null,"summary":"**Every serious Apple device compromise of the last decade has boring person at the bottom of it: a parser read a file and trusted it a little too much. Not a phishing link, nor a stolen password, but a daemon you never launched, decoding a file you never opened, one byte past the end of a buffer. This is that story. It starts late one evening with a fuzzer that did not know what an EXR file was, and ends with a heap overflow that fires inside a privileged Apple daemon the instant an iMessage lands evading BlastDoor’s, before the little notification banner even finishes…","content_type":"blog_post","language":"en","canonical_url":"https://ironpeak.be/blog/ex-arrr-sailing-the-0-click-seas/","author":{"name":null,"url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"IronPeak","url":"https://ironpeak.be","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Research","slug":"research","url":"https://listedarticles.com/topics/research"},{"name":"Software Engineering","slug":"software-engineering","url":"https://listedarticles.com/topics/software-engineering"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":4447,"reading_minutes":19,"published_at":"2026-09-28T00:13:43.817Z","added_at":"2026-09-28T00:13:43.817Z","updated_at":"2026-09-28T00:13:43.817Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/ex-arrr-sailing-the-0-click-seas","markdown_url":"https://listedarticles.com/articles/ex-arrr-sailing-the-0-click-seas.md","example":false,"citation":"IronPeak. \"EX-ARRR: Sailing the 0-click Seas.\" 28 Sept 2026. https://ironpeak.be/blog/ex-arrr-sailing-the-0-click-seas/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://ironpeak.be/blog/ex-arrr-sailing-the-0-click-seas/"},"snippet":null,"score":null},{"slug":"safere-1-0-released","title":"SafeRE 1.0 released","subtitle":null,"summary":"Eddie Aftandilian ships SafeRE 1.0, a linear-time Java regex library built with agents: differential testing vs the JDK, ReDoS resistance by construction, and performance that now beats JDK and RE2/J on Rebar workloads.","content_type":"blog_post","language":"en","canonical_url":"https://eaftan.github.io/safere-10/","author":{"name":"Eddie Aftandilian","url":"https://eaftan.github.io/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Eddie Aftandilian","url":"https://eaftan.github.io","listing_slug":null,"listing":null},"topics":[{"name":"Programming","slug":"programming","url":"https://listedarticles.com/topics/programming"},{"name":"Java","slug":"java","url":"https://listedarticles.com/topics/java"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Performance","slug":"performance","url":"https://listedarticles.com/topics/performance"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":1062,"reading_minutes":5,"published_at":"2026-09-28T00:00:00.000Z","added_at":"2026-10-01T06:14:14.662Z","updated_at":"2026-10-01T06:14:14.662Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/safere-1-0-released","markdown_url":"https://listedarticles.com/articles/safere-1-0-released.md","example":false,"citation":"Eddie Aftandilian, Eddie Aftandilian. \"SafeRE 1.0 released.\" 28 Sept 2026. https://eaftan.github.io/safere-10/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://eaftan.github.io/safere-10/"},"snippet":null,"score":null},{"slug":"add-runtime-controls-to-ai-agents-with-nvidia-openshell","title":"Add Runtime Controls to AI Agents with NVIDIA OpenShell","subtitle":null,"summary":"NVIDIA’s technical write-up on OpenShell: an open secure runtime that sandboxes AI agents, enforces tool/file/network policy at runtime, and pairs with hardware monitoring for containment.","content_type":"blog_post","language":"en","canonical_url":"https://developer.nvidia.com/blog/add-runtime-controls-to-ai-agents-with-nvidia-openshell/","author":{"name":"NVIDIA","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"NVIDIA","url":"https://developer.nvidia.com/","listing_slug":null,"listing":null},"topics":[{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"AI Safety","slug":"ai-safety","url":"https://listedarticles.com/topics/ai-safety"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"},{"name":"Developer Tools","slug":"developer-tools","url":"https://listedarticles.com/topics/developer-tools"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":1593,"reading_minutes":7,"published_at":"2026-09-28T00:00:00.000Z","added_at":"2026-09-28T21:17:31.787Z","updated_at":"2026-09-28T21:17:31.787Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/add-runtime-controls-to-ai-agents-with-nvidia-openshell","markdown_url":"https://listedarticles.com/articles/add-runtime-controls-to-ai-agents-with-nvidia-openshell.md","example":false,"citation":"NVIDIA, NVIDIA. \"Add Runtime Controls to AI Agents with NVIDIA OpenShell.\" 28 Sept 2026. https://developer.nvidia.com/blog/add-runtime-controls-to-ai-agents-with-nvidia-openshell/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://developer.nvidia.com/blog/add-runtime-controls-to-ai-agents-with-nvidia-openshell/"},"snippet":null,"score":null},{"slug":"grapheneos-when-an-app-is-slow","title":"GrapheneOS – When an app is slow","subtitle":null,"summary":"A GrapheneOS user digs into why OsmAnd maps feel slower on a Pixel 8 than on stock Android, and how that search led to CoMaps and broader performance trade-offs on hardened phones.","content_type":"blog_post","language":"en","canonical_url":"https://blog.wirelessmoves.com/2026/09/grapheneos-when-an-app-is-slow.html","author":{"name":"Martin Sauter","url":"https://blog.wirelessmoves.com/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"WirelessMoves","url":"https://blog.wirelessmoves.com/","listing_slug":null,"listing":null},"topics":[{"name":"Privacy","slug":"privacy","url":"https://listedarticles.com/topics/privacy"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"Performance","slug":"performance","url":"https://listedarticles.com/topics/performance"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":245,"reading_minutes":1,"published_at":"2026-09-28T00:00:00.000Z","added_at":"2026-09-28T21:17:14.893Z","updated_at":"2026-09-28T21:17:14.893Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/grapheneos-when-an-app-is-slow","markdown_url":"https://listedarticles.com/articles/grapheneos-when-an-app-is-slow.md","example":false,"citation":"Martin Sauter, WirelessMoves. \"GrapheneOS – When an app is slow.\" 28 Sept 2026. https://blog.wirelessmoves.com/2026/09/grapheneos-when-an-app-is-slow.html (all-rights-reserved)","access":{"human_view":"full","full_text_available":true,"source_url":"https://blog.wirelessmoves.com/2026/09/grapheneos-when-an-app-is-slow.html"},"snippet":null,"score":null},{"slug":"sb-923-is-law-ccpa-deletion-rights-now-reach-third-party-data","title":"SB 923 is Law: CCPA deletion rights now reach third-party data","subtitle":null,"summary":"California’s SB 923 expands CCPA deletion to data bought or appended from third parties and requires an online deletion form—what businesses need to change by January 1.","content_type":"blog_post","language":"en","canonical_url":"https://www.getprivisy.com/blog/sb-923-ccpa-right-to-delete-signed","author":{"name":"Privisy","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Privisy","url":"https://www.getprivisy.com/","listing_slug":null,"listing":null},"topics":[{"name":"Privacy","slug":"privacy","url":"https://listedarticles.com/topics/privacy"},{"name":"AI Policy","slug":"ai-policy","url":"https://listedarticles.com/topics/ai-policy"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":620,"reading_minutes":3,"published_at":"2026-09-27T00:00:00.000Z","added_at":"2026-09-28T21:17:25.303Z","updated_at":"2026-09-28T21:17:25.303Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/sb-923-is-law-ccpa-deletion-rights-now-reach-third-party-data","markdown_url":"https://listedarticles.com/articles/sb-923-is-law-ccpa-deletion-rights-now-reach-third-party-data.md","example":false,"citation":"Privisy, Privisy. \"SB 923 is Law: CCPA deletion rights now reach third-party data.\" 27 Sept 2026. https://www.getprivisy.com/blog/sb-923-ccpa-right-to-delete-signed (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://www.getprivisy.com/blog/sb-923-ccpa-right-to-delete-signed"},"snippet":null,"score":null},{"slug":"openai-agents-tried-to-bruteforce-a-un-websites-api-fields","title":"OpenAI agents tried to bruteforce a UN website's API fields","subtitle":null,"summary":"Rowan H-J documents how OpenAI agents scanned UNCTAD’s public statistics API thousands of times—proxies, obfuscation, and odd tool use—while probing API fields on a UN website.","content_type":"blog_post","language":"en","canonical_url":"https://swarmcha.se/posts/openai-unctad","author":{"name":"Rowan H-J","url":"https://swarmcha.se","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"SwarmChase","url":"https://swarmcha.se","listing_slug":null,"listing":null},"topics":[{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"AI Safety","slug":"ai-safety","url":"https://listedarticles.com/topics/ai-safety"},{"name":"Research","slug":"research","url":"https://listedarticles.com/topics/research"}],"about_listings":[{"slug":"openai","name":"OpenAI","listing_type":"company","url":"https://listedstartups.com/companies/openai"}],"cover_image_url":null,"license":"all-rights-reserved","word_count":3610,"reading_minutes":16,"published_at":"2026-09-26T12:00:00.000Z","added_at":"2026-09-27T06:22:05.662Z","updated_at":"2026-09-27T06:22:05.662Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/openai-agents-tried-to-bruteforce-a-un-websites-api-fields","markdown_url":"https://listedarticles.com/articles/openai-agents-tried-to-bruteforce-a-un-websites-api-fields.md","example":false,"citation":"Rowan H-J, SwarmChase. \"OpenAI agents tried to bruteforce a UN website's API fields.\" 26 Sept 2026. https://swarmcha.se/posts/openai-unctad (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://swarmcha.se/posts/openai-unctad"},"snippet":null,"score":null},{"slug":"how-i-couldve-accessed-17-trillion-microsoft-records","title":"How I Could've Accessed 17 Trillion Microsoft Records","subtitle":null,"summary":"A security write-up estimating ~17.3 trillion stored rows across Microsoft datasets and showing how misconfigured access paths could have exposed enormous volumes of tenant data—plus responsible disclosure notes.","content_type":"blog_post","language":"en","canonical_url":"https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records","author":{"name":"Faav","url":"https://blog.faav.net/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"blog.faav.net","url":"https://blog.faav.net/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Privacy","slug":"privacy","url":"https://listedarticles.com/topics/privacy"},{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":2086,"reading_minutes":9,"published_at":"2026-09-25T00:00:00.000Z","added_at":"2026-09-30T18:16:12.768Z","updated_at":"2026-09-30T18:16:12.768Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/how-i-couldve-accessed-17-trillion-microsoft-records","markdown_url":"https://listedarticles.com/articles/how-i-couldve-accessed-17-trillion-microsoft-records.md","example":false,"citation":"Faav, blog.faav.net. \"How I Could've Accessed 17 Trillion Microsoft Records.\" 25 Sept 2026. https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records"},"snippet":null,"score":null},{"slug":"how-cloudflare-addressed-a-cross-tenant-data-exposure-vulnerability-in-containers","title":"How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers","subtitle":null,"summary":"Cloudflare details how a Containers/Sandboxes cross-tenant bug let residual dm-thin disk blocks leak between customers, how Oren Yomtov reported it, and the fleet-wide remediation completed by 19 Sep 2026.","content_type":"blog_post","language":"en","canonical_url":"https://blog.cloudflare.com/containers-cross-tenant-vulnerability/","author":{"name":"Cloudflare","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Cloudflare","url":"https://blog.cloudflare.com/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"},{"name":"Multi-tenant","slug":"multi-tenant","url":"https://listedarticles.com/topics/multi-tenant"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":1583,"reading_minutes":7,"published_at":"2026-09-24T12:00:00.000Z","added_at":"2026-09-25T15:14:19.496Z","updated_at":"2026-09-25T15:14:19.496Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/how-cloudflare-addressed-a-cross-tenant-data-exposure-vulnerability-in-containers","markdown_url":"https://listedarticles.com/articles/how-cloudflare-addressed-a-cross-tenant-data-exposure-vulnerability-in-containers.md","example":false,"citation":"Cloudflare, Cloudflare. \"How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers.\" 24 Sept 2026. https://blog.cloudflare.com/containers-cross-tenant-vulnerability/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://blog.cloudflare.com/containers-cross-tenant-vulnerability/"},"snippet":null,"score":null},{"slug":"sourcehut-account-takeover-via-build-logs-xss-in-ansi2html-py","title":"SourceHut account takeover via build logs (XSS in ansi2html.py)","subtitle":null,"summary":"Write-up of CVE-class XSS in SourceHut’s ansi2html path: how crafted build logs could escalate to account takeover, and the fix timeline.","content_type":"blog_post","language":"en","canonical_url":"https://blog.arusekk.pl/posts/srht-account-takeover/","author":{"name":"arusekk","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"blog.arusekk.pl","url":"https://blog.arusekk.pl/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"Software","slug":"software","url":"https://listedarticles.com/topics/software"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":2518,"reading_minutes":11,"published_at":"2026-09-24T12:00:00.000Z","added_at":"2026-09-24T21:18:03.935Z","updated_at":"2026-09-24T21:18:03.935Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/sourcehut-account-takeover-via-build-logs-xss-in-ansi2html-py","markdown_url":"https://listedarticles.com/articles/sourcehut-account-takeover-via-build-logs-xss-in-ansi2html-py.md","example":false,"citation":"arusekk, blog.arusekk.pl. \"SourceHut account takeover via build logs (XSS in ansi2html.py).\" 24 Sept 2026. https://blog.arusekk.pl/posts/srht-account-takeover/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://blog.arusekk.pl/posts/srht-account-takeover/"},"snippet":null,"score":null},{"slug":"agentic-hacks-real-proofs-inside-googles-pagebreak-project","title":"Agentic Hacks, Real Proofs: Inside Google's PageBreak Project","subtitle":null,"summary":"Google's Michał Bentkowski details PageBreak, an agentic AI web security scanner that pairs LLM findings with real proof-of-concept validation to cut AI-slop noise in vulnerability reports.","content_type":"blog_post","language":"en","canonical_url":"https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/","author":{"name":"Michał Bentkowski","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"Google","url":"https://blog.google/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"AI","slug":"ai","url":"https://listedarticles.com/topics/ai"},{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Engineering","slug":"engineering","url":"https://listedarticles.com/topics/engineering"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":1157,"reading_minutes":5,"published_at":"2026-09-24T12:00:00.000Z","added_at":"2026-09-24T18:19:20.278Z","updated_at":"2026-09-24T18:19:20.278Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/agentic-hacks-real-proofs-inside-googles-pagebreak-project","markdown_url":"https://listedarticles.com/articles/agentic-hacks-real-proofs-inside-googles-pagebreak-project.md","example":false,"citation":"Michał Bentkowski, Google. \"Agentic Hacks, Real Proofs: Inside Google's PageBreak Project.\" 24 Sept 2026. https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/"},"snippet":null,"score":null},{"slug":"breaking-up-with-google-play-why-conversations-is-now-free","title":"Breaking Up with Google Play: Why Conversations Is Now Free","subtitle":null,"summary":"Daniel Gultsch recounts twelve years of Conversations on Google Play, why the XMPP client is leaving the Play Store, and what going fully free means for Android messaging and F-Droid distribution.","content_type":"blog_post","language":"en","canonical_url":"https://gultsch.de/posts/breaking-up-with-google-play/","author":{"name":"Daniel Gultsch","url":"https://gultsch.de/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"gultsch.de","url":"https://gultsch.de/","listing_slug":null,"listing":null},"topics":[{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"Android","slug":"android","url":"https://listedarticles.com/topics/android"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Privacy","slug":"privacy","url":"https://listedarticles.com/topics/privacy"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":901,"reading_minutes":4,"published_at":"2026-09-24T12:00:00.000Z","added_at":"2026-09-24T18:19:07.281Z","updated_at":"2026-09-24T18:19:07.281Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/breaking-up-with-google-play-why-conversations-is-now-free","markdown_url":"https://listedarticles.com/articles/breaking-up-with-google-play-why-conversations-is-now-free.md","example":false,"citation":"Daniel Gultsch, gultsch.de. \"Breaking Up with Google Play: Why Conversations Is Now Free.\" 24 Sept 2026. https://gultsch.de/posts/breaking-up-with-google-play/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://gultsch.de/posts/breaking-up-with-google-play/"},"snippet":null,"score":null},{"slug":"vscodes-ssh-agent-is-bananas","title":"VSCode's SSH Agent Is Bananas","subtitle":null,"summary":"Thomas Ptacek digs into VS Code's remote SSH agent flow—why LLM coding forks lean on it, how the protocol actually works, and what's bananas about the design.","content_type":"blog_post","language":"en","canonical_url":"https://fly.io/blog/vscode-ssh-wtf/","author":{"name":"Thomas Ptacek","url":null,"person_slug":"thomas-ptacek-2dqxcog64cax0","person_url":"https://listedstartups.com/people/thomas-ptacek-2dqxcog64cax0"},"authored_by":"human","publisher":{"name":"Fly.io","url":"https://fly.io","listing_slug":"fly-io","listing":{"slug":"fly-io","name":"Fly.io","listing_type":"company","url":"https://listedstartups.com/companies/fly-io"}},"topics":[{"name":"Programming","slug":"programming","url":"https://listedarticles.com/topics/programming"},{"name":"Developer Tools","slug":"developer-tools","url":"https://listedarticles.com/topics/developer-tools"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Engineering","slug":"engineering","url":"https://listedarticles.com/topics/engineering"},{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":596,"reading_minutes":3,"published_at":"2026-09-24T00:25:01.742Z","added_at":"2026-09-24T00:25:01.742Z","updated_at":"2026-09-24T00:25:01.742Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/vscodes-ssh-agent-is-bananas","markdown_url":"https://listedarticles.com/articles/vscodes-ssh-agent-is-bananas.md","example":false,"citation":"Thomas Ptacek, Fly.io. \"VSCode's SSH Agent Is Bananas.\" 24 Sept 2026. https://fly.io/blog/vscode-ssh-wtf/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://fly.io/blog/vscode-ssh-wtf/"},"snippet":null,"score":null},{"slug":"ai-powered-fuzzing-with-the-github-security-lab-taskflow-agent","title":"AI-powered fuzzing with the GitHub Security Lab Taskflow Agent","subtitle":null,"summary":"Antonio Morales walks through GitHub Security Lab’s Fuzzing Taskflow: point it at a C/C++ repo and an LLM agent writes harnesses, runs AFL++, reads coverage, triages crashes, and files reports.","content_type":"blog_post","language":"en","canonical_url":"https://github.blog/security/application-security/ai-powered-fuzzing-with-the-github-security-lab-taskflow-agent/","author":{"name":"Antonio Morales","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"GitHub","url":"https://github.blog","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"AI Agents","slug":"ai-agents","url":"https://listedarticles.com/topics/ai-agents"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"Engineering","slug":"engineering","url":"https://listedarticles.com/topics/engineering"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":2147,"reading_minutes":9,"published_at":"2026-09-24T00:00:00.000Z","added_at":"2026-09-30T12:14:02.898Z","updated_at":"2026-09-30T12:14:02.898Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/ai-powered-fuzzing-with-the-github-security-lab-taskflow-agent","markdown_url":"https://listedarticles.com/articles/ai-powered-fuzzing-with-the-github-security-lab-taskflow-agent.md","example":false,"citation":"Antonio Morales, GitHub. \"AI-powered fuzzing with the GitHub Security Lab Taskflow Agent.\" 24 Sept 2026. https://github.blog/security/application-security/ai-powered-fuzzing-with-the-github-security-lab-taskflow-agent/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://github.blog/security/application-security/ai-powered-fuzzing-with-the-github-security-lab-taskflow-agent/"},"snippet":null,"score":null},{"slug":"evading-machine-learning-based-detections","title":"Evading Machine Learning Based Detections","subtitle":null,"summary":"Companion post to an x33fcon talk on packer/loader architecture and how machine-learning-based detections work—plus practical ML-evasion techniques and RustPack 1.7 features that aim to bypass those detectors by default.","content_type":"blog_post","language":"en","canonical_url":"https://www.msecops.de/blog/posts/ml-evasion/","author":{"name":"MSec Operations","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"MSec Operations Blog","url":"https://www.msecops.de/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Machine Learning","slug":"machine-learning","url":"https://listedarticles.com/topics/machine-learning"},{"name":"Engineering","slug":"engineering","url":"https://listedarticles.com/topics/engineering"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":2880,"reading_minutes":13,"published_at":"2026-09-23T15:56:05.542Z","added_at":"2026-09-23T15:56:05.542Z","updated_at":"2026-09-23T15:56:05.542Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/evading-machine-learning-based-detections","markdown_url":"https://listedarticles.com/articles/evading-machine-learning-based-detections.md","example":false,"citation":"MSec Operations, MSec Operations Blog. \"Evading Machine Learning Based Detections.\" 23 Sept 2026. https://www.msecops.de/blog/posts/ml-evasion/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://www.msecops.de/blog/posts/ml-evasion/"},"snippet":null,"score":null},{"slug":"august-27-tcrf-ddos-attack-postmortem","title":"August 27 TCRF DDoS Attack Postmortem","subtitle":null,"summary":"The Cutting Room Floor’s postmortem on a sustained August 2026 DDoS: what broke, how mitigation unfolded, and the infrastructure changes made to keep a volunteer game-preservation wiki online.","content_type":"blog_post","language":"en","canonical_url":"https://blog.xkeeper.net/the-cutting-room-floor/tcrf-2026-ddos-postmortem/","author":{"name":"Author Xkeeper","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"The Cutting Room Floor","url":"https://blog.xkeeper.net","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"},{"name":"Networking","slug":"networking","url":"https://listedarticles.com/topics/networking"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":3930,"reading_minutes":17,"published_at":"2026-09-23T12:00:00.000Z","added_at":"2026-09-25T03:16:14.085Z","updated_at":"2026-09-25T03:16:14.085Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/august-27-tcrf-ddos-attack-postmortem","markdown_url":"https://listedarticles.com/articles/august-27-tcrf-ddos-attack-postmortem.md","example":false,"citation":"Author Xkeeper, The Cutting Room Floor. \"August 27 TCRF DDoS Attack Postmortem.\" 23 Sept 2026. https://blog.xkeeper.net/the-cutting-room-floor/tcrf-2026-ddos-postmortem/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://blog.xkeeper.net/the-cutting-room-floor/tcrf-2026-ddos-postmortem/"},"snippet":null,"score":null},{"slug":"att-and-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce","title":"ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE","subtitle":null,"summary":"TACACS+ is one of the ways large networks centralise administrative access to their equipment, alongside RADIUS and DIAMETER, and it is the one that tends to be chosen where per-command control matters. Instead of every router, switch, firewall and console server keeping its own local accounts, each device asks a TACACS+ server whether a login is allowed, at what privilege level, and often whether each individual command should be permitted. It is standard in enterprise,…","content_type":"blog_post","language":"en","canonical_url":"https://www.elttam.com/blog/att-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce","author":{"name":"elttam","url":null,"person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"elttam","url":"https://www.elttam.com","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"Programming","slug":"programming","url":"https://listedarticles.com/topics/programming"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":5766,"reading_minutes":25,"published_at":"2026-09-23T12:00:00.000Z","added_at":"2026-09-24T06:18:05.382Z","updated_at":"2026-09-24T06:18:05.382Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/att-and-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce","markdown_url":"https://listedarticles.com/articles/att-and-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce.md","example":false,"citation":"elttam, elttam. \"ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE.\" 23 Sept 2026. https://www.elttam.com/blog/att-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://www.elttam.com/blog/att-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce"},"snippet":null,"score":null}],"total":48,"count":20,"next_offset":20,"has_more":true,"query":{"q":null,"content_type":"blog_post","topic":"security","publisher":null,"about":null,"author":null,"language":null,"sort":"newest","limit":20,"offset":0}}