Explore real-world engineering experiences from top tech companies.
Receive daily AI-curated summaries of engineering articles from top tech companies worldwide.
GitLab now supports passkeys for passwordless sign-in and phishing-resistant two-factor authentication.
This post explains how to design security boundaries in agentic AI systems to prevent credential theft and misuse via prompt injection.
Vercel Sandbox supports HTTP header injection for outbound requests, keeping API credentials outside the sandbox VM.
Cloudflare One becomes the first SASE platform to support modern post-quantum encryption across its entire platform, including Secure Web Gateway, Zero Trust, and WAN use cases.
GitLab's Threat Intelligence Team exposes North Korean nation-state threat actor operations, including the Contagious Interview malware campaign and IT worker activity observed on their platform in 2025.
GitLab's updated Security Dashboard provides application security teams with actionable insights to prioritize and track vulnerability remediation across projects.
HCP Packer introduces SBOM vulnerability scanning in public beta, enabling platform teams to identify security risks in image artifacts earlier in the deployment pipeline.
skills.sh has introduced automated security audits for its 60,000+ skills catalog, built in partnership with Gen, Socket, and Snyk.
This post recaps HCP Vault Radar's 2025 milestones in secrets discovery and remediation across development and cloud environments.
HCP Vault Dedicated introduces secrets and certificates inventory reporting (beta) to improve visibility and audit readiness for security teams.
The crates.io team announces a policy change regarding notifications for malicious crates detected on the registry.
This article explains how HashiCorp Vault combined with Workload Identity Federation (WIF) eliminates static credentials and the "secret zero" problem in modern cloud-native environments.