Skip to content

WorthPosting

  • Home
  • About

Tag: security

Cat Links Software Engineering

Software Supply Chain Security in 2026: Pinning, Provenance, Signing, and SBOMs That Get Consumed

Posted on October 4, 2026 teliaz

A few years ago, “supply chain security” meant checking your Docker base images for critical CVEs and hoping your dependency

Continue readingSoftware Supply Chain Security in 2026: Pinning, Provenance, Signing, and SBOMs That Get Consumed

Cat Links Software Engineering

Secrets Management Beyond Environment Variables: Vault, SOPS, Sealed Secrets, and Rotation That Works

Posted on September 24, 2026 teliaz

Every team starts with environment variables because every framework supports them. A DATABASE_URL in a .env file, a compose file

Continue readingSecrets Management Beyond Environment Variables: Vault, SOPS, Sealed Secrets, and Rotation That Works

Cat Links Software Engineering

Service-to-Service Authentication in Microservices: mTLS, JWTs, and the Token Exchange Pattern

Posted on September 22, 2026 teliaz

Getting a request into your system is the easy part. The hard question arrives at hop two: when the order

Continue readingService-to-Service Authentication in Microservices: mTLS, JWTs, and the Token Exchange Pattern

Cat Links Software Engineering

SSRF Defense in Go: Why URL Validation Fails and How to Fix It at the Dial Layer

Posted on September 19, 2026 teliaz

Server-Side Request Forgery (SSRF) keeps topping real-world breach reports for a simple reason: modern applications are glued together with outbound

Continue readingSSRF Defense in Go: Why URL Validation Fails and How to Fix It at the Dial Layer

Cat Links Software Engineering

AI Agents Are Machine Identities: Governing Non-Human Credentials Before They Proliferate

Posted on September 16, 2026September 17, 2026 teliaz

Your microservices fleet has 3,000 machine identities and 300 employees — a 10:1 ratio that is conservative by industry standards,

Continue readingAI Agents Are Machine Identities: Governing Non-Human Credentials Before They Proliferate

Cat Links Software Engineering

JWT Security Pitfalls: Algorithm Confusion, Header Injection, and the Claims Everyone Forgets to Check

Posted on September 14, 2026 teliaz

JWTs are everywhere because they solve an ugly problem: how does a stateless service know who’s calling without a database

Continue readingJWT Security Pitfalls: Algorithm Confusion, Header Injection, and the Claims Everyone Forgets to Check

Cat Links Software Engineering

gRPC Server Reflection in Production: Gate It, and Use Health Checks Instead

Posted on September 11, 2026 teliaz

Here is a debugging story that repeats across every gRPC team. A developer runs grpcurl -plaintext localhost:50051 list against a

Continue readinggRPC Server Reflection in Production: Gate It, and Use Health Checks Instead

Cat Links Software Engineering

Defending Against Supply Chain Attacks: An npm and PyPI Defense Playbook

Posted on September 9, 2026September 10, 2026 teliaz

When a popular npm package turns malicious, the window between publication and detection is measured in hours, and the first

Continue readingDefending Against Supply Chain Attacks: An npm and PyPI Defense Playbook

Cat Links Software Engineering

Secrets Management in Practice: From Hardcoded Credentials to Short-Lived Identity

Posted on September 5, 2026September 6, 2026 teliaz

Most breaches involving secrets do not involve sophisticated attacks. They involve a credential that was committed to a git repository

Continue readingSecrets Management in Practice: From Hardcoded Credentials to Short-Lived Identity

Cat Links Software Engineering

SSRF: The Vulnerability That Turns Your Server Against Its Own Network

Posted on September 3, 2026 teliaz

Your webapp has a feature where users can attach an image by URL. A user submits https://example.com/logo.png and the backend

Continue readingSSRF: The Vulnerability That Turns Your Server Against Its Own Network

Posts navigation

Older posts
  • Home
  • About
Copyright © 2026 WorthPosting | Signify by WEN Themes
Scroll Up