AI Security12 August 2026
Context Bombs: Using Prompt Injection to Stop AI Hacking Agents
Tracebit researchers show that planting a prompt injection next to a decoy AWS secret can trip an attacking LLM's own safety guardrails — cutting successful compromise rates dramatically across five frontier models.
ai-securityprompt-injectioncloud-security
4 min readRead
Application Security15 July 2026
FIFA's Broken Access Control Bug Left World Cup Streams Open to Hijack
A researcher who signed up as a football agent found himself inside FIFA's internal platforms — because the authorization checks only ran in the browser.
broken-access-controlpenetration-testingvulnerability-disclosure
4 min readRead
DevSecOps & Infrastructure14 July 2026
Lobste.rs moves to SQLite: a lesson in shrinking your attack surface
The tech-news community site Lobsters has retired MariaDB in favour of SQLite after an eight-year migration effort — a small architectural decision with a useful security lesson about trading network attack surface for single-host risk.
devsecopsattack-surfacearchitecture
4 min readRead