Related reading
Second Circuit Allows Government to Search Electronic Devices at the Border
The 2nd U.S. Circuit Court upheld the border-search exception, allowing agents to seize and examine travelers’ phones without a warrant, rejecting amicus arguments that First and Fourth Amendment rights require a warrant.
Hacker News front pageknightcolumbia.org2 minHN13078Laravel Scalpel Scans for Filesystem Intrusion Evidence
Laravel Scalpel is a Laravel‑native scanner that looks for post‑deployment filesystem tampering – rogue PHP files, obfuscated backdoors, altered .htaccess/.user.ini, missing or mis‑configured .env, and diffs against a signed baseline. It ships with six built‑in scanners, baseline snapshot commands, fast vs strict hashing modes, CI‑friendly output (JSON, SARIF, GitHub annotations) and a ScanFinish…
Laravellaravel-news.com5 minHackers Got Inside a Flock Camera
Hackers removed a Flock license‑plate reader camera, copied its storage, extracted an on‑device encryption key, and released ~1.6 M images and logs covering 21 days of operation. Analysis shows the device captures ~28 images per vehicle, detects people, and stores raw media in unencrypted partitions. License‑plate detection runs on the cloud, and the camera’s software can mis‑identify graphics as…
Hacker News front pagewired.com7 minpostmortemHN578267APort Vault: Benchmarking AI Agent Payment Authorization with the Open Agent Passport
APort Vault is a benchmark that replays 4,371 human‑written attacks against a live payment‑handling AI agent across 14 models and multiple policy configurations, generating 225,964 evaluations. Adding the Open Agent Passport pre‑action check eliminated all unauthorized transfers in the test, showing a per‑session breach upper bound of 0.38%.
Hugging Face Daily Papersarxiv.org2 minpaperConfused Deputy: The Old Bug That AI Agents Keep Reintroducing
The Confused Deputy problem—where a privileged component is tricked into misusing its authority—has resurfaced in AI agents that process natural‑language prompts. The article shows real 2026 attacks, explains why agents are especially vulnerable, and outlines mitigations like least‑privilege scopes, capability‑based tokens, and human‑in‑the‑loop approvals.
Auth0auth0.com9 minBuilding Secure AI Agents with Microsoft Agent Framework and Auth0: Human-in-the-Loop Approval
This article demonstrates how to implement human-in-the-loop approval for an AI expense agent using Auth0's Client-Initiated Backchannel Authentication (CIBA). It enables secure, out-of-band manager approval via push notifications with specific binding messages, preventing the LLM from handling sensitive credentials.
Auth0auth0.com17 min





