Blog

Research, write-ups, tutorials.

How AppSec changes when agents write the code. Logic flaws, MCP, agent-time security. New every week.

Talk to us

All posts

30 articles
Your CLAUDE.md Works on the Rules You Did Not Need
Research

Your CLAUDE.md Works on the Rules You Did Not Need

Does Claude Code follow CLAUDE.md? In 90 graded runs, a realistic rules file scored exactly the same as no file at all. What worked instead, measured.

CybeDefendCYBEDEFEND24 min read
Read more
Codex danger-full-access, --yolo and Unsafe Mode: What Each Flag Disables
Security

Codex danger-full-access, --yolo and Unsafe Mode: What Each Flag Disables

Codex danger-full-access, --dangerously-bypass-approvals-and-sandbox (--yolo), -a never and --full-auto: what each removes, when it is safe, what to use instead.

CybeDefendCYBEDEFEND13 min read
Read more
Your Agent Never Escaped the Sandbox. It Did Not Need To.
Research

Your Agent Never Escaped the Sandbox. It Did Not Need To.

Seven sandbox escapes across four coding agents, and almost none of them broke the box. What the Trust Handoff Flaw means for how you contain an agent.

CybeDefendCYBEDEFEND17 min read
Read more
Nobody Is Reviewing Your Agent's Pull Requests
Research

Nobody Is Reviewing Your Agent's Pull Requests

A human alone reviews an agent's pull request 8% of the time. What the UK AI Security Institute incident means for your review process.

CybeDefendCYBEDEFEND20 min read
Read more
The 12 Best AI Security Platforms for Vulnerability Detection, and the One Question That Now Separates Them
Research

The 12 Best AI Security Platforms for Vulnerability Detection, and the One Question That Now Separates Them

Twelve platforms scored on what they detect, what survives triage and where the verdict lands, with each vendor's positioning as it stands today.

CybeDefendCYBEDEFEND18 min read
Read more
Your Model Got Smarter. Your Code Did Not Get Safer.
Research

Your Model Got Smarter. Your Code Did Not Get Safer.

Capability doubled in one model generation while security stayed flat. Why upgrading the model and telling it to be secure both fail under measurement.

CybeDefendCYBEDEFEND18 min read
Read more
Instruction File Injection: How AGENTS.md and CLAUDE.md Hijack Coding Agents
Security

Instruction File Injection: How AGENTS.md and CLAUDE.md Hijack Coding Agents

AGENTS.md and CLAUDE.md load with near system-prompt authority. How instruction file injection works, the named 2026 incidents, and how to defend your repo.

CybeDefendCYBEDEFEND21 min read
Read more
What Is an AI-BOM? The AI Bill of Materials the EU AI Act Assumes You Already Have
Compliance

What Is an AI-BOM? The AI Bill of Materials the EU AI Act Assumes You Already Have

What an AI-BOM contains, how it maps to EU AI Act Article 11 and Annex IV, and why an inventory kept as a document is stale before it is signed.

CybeDefendCYBEDEFEND26 min read
Read more
What Is Slopsquatting? Slopsquatting vs Typosquatting, and the HalluSquatting Attack
Security

What Is Slopsquatting? Slopsquatting vs Typosquatting, and the HalluSquatting Attack

Slopsquatting registers a package name an AI invented, typosquatting a misspelling of a real one. Why edit-distance defenses miss it, and the HalluSquatting attack.

CybeDefendCYBEDEFEND17 min read
Read more

Install VibeDefend in 5 seconds.

One command wires every coding agent on your machine to CybeDefend: your business rules, your compliance frameworks, and guards that block destructive calls before they fire.

Install in 5 secondsNode 18.17+
npx -y @cybedefend/vibedefend@latest install
Auto-detects
  • Claude CodeClaude Code
  • CursorCursor
  • OpenAI CodexOpenAI Codex
  • WindsurfWindsurf
  • GitHub CopilotVS Code Copilot