Security

A 65-part series to help you master this topic step by step.

65 parts in this series
AI

Powered by Claude Opus 4.5—understands meaning, not just keywords. Try “how do I configure Claude Code?”

Series Outline

ClawHavoc: AI Skills Supply Chain Attack Explained
1

ClawHavoc: AI Skills Supply Chain Attack Explained

Read article
Hidden Prompts in GitHub Issues Explained
2

Hidden Prompts in GitHub Issues Explained

Read article
Supabase RLS Security Risks: What Vibe Coders Need to Check Now
3

Supabase RLS Security Risks: What Vibe Coders Need to Check Now

Read article
GitHub Secrets Leaked: Why AI Tools Make It Worse
4

GitHub Secrets Leaked: Why AI Tools Make It Worse

Read article
Meta's Alleged Rogue AI Agent: What Vibe Coders Should Actually Learn
5

Meta's Alleged Rogue AI Agent: What Vibe Coders Should Actually Learn

Read article
GitHub Actions Security After a Supply Chain Attack
6

GitHub Actions Security After a Supply Chain Attack

Read article
64% of Leaked Secrets Still Work Years Later — And Yours Might Be One of Them
7

64% of Leaked Secrets Still Work Years Later — And Yours Might Be One of Them

Read article
After TeamPCP: A Vibe Coder's Supply-Chain Defense Plan
8

After TeamPCP: A Vibe Coder's Supply-Chain Defense Plan

Read article
GitHub Runner Compromise Explained for Vibe Coders
9

GitHub Runner Compromise Explained for Vibe Coders

Read article
GitHub Secret Scanning Now Detects Vercel and Supabase Keys
10

GitHub Secret Scanning Now Detects Vercel and Supabase Keys

Read article
Moltbook Breach: 150K API Keys Leaked by Missing RLS
11

Moltbook Breach: 150K API Keys Leaked by Missing RLS

Read article
252K Servers Leak Deployment Credentials via Exposed .git Folders
12

252K Servers Leak Deployment Credentials via Exposed .git Folders

Read article
OWASP LLM Top 10 for Vibe Coders
13

OWASP LLM Top 10 for Vibe Coders

Read article
Env Files the Right Way: Gitignore and Rotation
14

Env Files the Right Way: Gitignore and Rotation

Read article
Stop Hardcoded API Keys in AI Code
15

Stop Hardcoded API Keys in AI Code

Read article
Secrets in the Browser Are Public: Front-End Keys
16

Secrets in the Browser Are Public: Front-End Keys

Read article
29 Million GitHub Secrets: A Vibe Coder Wake-Up Call
17

29 Million GitHub Secrets: A Vibe Coder Wake-Up Call

Read article
DryRun Study: AI Coding Vulnerabilities Explained
18

DryRun Study: AI Coding Vulnerabilities Explained

Read article
Fake MCP Servers Are Poisoning AI Coding Tools
19

Fake MCP Servers Are Poisoning AI Coding Tools

Read article
Secrets Managers Explained: Stop Scattering Your Keys
20

Secrets Managers Explained: Stop Scattering Your Keys

Read article
5,000 Vibe-Coded Apps Had Zero Login — What Went Wrong
21

5,000 Vibe-Coded Apps Had Zero Login — What Went Wrong

Read article
AI Coding Tools Can Double Your Secret Leak Rate — Here's How to Fix It
22

AI Coding Tools Can Double Your Secret Leak Rate — Here's How to Fix It

Read article
node-ipc npm Attack: Why Hidden Dependencies Matter
23

node-ipc npm Attack: Why Hidden Dependencies Matter

Read article
AI Agent Security for Vibe Coders
24

AI Agent Security for Vibe Coders

Read article
Row Level Security: The Lock Behind Public Keys
25

Row Level Security: The Lock Behind Public Keys

Read article
Millions of Servers Still Expose .git Folders — Here’s How to Check Yours
26

Millions of Servers Still Expose .git Folders — Here’s How to Check Yours

Read article
Git Config Credentials: Why Exposed .git Files Can Leak Secrets
27

Git Config Credentials: Why Exposed .git Files Can Leak Secrets

Read article
Secret Scanning Before You Commit: GitHub MCP's Safety Net
28

Secret Scanning Before You Commit: GitHub MCP's Safety Net

Read article
Agent-to-Agent Attacks: How AI Tools Infect Each Other
29

Agent-to-Agent Attacks: How AI Tools Infect Each Other

Read article
Claw Chain & ClawHavoc: Why AI Marketplace Add-Ons Can Ship Malware
30

Claw Chain & ClawHavoc: Why AI Marketplace Add-Ons Can Ship Malware

Read article
Backups and Extortion: Resilience Before Things Go Wrong
31

Backups and Extortion: Resilience Before Things Go Wrong

Read article
Dependency Confusion: When a Fake Package Jumps the Line
32

Dependency Confusion: When a Fake Package Jumps the Line

Read article
Prompt Injection: When Your AI Reads Attacker Instructions
33

Prompt Injection: When Your AI Reads Attacker Instructions

Read article
Typosquatting on npm: One Wrong Letter, Stolen Keys
34

Typosquatting on npm: One Wrong Letter, Stolen Keys

Read article
MCP Config Files: The New Attack Surface for AI Tools
35

MCP Config Files: The New Attack Surface for AI Tools

Read article
Google Gemini API Key Exposure: What Vibe Coders Must Know
36

Google Gemini API Key Exposure: What Vibe Coders Must Know

Read article
AI Coding Tools Are Leaking Your Secrets: A Vibe Coder's Prevention Guide
37

AI Coding Tools Are Leaking Your Secrets: A Vibe Coder's Prevention Guide

Read article
OAuth Basics: Why 'Login with Google' Beats Rolling Your Own
38

OAuth Basics: Why 'Login with Google' Beats Rolling Your Own

Read article
Free Scanner Checks Packages, Extensions, MCP
39

Free Scanner Checks Packages, Extensions, MCP

Read article
Claude Code Sandbox Bypass: Update AI Tools
40

Claude Code Sandbox Bypass: Update AI Tools

Read article
Two-Factor Authentication After the May Token Thefts
41

Two-Factor Authentication After the May Token Thefts

Read article
When Your AI Provider Gets Sued: A Continuity Runbook for Vibe Coders
42

When Your AI Provider Gets Sued: A Continuity Runbook for Vibe Coders

Read article
Anthropic-Pentagon Risk: A Vibe Coder's Claude Audit
43

Anthropic-Pentagon Risk: A Vibe Coder's Claude Audit

Read article
GitHub Itself Was Breached: What 3,800 Stolen Repos Mean for You
44

GitHub Itself Was Breached: What 3,800 Stolen Repos Mean for You

Read article
Rate Limiting for Vibe Apps: Stop Abuse Fast
45

Rate Limiting for Vibe Apps: Stop Abuse Fast

Read article
Least Privilege: Scope Every Key So a Breach Can't Spread
46

Least Privilege: Scope Every Key So a Breach Can't Spread

Read article
May 2026 Vibe Coder Security Checklist: The Month in Review
47

May 2026 Vibe Coder Security Checklist: The Month in Review

Read article
BFG & git-filter-repo: Cleaning Leaked Secrets from Git History
48

BFG & git-filter-repo: Cleaning Leaked Secrets from Git History

Read article
Anthropic MITRE ATT&CK Report: What It Means
49

Anthropic MITRE ATT&CK Report: What It Means

Read article
Miasma Attack: npm Install Runs Code First
50

Miasma Attack: npm Install Runs Code First

Read article
Nx Console Extension Attack: 18 Minutes Was Enough
51

Nx Console Extension Attack: 18 Minutes Was Enough

Read article
The API Key Leak Crisis of 2026: Why AI-Built App Secrets Are Public
52

The API Key Leak Crisis of 2026: Why AI-Built App Secrets Are Public

Read article
Why AI-Generated Code Isn't Automatically Secure
53

Why AI-Generated Code Isn't Automatically Secure

Read article
Vibe Coder Security: Stop API Key Leaks Fast
54

Vibe Coder Security: Stop API Key Leaks Fast

Read article
Git History Is Forever: Why Deleting a Secret Doesn't Make It Gone
55

Git History Is Forever: Why Deleting a Secret Doesn't Make It Gone

Read article
Your Supabase Key Is Public — And That's Only Safe If You Did One Thing
56

Your Supabase Key Is Public — And That's Only Safe If You Did One Thing

Read article
Gemini API Key Exposure: A Security Lesson for Vibe Coders
57

Gemini API Key Exposure: A Security Lesson for Vibe Coders

Read article
Cloudflare Vinext Security Is a Vibe Coding Wake-Up Call
58

Cloudflare Vinext Security Is a Vibe Coding Wake-Up Call

Read article
AI Coding Tools Are Leaking Your API Keys: A Vibe Coder's Fix
59

AI Coding Tools Are Leaking Your API Keys: A Vibe Coder's Fix

Read article
Vet Extensions Before Installing: Your Editor Is a Front Door
60

Vet Extensions Before Installing: Your Editor Is a Front Door

Read article
Private-CISA Leak: Public Repo, Plaintext Secrets
61

Private-CISA Leak: Public Repo, Plaintext Secrets

Read article
Grafana Breach: One Missed Token Undid an Entire Rotation
62

Grafana Breach: One Missed Token Undid an Entire Rotation

Read article
Mini Shai-Hulud: The Self-Replicating npm Worm Vibe Coders Must Understand
63

Mini Shai-Hulud: The Self-Replicating npm Worm Vibe Coders Must Understand

Read article
Input Validation and SQL Injection for Vibe Coders
64

Input Validation and SQL Injection for Vibe Coders

Read article
Gitleaks Pre-Commit Hooks Stop Leaks Before Push
65

Gitleaks Pre-Commit Hooks Stop Leaks Before Push

Read article

Ready to start learning?

Begin with Part 1 and work your way through the series at your own pace.