Security
A 65-part series to help you master this topic step by step.
65 parts in this series
AI
Powered by Claude Opus 4.5—understands meaning, not just keywords. Try “how do I configure Claude Code?”
Series Outline

1
ClawHavoc: AI Skills Supply Chain Attack Explained
Read article

2
Hidden Prompts in GitHub Issues Explained
Read article

3
Supabase RLS Security Risks: What Vibe Coders Need to Check Now
Read article

4
GitHub Secrets Leaked: Why AI Tools Make It Worse
Read article

5
Meta's Alleged Rogue AI Agent: What Vibe Coders Should Actually Learn
Read article

6
GitHub Actions Security After a Supply Chain Attack
Read article

7
64% of Leaked Secrets Still Work Years Later — And Yours Might Be One of Them
Read article

8
After TeamPCP: A Vibe Coder's Supply-Chain Defense Plan
Read article

9
GitHub Runner Compromise Explained for Vibe Coders
Read article

10
GitHub Secret Scanning Now Detects Vercel and Supabase Keys
Read article

11
Moltbook Breach: 150K API Keys Leaked by Missing RLS
Read article

12
252K Servers Leak Deployment Credentials via Exposed .git Folders
Read article

13
OWASP LLM Top 10 for Vibe Coders
Read article

14
Env Files the Right Way: Gitignore and Rotation
Read article

15
Stop Hardcoded API Keys in AI Code
Read article

16
Secrets in the Browser Are Public: Front-End Keys
Read article

17
29 Million GitHub Secrets: A Vibe Coder Wake-Up Call
Read article

18
DryRun Study: AI Coding Vulnerabilities Explained
Read article

19
Fake MCP Servers Are Poisoning AI Coding Tools
Read article

20
Secrets Managers Explained: Stop Scattering Your Keys
Read article

21
5,000 Vibe-Coded Apps Had Zero Login — What Went Wrong
Read article

22
AI Coding Tools Can Double Your Secret Leak Rate — Here's How to Fix It
Read article

23
node-ipc npm Attack: Why Hidden Dependencies Matter
Read article

24
AI Agent Security for Vibe Coders
Read article

25
Row Level Security: The Lock Behind Public Keys
Read article

26
Millions of Servers Still Expose .git Folders — Here’s How to Check Yours
Read article

27
Git Config Credentials: Why Exposed .git Files Can Leak Secrets
Read article

28
Secret Scanning Before You Commit: GitHub MCP's Safety Net
Read article

29
Agent-to-Agent Attacks: How AI Tools Infect Each Other
Read article

30
Claw Chain & ClawHavoc: Why AI Marketplace Add-Ons Can Ship Malware
Read article

31
Backups and Extortion: Resilience Before Things Go Wrong
Read article

32
Dependency Confusion: When a Fake Package Jumps the Line
Read article

33
Prompt Injection: When Your AI Reads Attacker Instructions
Read article

34
Typosquatting on npm: One Wrong Letter, Stolen Keys
Read article

35
MCP Config Files: The New Attack Surface for AI Tools
Read article

36
Google Gemini API Key Exposure: What Vibe Coders Must Know
Read article

37
AI Coding Tools Are Leaking Your Secrets: A Vibe Coder's Prevention Guide
Read article

38
OAuth Basics: Why 'Login with Google' Beats Rolling Your Own
Read article

39
Free Scanner Checks Packages, Extensions, MCP
Read article

40
Claude Code Sandbox Bypass: Update AI Tools
Read article

41
Two-Factor Authentication After the May Token Thefts
Read article

42
When Your AI Provider Gets Sued: A Continuity Runbook for Vibe Coders
Read article

43
Anthropic-Pentagon Risk: A Vibe Coder's Claude Audit
Read article

44
GitHub Itself Was Breached: What 3,800 Stolen Repos Mean for You
Read article

45
Rate Limiting for Vibe Apps: Stop Abuse Fast
Read article

46
Least Privilege: Scope Every Key So a Breach Can't Spread
Read article

47
May 2026 Vibe Coder Security Checklist: The Month in Review
Read article

48
BFG & git-filter-repo: Cleaning Leaked Secrets from Git History
Read article

49
Anthropic MITRE ATT&CK Report: What It Means
Read article

50
Miasma Attack: npm Install Runs Code First
Read article

51
Nx Console Extension Attack: 18 Minutes Was Enough
Read article

52
The API Key Leak Crisis of 2026: Why AI-Built App Secrets Are Public
Read article

53
Why AI-Generated Code Isn't Automatically Secure
Read article

54
Vibe Coder Security: Stop API Key Leaks Fast
Read article

55
Git History Is Forever: Why Deleting a Secret Doesn't Make It Gone
Read article

56
Your Supabase Key Is Public — And That's Only Safe If You Did One Thing
Read article

57
Gemini API Key Exposure: A Security Lesson for Vibe Coders
Read article

58
Cloudflare Vinext Security Is a Vibe Coding Wake-Up Call
Read article

59
AI Coding Tools Are Leaking Your API Keys: A Vibe Coder's Fix
Read article

60
Vet Extensions Before Installing: Your Editor Is a Front Door
Read article

61
Private-CISA Leak: Public Repo, Plaintext Secrets
Read article

62
Grafana Breach: One Missed Token Undid an Entire Rotation
Read article

63
Mini Shai-Hulud: The Self-Replicating npm Worm Vibe Coders Must Understand
Read article

64
Input Validation and SQL Injection for Vibe Coders
Read article

65
Gitleaks Pre-Commit Hooks Stop Leaks Before Push
Read article
Ready to start learning?
Begin with Part 1 and work your way through the series at your own pace.