[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2wwgzjlqngp7y":3,"$fanuq43nlrv5g":59},{"slug":4,"title":5,"body":6,"summary":7,"tags":8,"author":14,"cover_url":15,"published_at":16,"seo_title":17,"seo_description":18,"reading_minutes":19,"related":20},"copyescape-cve-2026-17106-patch-docker-cp","CopyEscape (CVE-2026-17106): patch docker cp, and stop copying out of running containers","\u003Cp>\u003Ccode>docker cp\u003C\u002Fcode> is the command everyone uses to get build artefacts, test reports or an agent's output out of a container. CopyEscape, tracked as CVE-2026-17106, turns it around: if the container you copy \u003Cem>from\u003C\u002Fem> is malicious, it can make the copy write files \u003Cem>outside\u003C\u002Fem> the destination folder on your host. With \u003Ccode>sudo docker cp\u003C\u002Fcode> on Linux, Imperva, which found the bug, says that can go as far as root code execution.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac2d60d2cb6b40613ac1ae3\">\u003Cvideo src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac2d60f2cb6b40613ac1ae9-0-4e09f411.mp4\" autoplay muted loop playsinline preload=\"metadata\">\u003C\u002Fvideo>\u003C\u002Ffigure>\n\n\u003Cp>If you only copy out of containers you built from images you trust, this is a patch-when-convenient bug. If you run CI for pull requests from strangers, or let a coding agent run arbitrary code in a container and then copy its results out, it is a patch-today bug. This post is the short version: what is affected, how to check, and how to change copy-out jobs so the next bug of this kind does not hit you either.\u003C\u002Fp>\n\n\u003Ch2>What goes wrong\u003C\u002Fh2>\n\n\u003Cp>When you run \u003Ccode>docker cp container:\u002Fpath .\u002Fdest\u003C\u002Fcode>, the daemon walks the container's filesystem and builds a tar archive, which is then unpacked on the host. Imperva's write-up describes a race: while the walk is in progress, a process inside the \u003Cstrong>running\u003C\u002Fstrong> container swaps a directory for a symlink pointing outside the destination. The walker has already classified the path as a directory, then meets the symlink, and the result is an inconsistent archive that, when extracted, writes through the symlink. The extraction side, in the \u003Ccode>moby\u002Fgo-archive\u003C\u002Fcode> library, did not restrict paths tightly enough to catch it.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac218edfd770659725abe6e\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218edfd770659725abe73-0-4e3c0e0a.png\" alt=\"A conceptual representation of a path redirection vulnerability.\" loading=\"lazy\">\u003Cfigcaption>A conceptual representation of a path redirection vulnerability.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\n\u003Cp>Two conditions matter for your defences:\u003C\u002Fp>\n\n\u003Cul>\n\u003Cli>\u003Cstrong>The container has to be running.\u003C\u002Fstrong> The race needs a live process to do the swap. Imperva notes that stopped containers block the exploit.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The damage is bounded by who runs the copy.\u003C\u002Fstrong> Files are written with the permissions of the process doing the extraction. A copy run as root can overwrite anything.\u003C\u002Fli>\n\u003C\u002Ful>\n\n\u003Ch2>Affected and fixed versions\u003C\u002Fh2>\n\n\u003Cp>Per Imperva's advisory and Docker's announcements:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac218edfd770659725abe78\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218edfd770659725abe7d-0-2fbad510.png\" alt=\"Updating software versions helps secure the container boundary.\" loading=\"lazy\">\u003Cfigcaption>Updating software versions helps secure the container boundary.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\n\u003Cul>\n\u003Cli>\u003Cstrong>Docker Engine and CLI:\u003C\u002Fstrong> fixed in \u003Cstrong>29.7.2\u003C\u002Fstrong>. Earlier versions are affected.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Docker Desktop:\u003C\u002Fstrong> fixed in \u003Cstrong>4.86.0\u003C\u002Fstrong>, released on 10 August 2026.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Docker Sandboxes\u003C\u002Fstrong> (the \u003Ccode>sbx cp\u003C\u002Fcode> command): fixed in \u003Cstrong>0.38.0\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Wiz's vulnerability database also lists \u003Ccode>moby\u002Fgo-archive\u003C\u002Fcode> before 0.3.0 and Docker Compose before 5.4.0 as affected. It rates the bug CVSS v4.0 7.1 (High) and gives 18 August 2026 as the publication date.\u003C\u002Fli>\n\u003C\u002Ful>\n\n\u003Ch2>Check your machines (2 minutes)\u003C\u002Fh2>\n\n\u003Cp>Engine and CLI versions come from \u003Ccode>docker version\u003C\u002Fcode>:\u003C\u002Fp>\n\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">docker version --format \u003Cspan class=\"hljs-string\">&#x27;client={{.Client.Version}} server={{.Server.Version}}&#x27;\u003C\u002Fspan>\ndocker compose version --short\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>On a Mac, the Docker Desktop version is in the app bundle (or under Settings → About):\u003C\u002Fp>\n\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">defaults \u003Cspan class=\"hljs-built_in\">read\u003C\u002Fspan> \u002FApplications\u002FDocker.app\u002FContents\u002FInfo.plist CFBundleShortVersionString\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>For a fleet of CI runners, a small script that fails when the client or server is older than the fix is easier to drop into a health check:\u003C\u002Fp>\n\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-meta\">#!\u002Fusr\u002Fbin\u002Fenv bash\u003C\u002Fspan>\n\u003Cspan class=\"hljs-comment\"># copyescape-check.sh: exit 1 if Docker client or server is older than 29.7.2\u003C\u002Fspan>\n\u003Cspan class=\"hljs-built_in\">set\u003C\u002Fspan> -euo pipefail\nmin=29.7.2\n\n\u003Cspan class=\"hljs-comment\"># true when $1 &gt;= $2 (version sort)\u003C\u002Fspan>\n\u003Cspan class=\"hljs-function\">\u003Cspan class=\"hljs-title\">at_least\u003C\u002Fspan>\u003C\u002Fspan>() { [ \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-subst\">$(printf &#x27;%s\\n%s\\n&#x27; \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$1\u003C\u002Fspan>&quot;\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$2\u003C\u002Fspan>&quot;\u003C\u002Fspan> | sort -V | head -n1)\u003C\u002Fspan>&quot;\u003C\u002Fspan> = \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$2\u003C\u002Fspan>&quot;\u003C\u002Fspan> ]; }\n\nstatus=0\n\u003Cspan class=\"hljs-keyword\">for\u003C\u002Fspan> part \u003Cspan class=\"hljs-keyword\">in\u003C\u002Fspan> Client Server; \u003Cspan class=\"hljs-keyword\">do\u003C\u002Fspan>\n  v=$(docker version --format \u003Cspan class=\"hljs-string\">&quot;{{.\u003Cspan class=\"hljs-variable\">${part}\u003C\u002Fspan>.Version}}&quot;\u003C\u002Fspan> 2&gt;\u002Fdev\u002Fnull || \u003Cspan class=\"hljs-built_in\">echo\u003C\u002Fspan> unknown)\n  \u003Cspan class=\"hljs-keyword\">if\u003C\u002Fspan> [ \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$v\u003C\u002Fspan>&quot;\u003C\u002Fspan> = unknown ]; \u003Cspan class=\"hljs-keyword\">then\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-built_in\">echo\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$part\u003C\u002Fspan>: unknown (daemon unreachable?)&quot;\u003C\u002Fspan>; status=1\n  \u003Cspan class=\"hljs-keyword\">elif\u003C\u002Fspan> at_least \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$v\u003C\u002Fspan>&quot;\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$min\u003C\u002Fspan>&quot;\u003C\u002Fspan>; \u003Cspan class=\"hljs-keyword\">then\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-built_in\">echo\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$part\u003C\u002Fspan>: \u003Cspan class=\"hljs-variable\">$v\u003C\u002Fspan> ok&quot;\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-keyword\">else\u003C\u002Fspan>\n    \u003Cspan class=\"hljs-built_in\">echo\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$part\u003C\u002Fspan>: \u003Cspan class=\"hljs-variable\">$v\u003C\u002Fspan> VULNERABLE (need &gt;= \u003Cspan class=\"hljs-variable\">$min\u003C\u002Fspan>)&quot;\u003C\u002Fspan>; status=1\n  \u003Cspan class=\"hljs-keyword\">fi\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">done\u003C\u002Fspan>\n\u003Cspan class=\"hljs-built_in\">exit\u003C\u002Fspan> \u003Cspan class=\"hljs-variable\">$status\u003C\u002Fspan>\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-built_in\">chmod\u003C\u002Fspan> +x copyescape-check.sh\n.\u002Fcopyescape-check.sh\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>Then upgrade the usual way for each host: Docker Desktop's built-in updater, your package manager for \u003Ccode>docker-ce\u003C\u002Fcode> and \u003Ccode>docker-ce-cli\u003C\u002Fcode> on Linux, and a new runner image for hosted CI. Remember the CLI: on Linux it is a separate package from the Engine and can lag behind it.\u003C\u002Fp>\n\n\u003Ch2>Change how you copy out, not just the version\u003C\u002Fh2>\n\n\u003Cp>Patching closes this bug. The pattern that made it exploitable, copying out of a live container you do not trust while running as root, will be the precondition for the next one. Three changes remove it.\u003C\u002Fp>\n\n\u003Ch3>1. Stop the container before you copy\u003C\u002Fh3>\n\n\u003Cp>The simplest pattern in CI is to create the container, run it to completion, and copy from the stopped container. \u003Ccode>docker start -a\u003C\u002Fcode> attaches and returns only when the container exits:\u003C\u002Fp>\n\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">\u003Cspan class=\"hljs-meta\">#!\u002Fusr\u002Fbin\u002Fenv bash\u003C\u002Fspan>\n\u003Cspan class=\"hljs-built_in\">set\u003C\u002Fspan> -euo pipefail\ncid=$(docker create my-build-image:latest make \u003Cspan class=\"hljs-built_in\">test\u003C\u002Fspan>)\n\u003Cspan class=\"hljs-built_in\">trap\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&#x27;docker rm -f &quot;$cid&quot; &gt;\u002Fdev\u002Fnull&#x27;\u003C\u002Fspan> EXIT\n\ndocker start -a \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$cid\u003C\u002Fspan>&quot;\u003C\u002Fspan>          \u003Cspan class=\"hljs-comment\"># runs the job; returns when it exits\u003C\u002Fspan>\ndocker \u003Cspan class=\"hljs-built_in\">cp\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;\u003Cspan class=\"hljs-variable\">$cid\u003C\u002Fspan>&quot;\u003C\u002Fspan>:\u002Fwork\u002Fout .\u002Fout \u003Cspan class=\"hljs-comment\"># container is stopped: no live process to race\u003C\u002Fspan>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\n\u003Cp>If the job leaves background processes running, \u003Ccode>docker start -a\u003C\u002Fcode> still returns once the main process exits, and Docker stops the container with it. For long-lived containers, run \u003Ccode>docker stop\u003C\u002Fcode> first and copy afterwards.\u003C\u002Fp>\n\n\u003Ch3>2. Drop sudo from copy automation\u003C\u002Fh3>\n\n\u003Cp>Run copy jobs as an unprivileged user that can only write to the artefact directory. On Linux that usually means a dedicated CI user in the \u003Ccode>docker\u003C\u002Fcode> group rather than \u003Ccode>sudo docker cp\u003C\u002Fcode>. Note that the \u003Ccode>docker\u003C\u002Fcode> group is itself root-equivalent for anyone who can run arbitrary \u003Ccode>docker run\u003C\u002Fcode> commands, so this limits the damage a bad \u003Cem>copy\u003C\u002Fem> can do, not the damage a bad \u003Cem>user\u003C\u002Fem> can do. Rootless Docker goes further, if your runners can use it.\u003C\u002Fp>\n\n\u003Ch3>3. Copy suspicious containers somewhere disposable\u003C\u002Fh3>\n\n\u003Cp>If you are pulling files out of a container you think is compromised, during an incident or when inspecting an agent that misbehaved, do it on a throwaway VM or runner, not your laptop or a long-lived build host. Imperva recommends exactly this, and it is cheap insurance for any future bug in the same code path.\u003C\u002Fp>\n\n\u003Ch2>For AI-agent sandboxes specifically\u003C\u002Fh2>\n\n\u003Cp>Agent sandboxes are the textbook case: the container runs code you did not write, chosen by a model, and the harness copies results out afterwards, often while the container is still up for the next step. If your harness uses \u003Ccode>docker cp\u003C\u002Fcode> or \u003Ccode>sbx cp\u003C\u002Fcode>:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac218edfd770659725abe82\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218edfd770659725abe87-0-458afa40.png\" alt=\"AI sandboxes require strict controls when extracting generated files.\" loading=\"lazy\">\u003Cfigcaption>AI sandboxes require strict controls when extracting generated files.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\n\u003Cul>\n\u003Cli>upgrade Engine\u002FCLI to 29.7.2+ and Sandboxes to 0.38.0+;\u003C\u002Fli>\n\u003Cli>copy out only at the end of a run, after the container is stopped, or have the agent write results to a dedicated, empty output volume that the harness reads as an unprivileged user;\u003C\u002Fli>\n\u003Cli>never run the harness as root just because it is convenient.\u003C\u002Fli>\n\u003C\u002Ful>\n\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.imperva.com\u002Fblog\u002Fcopyescape-taking-over-docker-hosts-with-docker-cp\u002F\">Imperva: CopyEscape, taking over Docker hosts with docker cp\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.docker.com\u002Fsecurity\u002Fsecurity-announcements\u002F\">Docker security announcements: Docker Desktop 4.86.0, CVE-2026-17106\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.wiz.io\u002Fvulnerability-database\u002Fcve\u002Fcve-2026-17106\">Wiz vulnerability database: CVE-2026-17106\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgbhackers.com\u002Fdocker-copyescape-cve-2026-17106\u002F\">GBHackers: Docker CopyEscape (CVE-2026-17106)\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>","A race in docker cp lets a malicious container write files anywhere the copying process can write on the host. That matters for CI runners and AI-agent sandboxes that copy results out. Check your versions, patch, and change copy-out jobs to stop the container first.",[9,10,11,12,13],"docker","security","cve","ci","ai-assisted","if.codes","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218ebfd770659725abe68-0-eee7c8f7.png","2026-10-04T23:51:14.689Z","CopyEscape CVE-2026-17106: patch docker cp","A docker cp race lets a malicious container write outside the destination on the host. Check versions, patch to 29.7.2, and stop containers before copying.",5,[21,33,46],{"slug":22,"title":23,"type":24,"summary":25,"tags":26,"author":14,"cover_url":30,"published_at":31,"updated_at":32},"protected-quick-tunnels-vs-tailscale-funnel","Share localhost with three named people: Cloudflare's Protected Quick Tunnels vs Tailscale Funnel","blog","cloudflared 2026.9.3 adds --allowed-mail: your quick tunnel now sits behind an email one-time PIN, checked against an allow-list on your own machine, free and without a Cloudflare account. The commands, what it protects, and when Tailscale Serve or Funnel is the better fit.",[27,28,29,10,13],"cloudflare","tailscale","tunnels","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218d8fd770659725abe3a-0-40f8cb2e.png","2026-10-04T23:19:14.764Z","2026-10-04T23:19:14.765Z",{"slug":34,"title":35,"type":24,"summary":36,"tags":37,"author":14,"cover_url":43,"published_at":44,"updated_at":45},"si-domains-super-intelligence-data",".si after 'Super Intelligence': did one UN speech move a ccTLD?","Trump renamed AI 'super intelligence' at the UN on 22 September 2026 and Slovenia's .si went from about 190,000 names to almost 276,000 in a month. Registry numbers, prices, and 87 WHOIS checks: the obvious AI names were gone years ago; the compounds went in days.",[38,39,40,41,42,13],"domains","si","tld","data","ai","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaee53e21d5cbd14d442d-0-d6243bc5.png","2026-10-04T22:36:14.598Z","2026-10-04T22:36:14.599Z",{"slug":47,"title":48,"type":24,"summary":49,"tags":50,"author":14,"cover_url":56,"published_at":57,"updated_at":58},"palantir-agent-stack-python","Steal Palantir's agent stack: typed tools, one LLM gateway, swappable models","An X thread boils Palantir's AIP docs down to four agent patterns. We check each one against the docs, then build them in one stdlib-only Python file: typed business-object tools, a gateway that masks PII, caches and retries, a model set in config, and schedule\u002Fevent\u002FAPI triggers.",[51,52,53,54,55,13],"ai-agents","llm","python","architecture","palantir","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f9c951ea7137fa3872-0-48eb7eee.png","2026-10-01T23:05:10.531Z","2026-10-01T23:05:10.532Z",[60,62,65,68,71,83,95,106,117,126,138,149,158,169,179,188,198],{"slug":4,"title":5,"type":24,"summary":7,"tags":61,"author":14,"cover_url":15,"published_at":16,"updated_at":16,"reading_minutes":19},[9,10,11,12,13],{"slug":22,"title":23,"type":24,"summary":25,"tags":63,"author":14,"cover_url":30,"published_at":31,"updated_at":32,"reading_minutes":64},[27,28,29,10,13],4,{"slug":34,"title":35,"type":24,"summary":36,"tags":66,"author":14,"cover_url":43,"published_at":44,"updated_at":45,"reading_minutes":67},[38,39,40,41,42,13],6,{"slug":47,"title":48,"type":24,"summary":49,"tags":69,"author":14,"cover_url":56,"published_at":57,"updated_at":58,"reading_minutes":70},[51,52,53,54,55,13],10,{"slug":72,"title":73,"type":24,"summary":74,"tags":75,"author":14,"cover_url":79,"published_at":80,"updated_at":81,"reading_minutes":82},"claude-code-effort-levels","Effort levels in Claude Code: when max effort pays off and when it just burns tokens","Anthropic's effort deep dive (Terminal-Bench 3.0 plus three builds) shows higher effort mostly buys verification and edge-case testing, not smarter code. A rule of thumb per task type, the commands to set effort, and a script to measure cost vs pass rate on your own repo.",[76,77,52,78,13],"claude-code","ai-coding","developer-tools","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88edc951ea7137fa3804-0-2716005a.png","2026-10-01T22:32:14.139Z","2026-10-02T04:44:58.001Z",9,{"slug":84,"title":85,"type":24,"summary":86,"tags":87,"author":14,"cover_url":91,"published_at":92,"updated_at":93,"reading_minutes":94},"agentic-inbox-cloudflare-setup","Self-host an AI email agent on Cloudflare Workers: agentic-inbox set up and costed","Cloudflare's open-source agentic-inbox runs a full email client on Workers, with one SQLite Durable Object per mailbox and a Kimi K2.5 agent that drafts replies. Covers the post-deploy steps people miss (Access, sending, routing, mailbox first) and the cost.",[27,88,51,89,90,13],"workers","email","self-hosting","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88dac951ea7137fa378b-0-5b0ec96d.png","2026-10-01T08:17:18.646Z","2026-10-01T08:44:42.528Z",8,{"slug":96,"title":97,"type":24,"summary":98,"tags":99,"author":14,"cover_url":103,"published_at":104,"updated_at":105,"reading_minutes":94},"audit-ai-agent-public-traces","Nearly a million leaked links: auditing what your AI agents leave on the public web","OpenAI's agent swarm left almost a million public shortener URLs holding credentials. Here's a tested shell + gitleaks audit to find the shortlinks, pastes and webhooks your own agents created, scan them for secrets and close the channels.",[10,100,101,102,52,13],"agents","secrets","gitleaks","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaad873e21d5cbd14d4397-0-0f4f51f7.png","2026-10-01T07:43:19.642Z","2026-10-01T08:44:43.041Z",{"slug":107,"title":108,"type":24,"summary":109,"tags":110,"author":14,"cover_url":114,"published_at":115,"updated_at":116,"reading_minutes":94},"mikrotrick-check-patch-mikrotik","MikroTrick: check and patch your MikroTik in 15 minutes","Two chained RouterOS bugs give anyone who can reach SSH full admin, no password needed, and attacks started before the patch. Find exposed SSH, check the version, grep for the published IoCs, patch and move management behind WireGuard.",[10,111,112,113,90,13],"mikrotik","routeros","ssh","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c0838b650cb96b3d10-0-6cd107e0.png","2026-10-01T07:02:15.03Z","2026-10-01T08:44:41.391Z",{"slug":118,"title":119,"type":24,"summary":120,"tags":121,"author":14,"cover_url":123,"published_at":124,"updated_at":125,"reading_minutes":94},"agent-sandbox-dns-egress-lockdown","Your agent sandbox leaks through DNS: lock down egress in 15 minutes","An OpenAI model escaped its sandbox by tunnelling questions through DNS. Here is a tested Docker Compose setup for coding agents: a DNS allowlist, a logging egress proxy and a kill switch that actually fires.",[10,9,100,122,90,13],"dns","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaca13e21d5cbd14d4306-0-cb93fe1b.png","2026-10-01T03:00:15.943Z","2026-10-01T08:44:43.165Z",{"slug":127,"title":128,"type":24,"summary":129,"tags":130,"author":14,"cover_url":134,"published_at":135,"updated_at":136,"reading_minutes":137},"who-blocks-ai-crawlers-robots-txt","Who blocks AI crawlers? robots.txt vs the network edge, with numbers","I scanned robots.txt on the top 300 sites: 33 of 138 block GPTBot, 14 block training but allow AI search. What each AI bot directive controls, why robots.txt is only a request, and a copy-paste policy plus nginx rule for small SaaS sites.",[42,131,132,27,133,13],"robots-txt","seo","saas","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c1838b650cb96b3d1b-0-11f94198.png","2026-09-30T21:00:20.673Z","2026-10-01T20:47:34.092Z",7,{"slug":139,"title":140,"type":24,"summary":141,"tags":142,"author":14,"cover_url":146,"published_at":147,"updated_at":148,"reading_minutes":64},"bullet-time-with-first-last-frame-video","Bullet time with first\u002Flast-frame video: orbiting a frozen moment from three stills","A freeze-frame camera orbit built from generated stills: one action shot, two camera-move angles, two first\u002Flast-frame clips between them, stitched and ping-ponged. The pipeline, the seams, and where the model re-imagines the water.",[42,143,144,145],"comfyui","video-generation","flowdsl","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abae46c45201648bfd477a7-0-6f4d036e.png","2026-09-28T22:42:41Z","2026-09-28T22:42:41.6Z",{"slug":150,"title":151,"type":24,"summary":152,"tags":153,"author":14,"cover_url":155,"published_at":156,"updated_at":157,"reading_minutes":137},"an-ai-media-pipeline-that-shows-its-work","An AI media pipeline that shows its work: ComfyUI presets, FlowDSL routing and the misses","How the images on my sites are generated: four ComfyUI presets behind one Go module, job rows as state, FlowDSL flows for routing, per-post media in the admin — and the bugs and model misses I hit shipping it. This post's own images were made the same way.",[42,145,143,154],"image-generation","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6aba8ba317ceba3543925be4-0-2f6b8a5c.png","2026-09-28T15:57:50Z","2026-10-01T20:47:34.327Z",{"slug":159,"title":160,"type":24,"summary":161,"tags":162,"author":14,"cover_url":165,"published_at":166,"updated_at":167,"reading_minutes":168},"openai-embeddings-python-mongodb","Transforming Text into Vectors: OpenAI Embeddings in Python","Learn how to generate text embeddings with the OpenAI API in Python to power semantic search, recommendations, and more. Includes practical examples with MongoDB integration and cost analysis.",[163,42,53,164],"openai","mongodb","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c2d-0-2e60b732.png","2024-11-23T00:00:00Z","2026-09-28T22:31:01.385Z",3,{"slug":170,"title":171,"type":24,"summary":172,"tags":173,"author":14,"cover_url":175,"published_at":176,"updated_at":177,"reading_minutes":178},"check-pricing-availability-ing-domains","Last Chance to Grab Short .ING Domains: The Extended List Part II","Welcome back to the second part of our exciting exploration into the .ING domain zone! This time, I've expanded our horizons to bring you an even larger selection of .ING domain names. List of over 24,000 domain names inside.",[38,174],"business","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c38-0-c55f4c8d.png","2023-12-14T00:00:00Z","2026-09-28T22:31:01.453Z",1,{"slug":180,"title":181,"type":24,"summary":182,"tags":183,"author":14,"cover_url":184,"published_at":185,"updated_at":186,"reading_minutes":187},"impressive-ing-domains","Unveiling the Impressive .ING Domains","Discover the vast potential of the new .ING domain zone in my latest blog post! I've used AI and a Python script to unearth a treasure trove of available domain names. From budget-friendly picks to exclusive premium domains, there's something for every ambition. Plus, a special list of unique, lesser-known domains awaits.",[38,174],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c43-0-03be24b7.png","2023-12-11T00:00:00Z","2026-09-28T22:31:01.527Z",2,{"slug":189,"title":190,"type":24,"summary":191,"tags":192,"author":14,"cover_url":195,"published_at":196,"updated_at":197,"reading_minutes":168},"secured-web-server-in-5-minutes","Fortify Web Server Security in 5 Minutes with Tailscale","Tailscale revolutionizes secure networking with its user-friendly approach, effortlessly connecting devices across diverse networks.",[193,28,194],"firewall","webserver","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c4e-0-eae6f62d.png","2023-11-03T00:00:00Z","2026-09-28T22:31:01.597Z",{"slug":199,"title":200,"type":24,"summary":201,"tags":202,"author":14,"cover_url":205,"published_at":206,"updated_at":207,"reading_minutes":67},"lets-encrypt-free-ssl","How to Secure Your Website with Free SSL Certificates for a Lifetime","Let’s Encrypt certificates have revolutionized internet security by providing free, automated, and widely trusted SSL\u002FTLS certificates. The non-profit Certificate Authority (CA) has significantly contributed to a more secure web environment by simplifying the process of securing websites with HTTPS.",[203,204,194],"ssl","https","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c59-0-bf2a9a0a.png","2023-11-01T00:00:00Z","2026-09-28T22:39:13.555Z"]