The security tracker
The patches, configs, and guardrails worth acting on.
This pillar collects everything on the site about security: authentication in ASP.NET Core, the CVE patches worth upgrading for, serialization and supply-chain risks, keeping secrets out of logs and prompts, and the guardrails a coding agent needs before you let it run unattended.
What to read first
For web apps, JWT vs cookie authentication settles the model, and validating a JWT’s issuer, audience, and lifetime is the config people get wrong. On the data side, migrating off BinaryFormatter removes the classic deserialization hole, and redacting sensitive values from logs keeps PII out of your sinks. For the supply chain, the NuGet signing-certificate rotation and Flutter 3.47.1 blocking plugin-registrant injection are the recent ones to act on.
For coding agents, start with a strict network egress allowlist and a credential gateway so the agent never holds a real key. Information-flow control is the structural answer to prompt injection, and the four permission-check bypasses closed in Claude Code 2.1.251 show why version pinning matters.
What’s on this page
The list below auto-collects posts tagged with any of: security, prompt-injection, jwt, authentication, cryptography. Newest first.
Companion pillars: the ASP.NET Core 11 cheat sheet and the coding agents tracker.
Index (47 posts)
2026 / 09
- How to Run a Coding Agent in a Disposable VM or Container Instead of on Your Laptop
Dev containers, Docker Sandboxes microVMs, Lima VMs, and hosted cloud sandboxes all move Claude Code, Codex, or Copilot CLI off your host. What each one actually isolates, the exact commands to make it throwaway, and the two things none of them protect: your writable workspace and your git hooks.
- How to Keep API Keys Out of a Coding Agent's Context With a Credential Gateway
Scoping a token does not stop a prompt-injected agent from leaking it. Moving the token out of the agent's process does. Three working setups: a 50-line gateway any agent can call, Claude Code 2.1.199+ sandbox masking with injectHosts, and Claude Managed Agents vaults, plus the measured leak that host-level injection still allows.
- Microsoft Is Rotating Its NuGet Author-Signing Certificate: Fix trustedSigners Before NU3034 Hits
Starting September 23, 2026, Microsoft packages on NuGet get author-signed with a new certificate (SHA-256 9A1B131B...). If your nuget.config pins Microsoft in trustedSigners, restores will fail with NU3034. Here is the fix, including the correct dotnet nuget trust command.
- How to block a Flutter WebView from navigating to external URLs with NavigationDelegate
Keep a Flutter WebView on your own domain with webview_flutter 4.14.1: parse the URL, compare Uri.host instead of startsWith, hand mailto: and tel: to url_launcher, and know what Android and iOS actually send to onNavigationRequest.
- How to disable antiforgery validation for a single minimal API form endpoint in ASP.NET Core 11
Call .DisableAntiforgery() on the one endpoint, or on a MapGroup. In ASP.NET Core 11 that opts out of both the token middleware and the new automatic CSRF check. Measured matrix, precedence traps, and narrower alternatives.
- MessagePack 3.1.9 and 2.5.303 Fix a 32 KiB Payload That Allocates 120 MiB
CVE-2026-92707: nested MessagePack array headers could reuse the same trailing bytes to pass the length check, so deserializing into object allocated thousands of times the payload size. The fix, a before/after probe, and why SignalR apps on .NET 8 through 11 RC 1 need a direct package pin.
- Fix: GitHub Copilot can't see a file because a content exclusion rule excludes it
"File is configured to be ignored by Copilot" or "Some files were excluded from the context" means a content exclusion rule matched. How to find the rule, why globs over-match, and how to narrow it.
- Fix: ASP.NET Core API endpoints return 401 instead of redirecting to the login page after upgrading to .NET 10
In .NET 10 cookie auth answers API-style endpoints with 401/403 instead of a login redirect. Restore it per endpoint, globally, or with an AppContext switch.
- Agent Framework 1.21: LocalCodeAct Stops Handing Your Host Environment to Model-Written Python
Microsoft Agent Framework .NET 1.21.0 ships Microsoft.Agents.AI.LocalCodeAct 1.21.0-preview.260911.1, which no longer lets the CodeAct Python subprocess inherit the parent environment when Environment is null. On 1.20, generated code could read every host variable, API keys included.
- Fix: IsAuthenticated is false and RemoteUserAccount is null in Blazor WebAssembly after an MSAL upgrade
Microsoft.Authentication.WebAssembly.Msal 10.0.8, 9.0.16 and 8.0.27 moved to msal.js 4, whose async init races itself. Initialize MSAL once in Program.cs, or pin 10.0.7.
- What is the W^X flag in .NET and does Native AOT need it?
W^X (write xor execute) is the rule that no memory page is writable and executable at the same time. In .NET it is the DOTNET_EnableWriteXorExecute knob, on by default since .NET 7, and it exists entirely for the JIT. Native AOT never reads it. Here is how the runtime implements it, what it costs, and when turning it off is a legitimate fix.
- Claude Code 2.1.259 Adds managedMcpServers: Ship MCP Servers Without MDM
Until now the only way to hand every developer the same MCP servers was managed-mcp.json, a file at a system path that takes exclusive control of MCP. Claude Code 2.1.259 adds a managedMcpServers setting for HTTP and SSE servers, and quietly narrows what allowedMcpServers governs.
- Information-Flow Control for AI Agents: Blocking Prompt Injection With Labels, Not Prompts
Defensive system prompts are heuristic. Information-flow control is not: label every piece of content with integrity and confidentiality, propagate most-restrictive-wins through every tool call, and check the label at the sink before it runs. An 80-line runnable harness, the Agent Framework FIDES implementation, and the false positives the pattern buys you.
- Migrate off BinaryFormatter after its removal in modern .NET
BinaryFormatter's implementation was deleted in .NET 9 and still throws PlatformNotSupportedException on .NET 10 and .NET 11: how to choose a replacement serializer, read already-persisted NRBF blobs with NrbfDecoder, and what breaks in WinForms, WPF, and ResX.
2026 / 08
- Claude Code 2.1.251 Closes Four Ways Around the Permission Check
A symlink swapped after the check, deny rules that stopped applying through a symlinked search path, a marketplace command pointing outside its plugin, and a workflow script read before approval. Four fixes in one release, all the same bug.
- Claude Code 2.1.238 Lets a Plugin Marketplace Mint Its Own Auth Headers
A headersHelper field on url marketplaces and catalog entries runs a local command that prints HTTP headers, so an internal plugin catalog behind S3 or an artifact repo can authenticate with a short-lived token. Here is the schema, the consent prompt, and the header names Claude Code drops.
- Flutter 3.47.1 Stops a Transitive Package From Injecting Native Code Into Your App
The 3.47.1 hotfix validates plugin class and package identifiers before they land in GeneratedPluginRegistrant. Here is the hole it closes, the regex that closes it, and the other 11 fixes in the release.
- Semantic Kernel 1.80.0 Stops OpenAPI Plugins From Following Redirects
Semantic Kernel .NET 1.80.0 ships a breaking change: the OpenAPI plugin's default HttpClient no longer follows redirects, closing an SSRF bypass. Here is what changes and why your own HttpClient reopens the hole.
- How to Centrally Control Which MCP Servers Your Team Can Run
Claude Code and GitHub Copilot both ship allowedMcpServers and deniedMcpServers, but the matchers behave differently. serverName is a fallback that a single serverCommand entry silently disables, deny is a union while allow is not, and an invalid allowlist locks everything out.
- How to redact sensitive values from logs with LogProperties and data redaction in .NET
A complete guide to redacting classified data in source-generated logs: build a taxonomy, write a Redactor, wire EnableRedaction and AddRedaction, and understand the discriminator that silently breaks partial masking. With real output from Microsoft.Extensions.Compliance.Redaction 10.9.0.
- System.IO.Compression Finally Reads and Writes Encrypted ZIPs in .NET 11 Preview 7
.NET 11 Preview 7 adds password-protected ZIP entries to System.IO.Compression, with AES-256 support, options types for whole-directory operations, and one empty-file bug that is already fixed in main.
- Safe File-Write Tools for an Agent: Preview, Confirm, Apply
A write tool that asks before it writes needs three things the MCP SDK does not give you: an approval bound to the exact diff, a precondition on the file it previewed, and an integrity-protected requestState. Verified end to end on @modelcontextprotocol/server 2.0.0 against protocol revision 2026-07-28, including the argument-swap that gets past a naive confirm.
- Copilot MCP Allowlists Land in Enterprise Managed Settings
GitHub's August 6, 2026 changelog adds allowedMcpServers and deniedMcpServers to copilot/managed-settings.json. URL and argv matchers, deny-wins precedence, and a fail-closed default the older name-based registry never had.
- Auto Mode vs Manual Approval in Claude Code: What Each Mode Actually Allows Through
Manual gates every tool call on you. Auto mode gates them on a classifier with 32 built-in block rules. The mode that surprises people is neither: acceptEdits auto-approves rm, mv, and sed, not just file edits. Measured on Claude Code 2.1.123.
- NuGet API Keys Get a 30-Day Cap on August 17, and Every Old Key Expires November 1
NuGet.org drops the 365-day API key option on August 17, 2026, caps new keys at 30 days, and expires every key created before that date on November 1. Here is what breaks and how to move a publish workflow to OIDC trusted publishing.
- Fix: "Write(src/**) is not matched by file permission checks" in Claude Code
Claude Code only consults Edit(path) and Read(path) rules. A Write(src/**) allow or deny rule is accepted and then silently ignored. Use Edit() instead.
2026 / 07
- How to Lock Down a Coding Agent's Network Egress With a Strict Host Allowlist
Claude Code, Cursor, and the GitHub Copilot coding agent all ship host allowlists for outbound traffic, and all three default to something looser than you want. The exact settings keys, a policy you can copy, and the four surfaces the allowlist does not cover.
- ASP.NET Core 11 Preview 6 turns on automatic CSRF protection
Preview 6 rejects unsafe cross-origin browser requests by default, reading the Sec-Fetch-Site header instead of an antiforgery token. Here is what it blocks and how to opt out.
- DuneSlide: Two Cursor Bugs That Turn Prompt Injection Into Zero-Click RCE
Cato AI Labs disclosed CVE-2026-50548 and CVE-2026-50549, a pair of 9.8 CVSS flaws in Cursor's terminal sandbox. A poisoned MCP response or web result can escape the sandbox and run code. Cursor 3.0 is the fix.
- How to set up JWT bearer authentication in a minimal API in ASP.NET Core 11
A complete, working setup for JWT bearer authentication in an ASP.NET Core 11 minimal API: install the package, wire up AddAuthentication().AddJwtBearer(), issue a token, protect endpoints with RequireAuthorization, add role and claim policies, and test the whole thing with dotnet user-jwts.
2026 / 06
- JWT vs cookie authentication in ASP.NET Core 11: which should you pick?
Use cookie authentication for any app where the browser is the only client, and reserve JWT bearer tokens for APIs called by mobile apps, other services, or third parties. Here is the full decision matrix.
- Claude Code 2.1.187 Stops the Sandbox From Reading Your AWS Keys
The new sandbox.credentials setting in Claude Code v2.1.187 denies reads of credential files and unsets secret env vars before sandboxed Bash commands run. Here is why the default read policy was a hole, and how to close it.
- Fix: 405 Method Not Allowed instead of 401 with JWT bearer in ASP.NET Core
A protected endpoint returning 405 instead of 401 almost always means routing rejected the HTTP verb before auth ran, or a cookie scheme stole the challenge. Here is how to tell which.
- Why your ASP.NET Core JWT returns 401 even with a valid token
A valid token that still 401s almost always means the bearer handler never ran or ran under the wrong scheme. Check middleware order, the default scheme, the scheme name, and whether the header even reached the handler.
- How to add policy enforcement and audit logging to a Microsoft Agent Framework agent
Wire the Agent Governance Toolkit into a Microsoft Agent Framework 1.0 agent so every tool call is checked against a YAML policy and written to a tamper-evident audit trail. Full C# middleware, policy file, and a hash-chained audit sink.
- How to validate a JWT's issuer, audience, and lifetime in ASP.NET Core 11
A complete guide to TokenValidationParameters in ASP.NET Core 11: how ValidateIssuer, ValidateAudience, and ValidateLifetime work, what the defaults actually are, why Authority auto-configures the issuer and signing keys, the 5-minute ClockSkew trap, and how to read the IDX error codes when a valid-looking token is rejected.
- How to configure CORS for a JWT-protected API in ASP.NET Core 11
A complete guide to CORS for a bearer-token API in ASP.NET Core 11: the correct UseCors ordering relative to authentication, why a bearer token in the Authorization header is not a CORS credential, why AllowAnyHeader works but a manual wildcard does not cover Authorization, and how to keep preflight from failing.
- X25519 Key Agreement Lands In-Box in .NET 11 Preview 5
.NET 11 Preview 5 adds a first-class X25519DiffieHellman type to System.Security.Cryptography, so you can do Curve25519 key exchange without BouncyCastle or NSec.
- Claude Code's Security-Guidance Plugin Reviews Its Own Diffs Before You Commit
Anthropic shipped a free security-guidance plugin for Claude Code that scans the agent's own edits for vulnerabilities in three layers, from a no-cost pattern match to an agentic review on commit.
2026 / 05
- NuGet Package Pruning Is On by Default in .NET 10
NuGet Package Pruning shipped on-by-default for net10.0 projects, cutting transitive vulnerability reports by 70% and restore times by up to 50%.
- Fix: System.Security.Cryptography.CryptographicException: Keyset does not exist
The certificate's private key lives in a separate Windows key file the current process identity cannot read. Grant ACL on the key, load the PFX with MachineKeySet, or use EphemeralKeySet.
- Agent Governance Toolkit puts a YAML policy in front of every MCP tool call from .NET
Microsoft's new Microsoft.AgentGovernance package wraps MCP tool calls with a policy kernel, a security scanner, and a response sanitizer. Here is what each piece does and how the wiring looks in C#.
2026 / 04
- How to add OpenAPI authentication flows to Swagger UI in .NET 11
In .NET 11 the OpenAPI document is generated by Microsoft.AspNetCore.OpenApi and Swagger UI is no longer in the template. Here is how to wire Bearer, OAuth2 with PKCE, and OpenID Connect so the Authorize button actually works.
- How to implement refresh tokens in ASP.NET Core Identity
Two working paths in .NET 11: the built-in MapIdentityApi /refresh endpoint, and a custom JWT setup with refresh token rotation, family tracking, and reuse detection.
- Aspire 13.2.4 Patches CVE-2026-40894: Baggage Header DoS in OpenTelemetry .NET
Aspire 13.2.4 ships an OpenTelemetry bump for CVE-2026-40894, a Gen0 allocation amplification in baggage, B3, and Jaeger propagator parsing. Update OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators to 1.15.3 even if you are not on Aspire.
- .NET 10.0.7 Ships Out-of-Band to Fix CVE-2026-40372 in ASP.NET Core Data Protection
A HMAC validation flaw in Microsoft.AspNetCore.DataProtection 10.0.0 through 10.0.6 lets attackers forge ciphertexts. .NET 10.0.7 is the mandatory fix.
2026 / 02
- .NET 10 Post-Quantum Cryptography: ML-KEM, ML-DSA, and SLH-DSA
.NET 10 adds native support for post-quantum cryptography algorithms ML-KEM, ML-DSA, and SLH-DSA, preparing your applications for a quantum-resistant future.