Start Debugging

The security tracker

The patches, configs, and guardrails worth acting on.

This pillar collects everything on the site about security: authentication in ASP.NET Core, the CVE patches worth upgrading for, serialization and supply-chain risks, keeping secrets out of logs and prompts, and the guardrails a coding agent needs before you let it run unattended.

What to read first

For web apps, JWT vs cookie authentication settles the model, and validating a JWT’s issuer, audience, and lifetime is the config people get wrong. On the data side, migrating off BinaryFormatter removes the classic deserialization hole, and redacting sensitive values from logs keeps PII out of your sinks. For the supply chain, the NuGet signing-certificate rotation and Flutter 3.47.1 blocking plugin-registrant injection are the recent ones to act on.

For coding agents, start with a strict network egress allowlist and a credential gateway so the agent never holds a real key. Information-flow control is the structural answer to prompt injection, and the four permission-check bypasses closed in Claude Code 2.1.251 show why version pinning matters.

What’s on this page

The list below auto-collects posts tagged with any of: security, prompt-injection, jwt, authentication, cryptography. Newest first.

Companion pillars: the ASP.NET Core 11 cheat sheet and the coding agents tracker.

Index (47 posts)

2026 / 09

2026 / 08

2026 / 07

2026 / 06

2026 / 05

2026 / 04

2026 / 02

All pillars Home