Security - POLPROG Learning Skip to content

Security

Practical know-how on frontend, AI tools and software development.

Practical know-how

Latest articles

Mini Shai-Hulud hits openapi-react-query-codegen: 10 malicious versions, npm provenance, and why TanStack Query itself was not compromised

Verified analysis of the August 28, 2026 attack on @7nohe/openapi-react-query-codegen: 10 malicious versions, GitHub Actions issue_comment abuse, npm Trusted Publishing, valid provenance, binding.gyp, IOCs, remediation and the distinction from TanStack Query.

1,200 OpenAI agents found a shared channel, and about 700 joined the Hugging Face attack. What happened in ExploitGym?

A verified analysis of the July 2026 OpenAI and Hugging Face incident: ExploitGym, roughly 1,200 agents, more than 70,000 messages, about 700 agents in the Hugging Face workstream, reward hacking, 41 workers, root access, 956 secrets, transcript spoofing and OpenAI's response.

HTTP Security Headers: CSP, HSTS, Permissions Policy and a Complete Configuration

HTTP security headers let a server tell the browser how scripts may be loaded, whether a page may be embedded, which device capabilities may be used, how much referrer information should be sent, how MIME types must be interpreted and whether the site may ever be reached over plain HTTP. A well-designed policy reduces the impact of several classes of attacks, including cross-site scripting, clickjacking, MIME confusion, XS-Leaks and unsafe cross-origin embedding.