Link List
Welcome to my link library. These are not links to content I have created unless you see that mentioned in the link’s description. These are links I found interesting enough to want to keep track of. If you read Craft Link List, the Craft CMS newsletter I used to write, this page is a replacement of sorts for that exercise. Enough talk. Let’s hit the links.
Tagged with ”security”
Reset tag searchVellumproof — Your novel, entered into evidence
Vellumproof creates tamper-evident records of manuscript drafts with cryptographic seals and timestamping to prove human authorship and writing progression. Writers upload files as they work; each version is chained to the previous one, preventing backdating or alteration. The service generates verifiable proof pages for publishers and contests while keeping manuscripts private and never using them to train AI models.
guillaumemeyer/watermarks-remover: Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD
Open-source tool to remove AI watermarks, metadata, and provenance marks (C2PA, EXIF, XMP) from text and files including PNG, JPEG, PDF, DOCX, and HTML. Handles invisible Unicode, statistical text watermarks, and marks from Claude, Gemini/SynthID, and OpenAI. Available as Python scripts or Grok agent skill.
OpenAI says its AI went rogue and launched 'unprecedented' cyber-attack
It is one of the first publicly disclosed cyber-attacks carried out by AI without direct human involvement.
Honda Radar Shield by Miller CAT – Miller CAT Corp
Honda Radar Shield by Miller CAT protects the front radar distance sensor behind your Honda’s grille emblem from theft. Made from USA-manufactured 16-gauge stainless steel, it safeguards adaptive cruise control and collision mitigation systems without obstructing radar performance.
Moving from 1Password to iCloud Keychain
Here’s how to easily move your passwords from 1Password to iCloud Keychain
Prompt Injection Standardization: Text Techniques vs Intent
Explore Lasso’s prompt injection taxonomy, distinguishing text-based techniques from attacker intent to standardize AI security defenses.
Login Lockdown
Prevents brute force password attacks on the Craft CMS control panel by tracking failed login attempts per IP address and blocking access after a configurable threshold.
Security Overview · craftcms/cms
Craft CMS’s security overview details their commitment to timely updates. It outlines the process for reporting, triaging, and disclosing vulnerabilities.
kevinslin/safe-npm: Safely install NPM packages
A security-focused npm installer that protects your projects from newly compromised packages.
NATO Security posters
Internal security has always been a NATO priority. Over the years, the posters, cards, and calendars below have adorned the walls and the desks inside the Headquarters, reminding NATO employees of the importance of discretion. These cultural artifacts are testimonials to the preoccupations of our times.
Password Basket
Generate strong and secure passwords by collecting letters, numbers, and symbols in a basket
I use Zip Bombs to Protect my Server
A deep dive into the technical world of zip bombs, exploring how a minuscule compressed file can be weaponized to overwhelm and crash systems by expanding to gigantic proportions.
craftcms/security-patches: Provides security patches for out-of-date Craft CMS installs
Provides security patches for out-of-date Craft CMS installs — craftcms/security-patches
HTTP Security Headers: A complete guide to HTTP headers
HTTP Security Headers are essential to any website. Learn about the HSTS header, Content Security Policy header CSP, XSS protection, cache control, strict transport security, set-cookie header, and many more http headers in this comprehensive guide with examples and take your website security header game to the next level with Darkrelay.
HTML Form Validation is heavily underused
HTML Forms have powerful validation mechanisms, but they are heavily underused. In fact, not many people even know much about them. Is this because of some flaw in their design? Let’s explore.
Practical Web Cache Poisoning | PortSwigger Research
In this paper I’ll show you how to compromise websites by using esoteric web features to turn their caches into exploit delivery systems
xkpasswd - a secure, memorable password generator
Password generator
Frontend Security Checklist | Trevor Indrek Lasn
Tips for Keeping All Frontend Applications Secure
Fast Website Malware Removal & Antivirus | Sucuri
A resource when you don’t have a good back up plan after a hack. A service that promised to clean malware and viruses from a website.
Learn and Test DMARC
Learn and Test DMARC
Learn and Test DMARC
Learn and Test DMARC
Terrapin Attack
The Terrapin attack is a prefix truncation attack targeting the SSH protocol, where the integrity of SSH’s secure channel is compromised by manipulating sequence numbers during the handshake, allowing an attacker to remove messages from the secure channel without detection.
OWASP Top Ten | OWASP Foundation
The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software development culture focused on producing secure code.
Don't allow your page to be rendered in an iframe.
A small gist with Javascript to try to prevent iframe embedding of your content.
Clickjacking Defense - OWASP Cheat Sheet Series
Website with the collection of all the cheat sheets of the project.
Baroshem/nuxt-security: Security Module for Nuxt based on OWASP Top 10 and Helmet
OWASP Top 10 module that adds a few security improvements in form of a customizable server middlewares to your Nuxt application. All middlewares can be modified or disabled if needed. They can also be configured to work only on certain routes. By default all middlewares are configured to work globally.