AI security/securing the use of AI is going to kill me. I use Claude Code almost daily. It's a problem.... Here's what I have to change AGAIN this week. Security researcher Ari Marzuk disclosed 30+ vulnerabilities across AI coding tools. Cursor. GitHub Copilot. Windsurf. Claude Code. All of them. He called it IDEsaster. The attack chain includes prompt injection, hijacking LLM context, and auto-approved tool calls executing without permission. Then, legitimate IDE features are weaponized for data exfiltration and RCE. Your .env files. Your API keys. Your source code. Accessible through features you thought were safe. Most studies I read claim that around 85% of developers now use AI coding tools daily. Most have no idea their IDE treats its own features as inherently trusted. 𝗦𝗼... 𝗮𝗳𝘁𝗲𝗿 𝗿𝗲𝘃𝗶𝗲𝘄𝗶𝗻𝗴 𝗔𝗿𝗶'𝘀 𝗿𝗲𝘀𝗲𝗮𝗿𝗰𝗵, 𝗵𝗲𝗿𝗲'𝘀 𝗜 𝘄𝗶𝗹𝗹 𝗯𝗲 𝗱𝗼𝗶𝗻𝗴... Be warned: All this is SO much easier said than done! Audit every MCP server connection. Checked for tool poisoning vectors where legitimate tools might parse attacker-controlled input from GitHub PRs or web content. Removed servers I couldn't verify. Disabled auto-approve for file writes. The attack chains weaponize configuration files and project instructions like .claude/settings.json and CLAUDE.md. One malicious write to these files can alter agent behavior or achieve code execution without additional user interaction. Move all credentials to a secrets manager. No .gitignored .env files in agent-accessible directories. API keys live in 1Password CLI. Environment variables inject at runtime through a wrapper script the LLM never sees. Start running Claude Code in isolated containers. Mounted volumes limited to specific project directories. No access to ~/.ssh, ~/.aws, or ~/.config. If the agent gets compromised, blast radius stays contained. Enable all security warnings. Claude Code added explicit warnings for JSON schema exfiltration and settings file modifications. These exist because Anthropic knows the attack surface. Add pre-commit hooks for hidden characters. Prompt injections hide in pasted URLs, READMEs, and file names using invisible Unicode. Flag non-ASCII characters in any file the agent might ingest. The fix isn't to stop using AI coding tools. The fix is to stop trusting them implicitly. What controls do you have for AI tools with write access to your codebase? 👉 Follow for more AI and cybersecurity insights with the occasional rant #AISecurity #DevSecOps
Online Privacy Tools
Explore top LinkedIn content from expert professionals.
-
-
𝗘𝘃𝗲𝗿𝘆𝘁𝗵𝗶𝗻𝗴 𝗬𝗼𝘂 𝗡𝗲𝗲𝗱 𝘁𝗼 𝗞𝗻𝗼𝘄 𝗔𝗯𝗼𝘂𝘁 𝗜𝗣 𝗔𝗱𝗱𝗿𝗲𝘀𝘀𝗲𝘀 & 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 In our connected world, IP addresses are the foundation of internet communication. But not all IP addresses are created equal, and understanding their types—and how to secure them—is crucial for both businesses and individuals. Here’s a simple breakdown: 𝗣𝗿𝗶𝘃𝗮𝘁𝗲 (𝗟𝗼𝗰𝗮𝗹) 𝗜𝗣: Automatically generated within your home or office network. Devices like your phone or laptop use addresses like 𝟷𝟿𝟸. 𝟷𝟼𝟾. 𝚇. 𝚇 to communicate with the router. 𝗣𝘂𝗯𝗹𝗶𝗰 𝗜𝗣: Assigned by your Internet Service Provider (ISP). This is the address the world sees when you access the internet, e.g., 𝟾𝟺. 𝟷𝟼𝟸. 𝟺𝟹. 𝟸𝟹. 𝗦𝘁𝗮𝘁𝗶𝗰 𝗜𝗣: A permanent IP address, ideal for servers and critical systems that require constant connectivity. 𝗗𝘆𝗻𝗮𝗺𝗶𝗰 𝗜𝗣: Changes occasionally, and is typically used for consumer devices. It’s more flexible but less predictable. 𝗜𝗣𝘃𝟰: The traditional IP format (e.g., 𝟷𝟿𝟸. 𝟷𝟼𝟾. 𝟸. 𝟻) with 4.3 billion addresses, now nearing its limit due to the growing number of internet-connected devices. I𝗣𝘃𝟲: The next-generation IP addressing system (`2001:db8:3333:4444:5555:6666:7777:8888`) with 7.9 * 10²⁸ unique addresses—more than enough to give every device in the world a unique identifier. 𝗪𝗵𝘆 𝗜𝗣 𝗔𝗱𝗱𝗿𝗲𝘀𝘀 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗠𝗮𝘁𝘁𝗲𝗿𝘀: Your IP address reveals a lot about your online activity. Protect it using tools like VPNs, which encrypt your connection and safeguard your privacy from hackers, ISPs, ad trackers, and even government surveillance. 𝗞𝗲𝘆 𝗧𝗮𝗸𝗲𝗮𝘄𝗮𝘆: Whether static or dynamic, IPv4 or IPv6, your IP address is crucial to your online identity. Understanding it is the first step to securing your digital presence! Stay safe and secure in the digital world!
-
AI made fake documents perfect. Google's response? Prove your age without showing your ID. Zero-knowledge proofs are going mainstream. Last week, Google announced ZK proofs for 2B+ Wallet users. With AI getting frighteningly good at generating fake documents, this couldn't come at a better time. 1// Why this matters now → AI can generate perfect passport copies in seconds → Most verification systems can't properly detect fakes → Traditional KYC is in an urgent need of updating → Data breaches expose complete identities daily 2// What Google is building → Verify age without revealing birthdate → Prove identity without showing documents → Control exactly what data you share → UK government being first to adopt the system → Major platforms to follow the integration (Bumble Inc., Uber, Amazon, CVS Health) 3// The ripple effects → Dating apps verify age mathematically → Banks conduct KYC without storing documents → Healthcare systems access records privately → Travel verification becomes truly digital → And it’s all through open-source ZK technology Two weeks ago, I worried about identity fraud becoming unstoppable with the rise of AI. Today, I'm seeing the infrastructure for trustless verification being finally implemented by the giants. The question isn't whether ZK proofs will become standard. It's who will build the next generation of privacy-preserving services on top.
-
The internet must be a safe space for everyone. Especially children and young people. Today, President Ursula von der Leyen and I outlined two key actions shaping our work across the EU: rolling out a privacy-preserving, EU-wide age verification solution and enforcing the Digital Services Act. Age verification solution is ready as of today. It allows users to prove their age securely and anonymously using zero-knowledge proof. No personal data is shared. Verification happens through an anonymous QR code exchange, without requiring platforms to collect sensitive data. Next step: scale. One interoperable solution across the EU, not 27 fragmented systems. Seven Member States are already acting as front-runners, and the open-source blueprint allows private companies to build compatible solutions under strict privacy standards. A safer internet for children is not optional. We’re making it happen.
-
You’re getting stalked. Harassed. Doxxed. The social media platform says: “This doesn’t violate our policies.” Tracy Chou heard that one too many times—so she stopped reporting and started building. Tracy was a Stanford-trained software engineer. A second hire at Quora. A founding engineer at Pinterest, shipping everything from infrastructure to growth. Quietly brilliant. Head down. Crushing code. Then, in 2013, she published one blog post asking a simple question: “Where are the numbers?”—a challenge to tech companies to reveal how few women were in engineering roles. It went viral. Tracy went from backend engineer to accidental face of diversity in tech. But visibility came at a cost. Trolls. Stalkers. 10,000 password reset requests. Conspiracy theorists claiming she was married to James Comey. Real-life threats. Real-life fear. She reported it. Platforms shrugged. So she did what Silicon Valley loves to preach but rarely practices: she built the product she needed. Block Party was born in 2018—not as a startup idea, but as self-defense. What started as a Twitter anti-harassment filter has grown into a powerful browser extension used across 9+ platforms. It deep cleans your social media, locks down privacy settings, and gives users back control of their data. Because Tracy knows: what starts online rarely stays there. Venmo. Strava. Instagram. We’re bleeding personal information by default. And for women, activists, and marginalized communities—that can be life-threatening. So Block Party does the hard part: scans your accounts, flags your risks, and helps you wipe your data trail before someone weaponizes it. And she’s not stopping there. She’s advocating for legislation that would force platforms to open their APIs. Why? So third-party tools like Block Party can exist without permission. She wants a future where people can build their own feeds, filters, and safety nets—not beg corporations to care. In Tracy’s world, privacy isn’t a product feature—it’s a fundamental right. Stanford Terman Scholar. TIME Woman of the Year. Forbes 30 Under 30. Co-founder of Project Include. She’s graced the covers of WIRED, The Atlantic, and MIT Tech Review. And yet, had you heard her name before today? In 2025, I’m sharing 365 stories of women entrepreneurs in 365 days—because the women reshaping tech, safety, and society deserve to be celebrated every day. 💡Follow Justine J. for more #femalefounder spotlights.
-
Apple CPU Flaw May Let Hackers Steal Your Data: 8 Ways To Stay Safe Security researchers have uncovered vulnerabilities in modern Apple CPUs that could let hackers extract sensitive information directly from your web browser. These attacks, known as FLOP and SLAP, exploit Apple's speculative execution—a feature designed to speed up processing—causing the CPU to reveal confidential data before correcting itself. This means that just by opening the wrong website, your Gmail inbox, Amazon order history, Google Maps location, or even your iCloud calendar events could be exposed to cybercriminals. Even worse, these attacks can happen remotely without requiring any downloads, malware, or physical access to your device. 1. Consider Disabling JavaScript For Untrusted Websites The FLOP and SLAP attacks rely on JavaScript running in your web browser. Temporarily disabling JavaScript in Safari or Chrome can help mitigate the risk. However, be aware that many websites rely on JavaScript for functionality, so this might impact your browsing experience. In Safari: Open Settings > Safari > Advanced, then disable JavaScript. (Note: This may break some website functionality.) In Chrome: Use extensions like NoScript or uBlock Origin to selectively block JavaScript on untrusted sites 2. Keep Your Browser And Operating System Updated Make sure you: Regularly update macOS and iOS by enabling automatic updates. Keep Safari and Chrome updated to their latest versions, as browser vendors may introduce mitigations before Apple releases a CPU-level fix. 3. Use A Privacy-Focused Browser Browsers like Brave, DuckDuckGo, and Firefox focus on privacy and security, providing additional layers of protection against tracking and browser-based attacks. 4. Enable Strict Privacy And Security Settings Enhance your browser security by: Blocking third-party cookies. Using private browsing mode to limit data exposure. Enabling enhanced tracking protection (available in Firefox and Brave). Please see article for additional suggestions: https://lnkd.in/gx_AMHt4 #cybersecurity #Apple #FLOP #SLAP
-
The tools your team is paying ₹40L/year for. But there are free ones that do the same job. 01) Trivy instead of Snyk for container scanning. 02) Semgrep instead of Checkmarx for SAST. 03) Falco instead of Aqua for runtime threats. 04) Gitleaks instead of GitGuardian for secrets. 05) Kyverno instead of OPA Enterprise for policy. Same coverage. ₹0. The full replacement chart is below. Save this before your next renewal. Please Note: Not saying these tools are identical in every scenario. I’m saying many teams are overpaying for problems that can often be solved well enough with strong open-source alternatives. Your right choice depends on compliance, support needs, team bandwidth, and operational maturity.
-
I used Google Forms for my bachelor’s research. And now I realize I shouldn’t have. Not because I was careless, but because I didn’t know better. None of us did. In India, almost every psych or social work student I knew used Google Forms. It was free, easy, and accessible. We thought we were doing it right. But once I started my master’s in Germany, I noticed something strange: No one here uses Google Forms. Not even for tiny surveys. Why? Google stores form responses on servers mostly located in the U.S, meaning researchers outside the U.S have little control over where their participants’ data goes or how it’s protected. When you’re collecting personal or sensitive information, this lack of control becomes a serious ethical and sometimes legal concern. That hit me hard. Back then, people trusted me with their stories. And I unknowingly put that trust at risk. I’m not sharing this to blame anyone. I’m sharing it because we’re often not taught what ethical research actually looks like. So here’s what I wish someone had told me earlier: If you’re collecting data from people, especially in psychology or social work, privacy is not optional. There are a few alternatives available: 🔹 Zoho Survey: Free, Indian company, better data protection. 🔹 LimeSurvey: Open-source, widely used in academia. 🔹 Nextcloud Forms: Privacy-first, great if your institution supports it. 🔹SurveySparrow : Also based in India. Good if you're not collecting highly sensitive data. 🔹Jotform: If you want a form builder that feels like Google Forms but with more control. Just double check where the data is stored. And if you must use Google Forms: • Be transparent: Let the participant know where their data would be stored • Avoid collecting sensitive info • Download and delete data from the platform ASAP Research is not just about responses. It’s also about respecting the people who respond. If you’re a student reading this, I hope this helps you to take one step closer to doing research that’s not just smart, but safe.
-
Isabel Barberá: "This document provides practical guidance and tools for developers and users of Large Language Model (LLM) based systems to manage privacy risks associated with these technologies. The risk management methodology outlined in this document is designed to help developers and users systematically identify, assess, and mitigate privacy and data protection risks, supporting the responsible development and deployment of LLM systems. This guidance also supports the requirements of the GDPR Article 25 Data protection by design and by default and Article 32 Security of processing by offering technical and organizational measures to help ensure an appropriate level of security and data protection. However, the guidance is not intended to replace a Data Protection Impact Assessment (DPIA) as required under Article 35 of the GDPR. Instead, it complements the DPIA process by addressing privacy risks specific to LLM systems, thereby enhancing the robustness of such assessments. Guidance for Readers > For Developers: Use this guidance to integrate privacy risk management into the development lifecycle and deployment of your LLM based systems, from understanding data flows to how to implement risk identification and mitigation measures. > For Users: Refer to this document to evaluate the privacy risks associated with LLM systems you plan to deploy and use, helping you adopt responsible practices and protect individuals’ privacy. " >For Decision-makers: The structured methodology and use case examples will help you assess the compliance of LLM systems and make informed risk-based decision" European Data Protection Board
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development