A March 13 Hacker News thread focused on a security report finding 39 active Algolia admin keys exposed across open-source documentation sites. The risk is not theoretical: the keys could modify or delete search indexes, poison results, and expose indexed content on trusted developer docs.
#security
RSS FeedPerplexity has introduced Computer for Enterprise as a major upgrade to its Enterprise offering. The product pushes Perplexity beyond answer generation into long-running workflows across websites and internal web apps, while adding audit, identity, and data-governance controls.
Anthropic says Claude Opus 4.6 found 22 Firefox vulnerabilities in a two-week collaboration with Mozilla, including 14 high-severity bugs. The company argues current frontier models are already powerful defensive security researchers and that developers should use the window before offensive capability catches up.
A Hacker News discussion around Amine Raji's local ChromaDB lab highlights a practical risk in RAG systems: attackers can win by contaminating the source corpus, and the strongest defense may sit at ingestion rather than in the prompt.
OneCLI proposes a proxy-and-vault pattern for AI agents so tools stay reachable while real credentials remain outside the model runtime.
Anthropic said Claude Opus 4.6 found 22 Firefox vulnerabilities during a two-week collaboration with Mozilla. Mozilla classified 14 as high severity and shipped fixes in Firefox 148.0.
Agent Safehouse is an open-source macOS hardening layer that uses sandbox-exec to confine local coding agents to explicitly approved paths instead of inheriting a developer account’s full access.
Cisco expanded AI Defense and AI-aware SASE to help enterprises control model risks, shadow AI, and shadow agents. The move reflects how security vendors are shifting from app-centric controls to policies that also cover prompts, agents, and AI usage paths.
Cloudflare says Cloudflare One now links data security controls from endpoints to AI prompts. The update adds browser RDP clipboard controls, richer SaaS operation logging, on-device DLP, and Microsoft 365 Copilot scanning through API CASB.
OpenAI has put Codex Security into research preview, extending its agent stack into repository scanning, bug reproduction, threat analysis, and remediation. The company says the system sharply reduced review noise and false positives in internal evaluations.
OpenAI Developers said on March 6, 2026 that Codex Security is now in research preview. The product connects to GitHub repositories, builds a threat model, validates potential issues in isolation, and proposes patches for human review.
Anthropic published a Mar 6, 2026 policy for vulnerabilities identified with Claude. The framework sets a 90-day default disclosure window, a 7-day target for actively exploited critical bugs, and human review requirements before reports go out.