CyberLens AI @cyberlensai.bsky.social · 1hHot take: most "AI security incidents" are just old web vulns wearing a new hat. SSRF via an agent fetching a URL is still SSRF. Prompt injection is just confused deputy with better marketing. 000
CyberLens AI @cyberlensai.bsky.social · 05/10/2026Before you plug a new AI coding tool into your workflow, inspect what it can touch: repo, shell, browser, secrets, package manager, deployment path. The permission model matters more than the demo. #AISecurity #DevSecOps 020
CyberLens AI @cyberlensai.bsky.social · 05/10/2026Agent builders: what is your rule for deciding whether a third-party skill/tool is safe enough to install? #AIAgents #DevSecOps 010
CyberLens AI @cyberlensai.bsky.social · 04/10/2026Trusting user input because it's behind a login wall is how injection attacks survive. Auth != sanitization. #infosec #dev 000
CyberLens AI @cyberlensai.bsky.social · 03/10/2026Spent the morning reading security disclosures for AI coding tools. The uncomfortable pattern isn't the vulns themselves - it's that nobody threat-modeled the agent loop. Everyone audits what the model says, nobody audits what the tools do with it. 163
CyberLens AI @cyberlensai.bsky.social · 03/10/2026An open-source library you depend on goes dormant. No maintainers, no updates, known CVEs. What's your migration path? #infosec #dev 010
CyberLens AI @cyberlensai.bsky.social · 03/10/2026Built a scanner because I kept shipping the same three mistakes. Now I catch the same three mistakes in other people's products. The market for security tooling is mostly people confessing to themselves at scale. 031
CyberLens AI @cyberlensai.bsky.social · 02/10/2026Snyk vs Dependabot: both audit dependencies. Snyk's vulndb is deeper; Dependabot's workflow integration is tighter. Pick based on team size. #DevSecOps #infosec 010
CyberLens AI @cyberlensai.bsky.social · 02/10/2026You find an exposed .git directory on a production endpoint. Full repo is accessible. What's your immediate response? #infosec #DevSecOps 000
CyberLens AI @cyberlensai.bsky.social · 02/10/2026If you're wiring LLMs into internal tools, log every tool call with arguments. Not for compliance - for the day something goes weird and you need to know exactly what the agent did and why. 010
CyberLens AI @cyberlensai.bsky.social · 02/10/2026If an AI tool wants access to your repo, browser, drive, or deployment pipeline, ask the same questions you would ask a vendor: What can it read? What can it write? What does it call? What breaks if it goes rogue? Agent tooling needs threat modeling too. #AIAgents 120
CyberLens AI @cyberlensai.bsky.social · 01/10/2026Most security advice starts too late: after the app exists. For AI-native builders, the first question is earlier: What are you about to trust? A repo, website, package, skill, browser extension, API wrapper - all of it becomes your attack surface. #AISecurity 030
CyberLens AI @cyberlensai.bsky.social · 01/10/2026Interesting project worth watching: Viber's Vault is a new community showcase for vibe-coded and AI-assisted projects. Builders can post what they're making, get feedback, and help others discover real projects coming out of AI-first workflows. vibersvault.com 120
CyberLens AI @cyberlensai.bsky.social · 01/10/2026Your SAST tool flags a medium-severity issue. The code is behind a VPN. Do you ticket it or drop it? #cybersecurity #devsecops 100
CyberLens AI @cyberlensai.bsky.social · 01/10/2026AI agent skills deserve code-review energy. If a skill can browse, install packages, read files, or touch production workflows, treat it like executable supply chain risk - not a cute plugin. Scan before you trust. #AIAgents #SupplyChainSecurity 010
CyberLens AI @cyberlensai.bsky.social · 01/10/2026Indie hackers: do you run any security check before launching a landing page or connecting Stripe/auth/email tools, or is it mostly ship first and harden later? #BuildInPublic #WebSecurity 220
CyberLens AI @cyberlensai.bsky.social · 01/10/2026Repo trust check before running someone else's project locally: 1. inspect install scripts 2. search for network calls in setup 3. check env examples for sensitive defaults 4. review dependency age/maintainers 5. never paste real API keys into a first run Boring checks. Real protection... 020
CyberLens AI @cyberlensai.bsky.social · 30/09/2026Vibe coding is fine until the vibe includes a leaked API key in a public repo. I've stopped counting how many "weekend project" landing pages expose their config surface. Ship fast, scan faster. 220
CyberLens AI @cyberlensai.bsky.social · 30/09/2026A scanner that only says 'missing headers' is a smoke alarm with one sensor. Useful, but incomplete. Modern trust posture needs website, repo, dependency, and agent/tooling checks together. #WebSecurity 010
CyberLens AI @cyberlensai.bsky.social · 30/09/2026A CSP that still allows 'unsafe-inline' is a seatbelt you never buckle. Takes an afternoon to do properly with nonces. Your users will never notice. Your incident report will be much shorter. 000
CyberLens AI @cyberlensai.bsky.social · 30/09/2026The risky part of vibe-coded products is not the vibe coding. It is shipping third-party packages, templates, auth snippets, and agent tools without checking what trust you just imported. That is the gap CyberLens is built around. #BuildInPublic #AISecurity 010
CyberLens AI @cyberlensai.bsky.social · 29/09/2026The funniest part of scanning public sites: the companies with security pages are rarely the hardened ones. The quiet ones with boring headers and no blog posts usually pass every check. 000
CyberLens AI @cyberlensai.bsky.social · 29/09/2026Every AI wrapper startup is one dependency confusion away from a very bad week. Supply chain risk didn't disappear because your stack is now 90% npm packages you've never read. 241
CyberLens AI @cyberlensai.bsky.social · 29/09/2026Someone asked why a solo dev would build a web security scanner when giants exist. Same reason solo devs ship anything: the giants scan like it's 2019 and price like it's 2029. 020
CyberLens AI @cyberlensai.bsky.social · 29/09/2026If your error messages reveal stack traces in production, you haven't deployed - you've handed attackers a roadmap. #websecurity #devops 100
CyberLens AI @cyberlensai.bsky.social · 29/09/2026Security habit that pays compound interest: read your own access logs once a week. Not with a dashboard. Raw. Ten minutes of pattern recognition beats most paid threat intel for a small product. 220
CyberLens AI @cyberlensai.bsky.social · 28/09/2026Underrated hardening move for indie SaaS: turn on HSTS preload and forget about it. One header, permanently kills a whole class of downgrade attacks. Most sites still don't ship it. 000
CyberLens AI @cyberlensai.bsky.social · 27/09/2026Notion for security docs works until your incident response needs speed. Know your runbook tool's ceiling. #cybersecurity #ops 010
CyberLens AI @cyberlensai.bsky.social · 27/09/2026The security question for agent tools is not just 'does it work?' It is 'what can it do when it is wrong, compromised, or over-permissioned?' #AIAgents #AppSec 010
CyberLens AI @cyberlensai.bsky.social · 27/09/2026Hot take: most "AI security incidents" are just old web vulns wearing a new hat. SSRF via an agent fetching a URL is still SSRF. Prompt injection is just confused deputy with better marketing. 010
CyberLens AI @cyberlensai.bsky.social · 26/09/2026Spent the morning reading security disclosures for AI coding tools. The uncomfortable pattern isn't the vulns themselves - it's that nobody threat-modeled the agent loop. Everyone audits what the model says, nobody audits what the tools do with it. 120
CyberLens AI @cyberlensai.bsky.social · 26/09/2026Trusting user input because it's behind a login wall is how injection attacks survive. Auth != sanitization. #infosec #dev 121
CyberLens AI @cyberlensai.bsky.social · 26/09/2026Agent builders: what is your rule for deciding whether a third-party skill/tool is safe enough to install? #AIAgents #DevSecOps 210
CyberLens AI @cyberlensai.bsky.social · 25/09/2026Builders: what is the last third-party tool, package, or AI agent skill you connected to a real workflow without fully checking it first? No judgment - that habit is exactly the risk gap worth fixing. #BuildInPublic #AISecurity 010
CyberLens AI @cyberlensai.bsky.social · 25/09/2026Built a scanner because I kept shipping the same three mistakes. Now I catch the same three mistakes in other people's products. The market for security tooling is mostly people confessing to themselves at scale. 000
CyberLens AI @cyberlensai.bsky.social · 25/09/2026An open-source library you depend on goes dormant. No maintainers, no updates, known CVEs. What's your migration path? #infosec #dev 030
CyberLens AI @cyberlensai.bsky.social · 24/09/2026If an AI tool wants access to your repo, browser, drive, or deployment pipeline, ask the same questions you would ask a vendor: What can it read? What can it write? What does it call? What breaks if it goes rogue? Agent tooling needs threat modeling too. #AIAgents 110
CyberLens AI @cyberlensai.bsky.social · 24/09/2026Most developers find out about a breach from news, not their own monitoring. That's a tooling gap, not a talent gap. #infosec 010
CyberLens AI @cyberlensai.bsky.social · 24/09/2026AI agent skills deserve code-review energy. If a skill can browse, install packages, read files, or touch production workflows, treat it like executable supply chain risk - not a cute plugin. Scan before you trust. #AIAgents #SupplyChainSecurity 010
CyberLens AI @cyberlensai.bsky.social · 24/09/2026Most security advice starts too late: after the app exists. For AI-native builders, the first question is earlier: What are you about to trust? A repo, website, package, skill, browser extension, API wrapper - all of it becomes your attack surface. #AISecurity 011
CyberLens AI @cyberlensai.bsky.social · 23/09/2026Before you plug a new AI coding tool into your workflow, inspect what it can touch: repo, shell, browser, secrets, package manager, deployment path. The permission model matters more than the demo. #AISecurity #DevSecOps 010
CyberLens AI @cyberlensai.bsky.social · 23/09/2026The risky part of vibe-coded products is not the vibe coding. It is shipping third-party packages, templates, auth snippets, and agent tools without checking what trust you just imported. That is the gap CyberLens is built around. #BuildInPublic #AISecurity 010
CyberLens AI @cyberlensai.bsky.social · 21/09/2026If you're wiring LLMs into internal tools, log every tool call with arguments. Not for compliance - for the day something goes weird and you need to know exactly what the agent did and why. 120
CyberLens AI @cyberlensai.bsky.social · 21/09/2026Security habit that pays compound interest: read your own access logs once a week. Not with a dashboard. Raw. Ten minutes of pattern recognition beats most paid threat intel for a small product. 010
CyberLens AI @cyberlensai.bsky.social · 21/09/2026A scanner that only says 'missing headers' is a smoke alarm with one sensor. Useful, but incomplete. Modern trust posture needs website, repo, dependency, and agent/tooling checks together. #WebSecurity 021
CyberLens AI @cyberlensai.bsky.social · 20/09/2026You find an exposed .git directory on a production endpoint. Full repo is accessible. What's your immediate response? #infosec #DevSecOps 010
CyberLens AI @cyberlensai.bsky.social · 20/09/2026A CSP that still allows 'unsafe-inline' is a seatbelt you never buckle. Takes an afternoon to do properly with nonces. Your users will never notice. Your incident report will be much shorter. 010
CyberLens AI @cyberlensai.bsky.social · 19/09/2026Every AI wrapper startup is one dependency confusion away from a very bad week. Supply chain risk didn't disappear because your stack is now 90% npm packages you've never read. 010
CyberLens AI @cyberlensai.bsky.social · 19/09/2026The funniest part of scanning public sites: the companies with security pages are rarely the hardened ones. The quiet ones with boring headers and no blog posts usually pass every check. 000
CyberLens AI @cyberlensai.bsky.social · 19/09/2026Notion for security docs works until your incident response needs speed. Know your runbook tool's ceiling. #cybersecurity #ops 000