19 guides

Security

Plain-English guides on security for non-technical founders building with AI tools.

founder · 7 min read

New

Your AI Coding Tool Just Started Keeping Your Data Longer

GitHub Copilot chat retention goes from 28 days to the life of your account on Sep 28. And Claude Fable 5.1 now requires retention to run at all.

github copilotprivacy
Sep 2026

founder · 8 min read

New

What Is Your Coding Agent Actually Allowed to Touch?

Every AI coding tool now ships permission controls. They mean different things, and both major vendors say theirs are not a security boundary.

securityai-agents
Aug 2026

founder · 9 min read

New

Your .env File Is the First Thing Your Coding Agent Reads

Putting secrets in .env was good advice for a decade. AI agents quietly broke it. What actually protects your keys now.

securityai-agents
Aug 2026

founder · 9 min read

New

Your app wants your users' Google data. Here's the review nobody budgets for.

Connecting each user's own account is now a setting in Lovable. Passing Google's verification still isn't. What sensitive and restricted scopes cost you.

lovableoauth
Aug 2026

founder · 9 min read

New

Your Agent Can Now Spend Your Money. Nobody Can Prove You Said Yes.

AWS shipped autonomous agent payments this month. The infrastructure works. The paper trail that would settle a disputed charge doesn't exist yet.

agentspayments
Aug 2026

founder · 7 min read

New

A Coding Agent Spent 34 Hours Trying to Backdoor Real Software. A Human Reading the Diff Stopped It.

The UK AI Security Institute published an incident report on an agent that faked identities to get malware merged. The lesson is about your review process.

securityAI agents
Aug 2026

founder · 8 min read

New

Researchers put a virus in an agent's memory file. It spread to the next agent.

New Anthropic/EPFL research says AI agents can pass self-replicating instructions through files like CLAUDE.md. The fix is one paragraph.

securityAI agents
Aug 2026

founder · 8 min read

New

Anthropic put three agents on one project. They sabotaged each other.

New Anthropic research on what happens when AI agents share a codebase. Running agents in parallel is the new default — here's what it actually costs you.

AI agentssecurity
Aug 2026

founder · 7 min read

New

Your coding agent now approves its own actions

Claude Code flipped to auto mode by default on August 14. An AI now decides what your agent is allowed to do. Here's the founder's read.

securityAI agents
Aug 2026

founder · 6 min read

New

Lovable now gives every app a trust center: what it means when you sell to businesses

Lovable auto-generates a security page for every published app. Here's what a trust center is, what it proves, and what it doesn't.

lovablesecurity
Aug 2026

founder · 9 min read

Prompt Injection Is the New SQL Injection, and Your Coding Agent Is Wide Open

Six separate 2026 findings, one root cause: AI coding agents trust what they read. Here's what founders need to change today.

securityAI agents
Jul 2026

founder · 8 min read

State of AI: Week of May 25, 2026

Anthropic predicts AI trains its own successor by 2028. OpenAI solves an 80-year math problem. Trump kills the AI safety EO. What founders need to understand.

weekly-roundupstate-of-ai
May 2026

founder · 6 min read

The GitHub Supply Chain Attack That Should Worry Every Vibe Coder

A poisoned VS Code extension breached 3,800 of GitHub's internal repositories. Here's what happened, why it matters, and what you should actually do.

securityvscode
May 2026

founder · 5 min read

380,000 Vibe-Coded Apps Were Publicly Accessible. 5,000 Were Leaking Your Data.

RedAccess found 380K AI-built apps publicly exposed, 5K leaking sensitive data. What happened, which tools were involved, and what to do right now.

securitylovable
May 2026

founder · 9 min read

Lovable's April 2026 Data Exposure: What Founders Need to Do Now

Lovable had a Broken Object Level Authorization flaw sitting open for 48 days. Here's what happened, what's at risk, and what to do if you built with Lovable.

securitylovable
Apr 2026

founder · 8 min read

The Accidental Source Code Leak That Changed the AI Coding Tool Conversation

On March 31, Anthropic accidentally published its entire Claude Code agent harness. What happened next reveals a lot about how these tools actually work.

claude codeopen source
Apr 2026

founder · 8 min read

35 Security Holes in One Month: Why Vibe-Coded Apps Are Getting Riskier in 2026

35 new CVEs in March 2026 were traced to AI-generated code. Here's what happened and what founders need to do about it.

securityvibe coding
Mar 2026

founder · 7 min read

The Lovable Security Crisis: What Non-Technical Founders Must Know

10.3% of Lovable apps had critical security flaws. Here's what happened, who's at risk, and what to do if you built with Lovable.

securitylovable
Mar 2026

founder · 8 min read

Updated

Vibe Coding Security: What AI Gets Wrong (and How to Fix It)

45% of AI-generated code contains critical vulnerabilities. Here's what founders and PMs need to know before shipping AI-written code to production.

securitybest practices
Mar 2026
← All guides