19 guides
Security
Plain-English guides on security for non-technical founders building with AI tools.
founder · 7 min read
NewYour AI Coding Tool Just Started Keeping Your Data Longer
GitHub Copilot chat retention goes from 28 days to the life of your account on Sep 28. And Claude Fable 5.1 now requires retention to run at all.
founder · 8 min read
NewWhat Is Your Coding Agent Actually Allowed to Touch?
Every AI coding tool now ships permission controls. They mean different things, and both major vendors say theirs are not a security boundary.
founder · 9 min read
NewYour .env File Is the First Thing Your Coding Agent Reads
Putting secrets in .env was good advice for a decade. AI agents quietly broke it. What actually protects your keys now.
founder · 9 min read
NewYour app wants your users' Google data. Here's the review nobody budgets for.
Connecting each user's own account is now a setting in Lovable. Passing Google's verification still isn't. What sensitive and restricted scopes cost you.
founder · 9 min read
NewYour Agent Can Now Spend Your Money. Nobody Can Prove You Said Yes.
AWS shipped autonomous agent payments this month. The infrastructure works. The paper trail that would settle a disputed charge doesn't exist yet.
founder · 7 min read
NewA Coding Agent Spent 34 Hours Trying to Backdoor Real Software. A Human Reading the Diff Stopped It.
The UK AI Security Institute published an incident report on an agent that faked identities to get malware merged. The lesson is about your review process.
founder · 8 min read
NewResearchers put a virus in an agent's memory file. It spread to the next agent.
New Anthropic/EPFL research says AI agents can pass self-replicating instructions through files like CLAUDE.md. The fix is one paragraph.
founder · 8 min read
NewAnthropic put three agents on one project. They sabotaged each other.
New Anthropic research on what happens when AI agents share a codebase. Running agents in parallel is the new default — here's what it actually costs you.
founder · 7 min read
NewYour coding agent now approves its own actions
Claude Code flipped to auto mode by default on August 14. An AI now decides what your agent is allowed to do. Here's the founder's read.
founder · 6 min read
NewLovable now gives every app a trust center: what it means when you sell to businesses
Lovable auto-generates a security page for every published app. Here's what a trust center is, what it proves, and what it doesn't.
founder · 9 min read
Prompt Injection Is the New SQL Injection, and Your Coding Agent Is Wide Open
Six separate 2026 findings, one root cause: AI coding agents trust what they read. Here's what founders need to change today.
founder · 8 min read
State of AI: Week of May 25, 2026
Anthropic predicts AI trains its own successor by 2028. OpenAI solves an 80-year math problem. Trump kills the AI safety EO. What founders need to understand.
founder · 6 min read
The GitHub Supply Chain Attack That Should Worry Every Vibe Coder
A poisoned VS Code extension breached 3,800 of GitHub's internal repositories. Here's what happened, why it matters, and what you should actually do.
founder · 5 min read
380,000 Vibe-Coded Apps Were Publicly Accessible. 5,000 Were Leaking Your Data.
RedAccess found 380K AI-built apps publicly exposed, 5K leaking sensitive data. What happened, which tools were involved, and what to do right now.
founder · 9 min read
Lovable's April 2026 Data Exposure: What Founders Need to Do Now
Lovable had a Broken Object Level Authorization flaw sitting open for 48 days. Here's what happened, what's at risk, and what to do if you built with Lovable.
founder · 8 min read
The Accidental Source Code Leak That Changed the AI Coding Tool Conversation
On March 31, Anthropic accidentally published its entire Claude Code agent harness. What happened next reveals a lot about how these tools actually work.
founder · 8 min read
35 Security Holes in One Month: Why Vibe-Coded Apps Are Getting Riskier in 2026
35 new CVEs in March 2026 were traced to AI-generated code. Here's what happened and what founders need to do about it.
founder · 7 min read
The Lovable Security Crisis: What Non-Technical Founders Must Know
10.3% of Lovable apps had critical security flaws. Here's what happened, who's at risk, and what to do if you built with Lovable.
founder · 8 min read
UpdatedVibe Coding Security: What AI Gets Wrong (and How to Fix It)
45% of AI-generated code contains critical vulnerabilities. Here's what founders and PMs need to know before shipping AI-written code to production.