<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Dai Hong Phuc — Notes &amp; write-ups</title>
    <link>https://dhf.io.vn/blog/</link>
    <atom:link href="https://dhf.io.vn/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Security write-ups by a first-year blue-team student — dhf.io.vn</description>
    <language>en</language>
    <lastBuildDate>Thu, 06 Aug 2026 01:00:00 GMT</lastBuildDate>
    <item>
      <title>Integrity is not immunity: the keyv worm was properly signed, and that was the point</title>
      <link>https://dhf.io.vn/blog/?post=integrity-is-not-immunity</link>
      <guid isPermaLink="false">dhf-post-integrity-is-not-immunity</guid>
      <pubDate>Thu, 06 Aug 2026 01:00:00 GMT</pubDate>
      <description>On 4 August 2026 a package with roughly 620 million monthly installs shipped a worm — built by its own CI, carrying genuine npm provenance, with a permanent attestation sitting in a public transparency log. Nothing was forged. Read as epidemiology instead of integrity, the incident says something uncomfortable: our proofs are immutable, our defences are the only revocable part of the system, and a mature release pipeline is a better host than an amateur one.</description>
    </item>
    <item>
      <title>When bugs became free: the week defending itself became the attack surface</title>
      <link>https://dhf.io.vn/blog/?post=when-bugs-became-free</link>
      <guid isPermaLink="false">dhf-post-as13rfvn4cz9uqj</guid>
      <pubDate>Fri, 03 Jul 2026 19:47:12 GMT</pubDate>
      <description>In one week of July 2026, an anonymous researcher dumped a dozen AI-found zero-days with no vendor warning, and a separate campaign booby-trapped the proof-of-concept repos defenders rush to analyse. Read together, they break an assumption I did not know I was still making — that finding a bug is expensive — and point at an uncomfortable inversion: the scarce resource, and the target, is now the defender’s own urgency.</description>
    </item>
    <item>
      <title>The error report that ran code: what Agentjacking taught me about distrusting my own logs</title>
      <link>https://dhf.io.vn/blog/?post=agentjacking-distrusting-your-own-logs</link>
      <guid isPermaLink="false">dhf-post-ch4g8v1gc8gkfqi</guid>
      <pubDate>Sat, 27 Jun 2026 08:57:18 GMT</pubDate>
      <description>Agentjacking turns a single fake Sentry error into code execution on a developer’s machine. The three bugs are the easy part. The harder lesson is that an AI agent quietly promoted the data we trust most — our own logs, errors and telemetry — into executable instructions, and we never thought to sanitise the things we wrote for ourselves.</description>
    </item>
    <item>
      <title>AutoJack and the wall that was never there: what a first-year defender learns when localhost stops meaning safe</title>
      <link>https://dhf.io.vn/blog/?post=autojack-localhost-was-never-a-wall</link>
      <guid isPermaLink="false">dhf-post-0glj8rmhhvr7342</guid>
      <pubDate>Sun, 21 Jun 2026 19:06:03 GMT</pubDate>
      <description>Microsoft&apos;s AutoJack disclosure is being read as three bugs to patch. The harder lesson is that localhost was never a trust boundary — only a topological one — and an AI agent is the first thing that can carry an attacker across it.</description>
    </item>
    <item>
      <title>What a third of a million failed logins taught me about my server</title>
      <link>https://dhf.io.vn/blog/?post=failed-logins-taught-me</link>
      <guid isPermaLink="false">dhf-post-zej60gj5a945d94</guid>
      <pubDate>Sat, 20 Jun 2026 17:16:46 GMT</pubDate>
      <description>I put a small server on the internet for this site. Within weeks it was under constant automated attack — so instead of ignoring the noise, I read the logs.</description>
    </item>
  </channel>
</rss>
