# Security & Privacy

Published articles for Security & Privacy.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## An Organizational Second Brain: Building an AI That Learns From Experts

DevFeed: [An Organizational Second Brain: Building an AI That Learns From Experts](<https://devfeed.tech/articles/an-organizational-second-brain-building-an-ai-that-learns-from-experts-132.md>)

Original publisher: [Read original article](<https://engineering.fb.com/2026/09/02/ml-applications/organizational-second-brain-ai-learns-from-experts/>)

Author: Shaurya Sengar; Jason Nawrocki; Jay Shah; Prashant Kommireddi

Published: 2026-09-02T09:00:29Z

Content type: article

Language: en

Sources: [Engineering at Meta](<https://devfeed.tech/sources/engineering-at-meta.md>), [Meta AI Research](<https://devfeed.tech/sources/meta-ai-research.md>), [Meta ML Applications](<https://devfeed.tech/sources/meta-ml-applications.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-research](<https://devfeed.tech/tags/ai-research.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [llms](<https://devfeed.tech/tags/llms.md>), [ml-applications](<https://devfeed.tech/tags/ml-applications.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

Meta describes an AI agent for a compliance domain that preserves specialist knowledge through an auditable knowledge architecture, an expert-like reasoning layer, and a feedback-driven improvement pipeline without model retraining.

### Source excerpt

We've built an AI agent that acts as a secondary expert for a given domain, making deep specialist knowledge readily available and preserved for anyone in an organization to access, share, and build upon. This is not a typical domain-specific agent. Its novelty comes from integrating two layers: A structured, auditable knowledge architecture separates what [...] Read More... The post An Organizational Second Brain: Building an AI That Learns From Experts appeared first on Engineering at Meta.

## How We're Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees

DevFeed: [How We're Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees](<https://devfeed.tech/articles/how-we-re-building-scam-alert-on-whatsapp-with-end-to-end-encryption-and-verifiability-guarantees-129.md>)

Original publisher: [Read original article](<https://engineering.fb.com/2026/08/12/security/how-were-building-scam-alert-whatsapp/>)

Author: Chris Wiltz

Published: 2026-08-12T13:00:28Z

Content type: article

Language: en

Sources: [Engineering at Meta](<https://devfeed.tech/sources/engineering-at-meta.md>)

Topics: [End-to-End Encryption](<https://devfeed.tech/topics/end-to-end-encryption.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [Security](<https://devfeed.tech/topics/security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>)

Tags: [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [user-control](<https://devfeed.tech/tags/user-control.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

An early technical overview of WhatsApp's optional Scam Alert feature, which uses a small on-device machine learning model to classify potential scam messages while keeping message content on the device. The article explains how the design preserves end-to-end encryption through local processing, avoids automatic reporting, gives users control, and supports independent security review during a limited Beta rollout.

### Source excerpt

WhatsApp is committed to helping people stay safe while protecting the privacy of their messages. As scam tactics evolve -- from impersonation to social engineering to AI-generated lures -- we're always evolving as well, so that our protections stay ahead of scammers while protecting people's personal messages with end-to-end encryption. Today, we're sharing an early [...] Read More... The post How We're Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees appeared first on Engineering at Meta.

## Univé builds an AI-ready workforce

DevFeed: [Univé builds an AI-ready workforce](<https://devfeed.tech/articles/unive-builds-an-ai-ready-workforce-6700.md>)

Original publisher: [Read original article](<https://openai.com/index/unive>)

Published: 2026-07-31T07:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>), [responsible-ai](<https://devfeed.tech/topics/responsible-ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [building](<https://devfeed.tech/tags/building.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [governance](<https://devfeed.tech/tags/governance.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [openai](<https://devfeed.tech/tags/openai.md>), [organizational](<https://devfeed.tech/tags/organizational.md>), [platform](<https://devfeed.tech/tags/platform.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [responsible-ai](<https://devfeed.tech/tags/responsible-ai.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

Univé describes building an AI-ready workforce by treating AI adoption as an organizational transformation rather than a technology deployment. Using ChatGPT Enterprise within its governance framework, the insurer combined leadership engagement, employee-led innovation, enterprise authentication, permission controls, privacy assessments, security reviews, responsible AI principles, continuous monitoring, and human accountability to support safe experimentation at scale.

### Source excerpt

See how Univé built an AI-ready workforce with ChatGPT Enterprise by combining leadership, responsible governance, and employee-led innovation to transform work at scale.

## Privacy-Aware Infrastructure in the AI-Native Era: An Asset Classification Case Study

DevFeed: [Privacy-Aware Infrastructure in the AI-Native Era: An Asset Classification Case Study](<https://devfeed.tech/articles/privacy-aware-infrastructure-in-the-ai-native-era-an-asset-classification-case-study-22581.md>)

Original publisher: [Read original article](<https://engineering.fb.com/2026/06/25/security/privacy-aware-infrastructure-in-the-ai-native-era-an-asset-classification-case-study/>)

Author: Rituraj Kirti; Vasileios Lakafosis

Published: 2026-06-25T22:30:51Z

Content type: article

Language: en

Sources: [Meta ML Applications](<https://devfeed.tech/sources/meta-ml-applications.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [audit](<https://devfeed.tech/topics/audit.md>), [systems](<https://devfeed.tech/topics/systems.md>), [Meta](<https://devfeed.tech/topics/meta.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [audit](<https://devfeed.tech/tags/audit.md>), [data](<https://devfeed.tech/tags/data.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [meta](<https://devfeed.tech/tags/meta.md>), [ml-applications](<https://devfeed.tech/tags/ml-applications.md>), [review](<https://devfeed.tech/tags/review.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [systems](<https://devfeed.tech/tags/systems.md>)

### AI overview

This Meta engineering article presents a hybrid approach to asset classification for privacy-aware infrastructure. It combines rich context, LLMs for ambiguous or novel assets, human-reviewed labels, and deterministic versioned rules for routine production enforcement.

### Source excerpt

Privacy controls -- systems that enforce retention, access, allowed-purpose, downstream-sharing, or anonymization policies -- require a reliable understanding of data to function. Before such a control can operate effectively, it must know exactly what it is looking at. This can be complex, as demonstrated by a field simply named "age": In one context, it [...] Read More... The post Privacy-Aware Infrastructure in the AI-Native Era: An Asset Classification Case Study appeared first on Engineering at Meta.

## OpenAI available at FedRAMP Moderate

DevFeed: [OpenAI available at FedRAMP Moderate](<https://devfeed.tech/articles/openai-available-at-fedramp-moderate-6568.md>)

Original publisher: [Read original article](<https://openai.com/index/openai-available-at-fedramp-moderate>)

Published: 2026-04-27T14:00:00Z

Content type: news

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [AI Chat](<https://devfeed.tech/topics/ai-chat.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api](<https://devfeed.tech/tags/api.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [global-affairs](<https://devfeed.tech/tags/global-affairs.md>), [government](<https://devfeed.tech/tags/government.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

OpenAI announced FedRAMP 20x Moderate authorization for ChatGPT Enterprise and its API Platform, expanding a path for U.S. federal agencies to use its managed AI products.

### Source excerpt

OpenAI is available at FedRAMP Moderate authorization for ChatGPT Enterprise and the OpenAI API, enabling secure AI adoption for U.S. federal agencies.

## OWASP Top 10 Agents & AI Vulnerabilities (2026 Cheat Sheet)

DevFeed: [OWASP Top 10 Agents & AI Vulnerabilities (2026 Cheat Sheet)](<https://devfeed.tech/articles/owasp-top-10-agents-ai-vulnerabilities-2026-cheat-sheet-29085.md>)

Original publisher: [Read original article](<https://blog.alexewerlof.com/p/owasp-top-10-ai-llm-agents>)

Author: Alex Ewerlöf

Published: 2026-03-10T18:18:04Z

Content type: tutorial

Language: en

Sources: [Alex Ewerlof Notes](<https://devfeed.tech/sources/alex-ewerlof-notes.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [llm](<https://devfeed.tech/tags/llm.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [recipe](<https://devfeed.tech/tags/recipe.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A pragmatic engineering guide examines the OWASP Top 10 for LLMs and the OWASP Top 10 for Agents. It explains how mixed instructions and data, unpredictability, agentic attack surfaces, reliability failures, cascading failures, and high LLM costs create security and operational risks, with examples and mitigations.

### Source excerpt

A pragmatic engineering guide and cheat sheet for the OWASP Top 10 AI, OWASP Top 10 LLM, and OWASP Top 10 Agents vulnerabilities

## PVH reimagines the future of fashion with OpenAI

DevFeed: [PVH reimagines the future of fashion with OpenAI](<https://devfeed.tech/articles/pvh-reimagines-the-future-of-fashion-with-openai-6623.md>)

Original publisher: [Read original article](<https://openai.com/index/pvh-future-of-fashion>)

Published: 2026-01-27T06:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [data](<https://devfeed.tech/topics/data.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [accelerate](<https://devfeed.tech/tags/accelerate.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [creativity](<https://devfeed.tech/tags/creativity.md>), [data](<https://devfeed.tech/tags/data.md>), [design](<https://devfeed.tech/tags/design.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [global-affairs](<https://devfeed.tech/tags/global-affairs.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [openai](<https://devfeed.tech/tags/openai.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [product](<https://devfeed.tech/tags/product.md>), [retail](<https://devfeed.tech/tags/retail.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

PVH Corp. is adopting ChatGPT Enterprise and OpenAI frontier models across its global fashion operations. The initiative targets product design, demand planning, inventory optimization, supply-chain management, marketing, and consumer engagement, with an emphasis on data-driven decisions, creativity, efficiency, security, privacy, and responsible data governance.

### Source excerpt

PVH Corp., parent company of Calvin Klein and Tommy Hilfiger, is adopting ChatGPT Enterprise to bring AI into fashion design, supply chain, and consumer engagement.

## Moved my blog to \[blog.wagemakers.be\](https://blog.wagemakers.be)

DevFeed: [Moved my blog to \[blog.wagemakers.be\](https://blog.wagemakers.be)](<https://devfeed.tech/articles/moved-my-blog-to-blog-wagemakers-be-https-blog-wagemakers-be-39540.md>)

Original publisher: [Read original article](<https://blog.wagemakers.be/blog/2026/01/26/blog-wagemakers-be/>)

Author: Staf Wagemakers

Published: 2026-01-26T17:26:00Z

Content type: tutorial

Language: en

Sources: [stafwag Blog](<https://devfeed.tech/sources/stafwag-blog.md>)

Topics: [migration](<https://devfeed.tech/topics/migration.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [RSS Feed](<https://devfeed.tech/topics/rss-feed.md>), [Hugo](<https://devfeed.tech/topics/hugo.md>), [Atom](<https://devfeed.tech/topics/atom.md>), [XML](<https://devfeed.tech/topics/xml.md>)

Tags: [atom](<https://devfeed.tech/tags/atom.md>), [blog](<https://devfeed.tech/tags/blog.md>), [disquss](<https://devfeed.tech/tags/disquss.md>), [github](<https://devfeed.tech/tags/github.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [html](<https://devfeed.tech/tags/html.md>), [https](<https://devfeed.tech/tags/https.md>), [hugo](<https://devfeed.tech/tags/hugo.md>), [jekell](<https://devfeed.tech/tags/jekell.md>), [migration](<https://devfeed.tech/tags/migration.md>), [rss](<https://devfeed.tech/tags/rss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [xml](<https://devfeed.tech/tags/xml.md>)

### AI overview

The author moved the blog from GitHub to self-hosted hosting and documents the migration issues encountered. The article covers HTML redirects, updating hardcoded links, Disqus comment reindexing, and difficulties redirecting RSS feeds when moving from Octopress to Jekyll.

### Source excerpt

If you follow my blog posts with an RSS reader, update the rss feed to: https://blog.wagemakers.be/atom.xml ...If you want to continue to follow me off-course ;-) I moved my blog from GitHub to my own hosting ( powered by Procolix ). Procolix sponsored my hosting for 20 years, till I decided to start my company Mask27.dev. One reason is that Microsoft seems to like to put "copilot everywhere", including on repositories hosted on github. While I don't dislike AI ( artificial intelligence ), LLM ( Large Language Models ) are a nice piece of technology. The security, privacy, and other issues are overlooked or even just ignored. The migration was a bit more complicated as usual, as nothing "is easy" ;-) You'll find the pitfalls of moving my blog below as they might be useful for somebody else ( including the future me ).

## Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

DevFeed: [Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing](<https://devfeed.tech/articles/android-quick-share-support-for-airdrop-a-secure-approach-to-cross-platform-file-sharing-19805.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2025/11/android-quick-share-support-for-airdrop-security.html>)

Author: Edward Fernandez (noreply@blogger.com)

Published: 2025-11-20T17:00:00Z

Content type: release

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Google](<https://devfeed.tech/topics/google.md>), [Rust](<https://devfeed.tech/topics/rust.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [google](<https://devfeed.tech/tags/google.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [ios](<https://devfeed.tech/tags/ios.md>), [none](<https://devfeed.tech/tags/none.md>), [rust](<https://devfeed.tech/tags/rust.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

Google describes Quick Share interoperability with AirDrop, enabling two-way file sharing between Android and iOS devices starting with the Pixel 10 Family. The article explains the security measures used in the feature, including threat modeling, privacy reviews, penetration testing, and a Rust-based communication channel.

### Source excerpt

Posted by Dave Kleidermacher, VP, Platforms Security & Privacy, Google Technology should bring people closer together, not create walls. Being able to communicate and connect with friends and family should be easy regardless of the phone they use. That's why Android has been building experiences that help you stay connected across platforms. As part of our efforts to continue to make cross-platform communication more seamless for users, we've made Quick Share interoperable with AirDrop, allowing for two-way file sharing between Android and iOS devices, starting with the Pixel 10 Family. This new feature makes it possible to quickly share your photos, videos, and files with people you choose to communicate with, without worrying about the kind of phone they use. Most importantly, when you share personal files and content, you need to trust that it stays secure. You can share across devices with confidence knowing we built this feature with security at its core, protecting your data with strong safeguards that have been tested by independent security experts. Secure by Design We built Quick Share's interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products. Our approach to security is proactive and deeply integrated into every stage of the development process. This includes: Threat Modeling: We identify and address potential security risks before they can become a problem. Internal Security Design and Privacy Reviews: Our dedicated security and privacy teams thoroughly review the design to ensure it meets our high standards. Internal Penetration Testing: We conduct extensive in-house testing to identify and fix vulnerabilities. This Secure by Design philosophy ensures that all of our products are not just functional but also fundamentally secure. This feature is also protected by a multi-layered security approach to ensure a safe sharing experience from end-to-end, regardless of what platform you're on. Secure S

## Meta's ACH Tool Uses LLMs for Mutation-Guided Test Generation and Compliance Testing

DevFeed: [Meta's ACH Tool Uses LLMs for Mutation-Guided Test Generation and Compliance Testing](<https://devfeed.tech/articles/llms-are-the-key-to-mutation-testing-and-better-compliance-30491.md>)

Original publisher: [Read original article](<https://engineering.fb.com/2025/09/30/security/llms-are-the-key-to-mutation-testing-and-better-compliance/>)

Author: Mark Harman

Published: 2025-09-30T16:00:08Z

Content type: article

Language: en

Sources: [Meta AI Research](<https://devfeed.tech/sources/meta-ai-research.md>)

Topics: [Testing](<https://devfeed.tech/topics/testing.md>), [mutation-testing](<https://devfeed.tech/topics/mutation-testing.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Meta](<https://devfeed.tech/topics/meta.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-research](<https://devfeed.tech/tags/ai-research.md>), [code](<https://devfeed.tech/tags/code.md>), [llms](<https://devfeed.tech/tags/llms.md>), [meta](<https://devfeed.tech/tags/meta.md>), [ml-applications](<https://devfeed.tech/tags/ml-applications.md>), [mutation-testing](<https://devfeed.tech/tags/mutation-testing.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Meta describes its Automated Compliance Hardening (ACH) tool, which uses large language models to generate relevant code mutants and tests designed to catch them. The article explains how this supports mutation testing and helps identify compliance-related bugs.

### Source excerpt

Following our keynote presentations at FSE 2025 and Eurostar 2025, we're delving further into the development of Meta's Automated Compliance Hardening (ACH) tool, an LLM-based tool for software testing that is automating aspects of compliance adherence at Meta, while accelerating developer and product velocity. By leveraging LLMs we've been able to overcome the barriers that [...] Read More... The post LLMs Are the Key to Mutation Testing and Better Compliance appeared first on Engineering at Meta.

## Data Inventory

DevFeed: [Data Inventory](<https://devfeed.tech/articles/data-inventory-15451.md>)

Original publisher: [Read original article](<https://medium.com/wise-engineering/data-inventory-4eff3f015553?source=rss----f2565bbe9c46---4>)

Author: Ritesh Modi

Published: 2025-02-19T14:24:14Z

Content type: tutorial

Language: en

Sources: [Wise Engineering - Medium](<https://devfeed.tech/sources/wise-engineering-medium.md>)

Topics: [data-governance](<https://devfeed.tech/topics/data-governance.md>), [data-architecture](<https://devfeed.tech/topics/data-architecture.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [backend](<https://devfeed.tech/tags/backend.md>), [data](<https://devfeed.tech/tags/data.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [databases](<https://devfeed.tech/tags/databases.md>), [frontend](<https://devfeed.tech/tags/frontend.md>), [governance](<https://devfeed.tech/tags/governance.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [platform](<https://devfeed.tech/tags/platform.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

Wise's Data Governance team describes Data Inventory, a catalog of data assets that records their locations and security or privacy controls. The article explains the system's constraints, design outcomes, and process for discovering operational databases and their metadata.

### Source excerpt

The Data Governance team, part of Data Platform, develops and operates platform products through which autonomous teams can govern their data. The team's vision is to democratise data in a secure and compliant manner. Data Inventory was the team's first product. What is Data Inventory? A data inventory is an extensive catalog of the Wise's data assets. It helps us understand where the data is located and what kind of security / privacy controls are in place. This is also a requirement for ISO 27001:2022. What are the constraints? Any system has to work well with our controls and way-of-working. This led to following constraints: It shall be built in a way that satisfies our security controls such as network segmentation, least privilege access, secure secret management, etc. It shall be easy to integrate with other in-house platforms to provide cohesive experience. It shall be built to connect with heterogeneous and fragmented infrastructure. Many data systems are built through off-the-shelf or managed service offering but others are built & operated in-house. The system shall be integrated by default with technology provided by Data Platform. On another hand, it shall be extensible enough to integrate with data systems not maintained by Data Platform. How did we build our inventory? At high level, we split this into 4 main outcomes: 1. Register assets at correct granularity. 2. Identify the correct owner and make them accountable for the life cycle. 3. Extract the schema of the data asset. 4. Classify the asset with correct sensitivity. This is how design looks at high level: To achieve the above design and outcome, we follow the following steps: Step 0: Discover data systems network metadata Scanners need to be aware of the network metadata before doing scanning. For example: - What is the host or connection string? - What is the technology of the data system? - What is the name of the data system? Let us take an example of how we solve it in our operational datab

## Manifest V2 phase-out begins

DevFeed: [Manifest V2 phase-out begins](<https://devfeed.tech/articles/manifest-v2-phase-out-begins-4184.md>)

Original publisher: [Read original article](<https://blog.chromium.org/2024/05/manifest-v2-phase-out-begins.html>)

Author: Chromium Blog (noreply@blogger.com)

Published: 2024-05-30T16:45:00Z

Content type: article

Language: en

Sources: [Chromium Blog](<https://devfeed.tech/sources/chromium-blog.md>)

Topics: [Extension](<https://devfeed.tech/topics/extension.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Document Object Model (DOM)](<https://devfeed.tech/topics/dom.md>), [uBlock Origin Filters](<https://devfeed.tech/topics/ublock-origin-filters.md>)

Tags: [chrome](<https://devfeed.tech/tags/chrome.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [community](<https://devfeed.tech/tags/community.md>), [extension](<https://devfeed.tech/tags/extension.md>), [extensions](<https://devfeed.tech/tags/extensions.md>), [feature](<https://devfeed.tech/tags/feature.md>), [manifest](<https://devfeed.tech/tags/manifest.md>), [migration](<https://devfeed.tech/tags/migration.md>), [none](<https://devfeed.tech/tags/none.md>), [performance](<https://devfeed.tech/tags/performance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Chrome has begun disabling extensions that still use Manifest V2. The article describes the transition to Manifest V3, which is intended to improve extension security, privacy, performance, and trustworthiness while preserving existing functionality. It highlights community-driven improvements, including user scripts, offscreen documents for DOM APIs, larger declarativeNetRequest rulesets, faster review of safe rule updates, and version rollback. More than 85% of actively maintained Chrome Web Store extensions were reported to use Manifest V3.

### Source excerpt

Update (10/10/2024): We've started disabling extensions still using Manifest V2 in Chrome stable. Read more details in the MV2 support timeline documentation. In November 2023, we shared a timeline for the phasing out of Manifest V2 extensions in Chrome. Based on the progress and feedback we've seen from the community, we're now ready to roll out these changes as scheduled. We've always been clear that the goal of Manifest V3 is to protect existing functionality while improving the security, privacy, performance and trustworthiness of the extension ecosystem as a whole. We appreciate the collaboration and feedback from the community that has allowed us - and continues to allow us - to constantly improve the extensions platform. Addressing community feedback We understand migrations of this magnitude can be challenging, which is why we've listened to developer feedback and spent years refining Manifest V3 to support the innovation happening across the extensions community. This included adding support for user scripts and introducing offscreen documents to allow extensions to use DOM APIs from a background context. Based on input from the extension community, we also increased the number of rulesets for declarativeNetRequest, allowing extensions to bundle up to 330,000 static rules and dynamically add a further 30,000. You can find more detail in our content filtering guide. This month, we made the transition even easier for extensions using declarativeNetRequest with the launch of review skipping for safe rule updates. If the only changes are for safe modifications to an extension's static rule list for declarativeNetRequest, Chrome will approve the update in minutes. Coupled with the launch of version roll back last month, developers now have greater control over how their updates are deployed. Ecosystem progress After we addressed the top issues and feature gaps blocking migration last year, we saw an acceleration of extensions migrating successfully to Manifest V

## 3 tips from Snyk and Dynatrace's AI security experts

DevFeed: [3 tips from Snyk and Dynatrace's AI security experts](<https://devfeed.tech/articles/3-tips-from-snyk-and-dynatrace-s-ai-security-experts-8124.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-dynatrace-ai-fireside-chat/>)

Author: Sarah Conway

Published: 2024-01-22T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [ai-governance](<https://devfeed.tech/topics/ai-governance.md>), [dynatrace](<https://devfeed.tech/topics/dynatrace.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [dynatrace](<https://devfeed.tech/tags/dynatrace.md>), [executive](<https://devfeed.tech/tags/executive.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [governance](<https://devfeed.tech/tags/governance.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

This article recaps a Snyk and Dynatrace fireside chat about generative AI security. It examines AI's effects on software development and business application security, emphasizing cross-team governance, careful testing and implementation, and sustained security attention throughout development.

### Source excerpt

Learn more about generative AI security in this recap from our recent fireside chat, featuring security and privacy experts from Snyk and Dynatrace.

## How to intercept, observe & mock WebRTC traffic

DevFeed: [How to intercept, observe & mock WebRTC traffic](<https://devfeed.tech/articles/how-to-intercept-observe-mock-webrtc-traffic-19079.md>)

Original publisher: [Read original article](<https://httptoolkit.com/blog/intercepting-webrtc-traffic/>)

Author: HTTP Toolkit; Tim Perry

Published: 2022-10-13T10:00:00Z

Content type: tutorial

Language: en

Sources: [HTTP Toolkit](<https://devfeed.tech/sources/http-toolkit.md>)

Topics: [WebRTC](<https://devfeed.tech/topics/webrtc.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [debugging](<https://devfeed.tech/tags/debugging.md>), [developer-tools](<https://devfeed.tech/tags/developer-tools.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [interception](<https://devfeed.tech/tags/interception.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [p2p](<https://devfeed.tech/tags/p2p.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [webrtc](<https://devfeed.tech/tags/webrtc.md>)

### AI overview

This tutorial explains why WebRTC traffic is difficult to inspect and mock, covering its peer-to-peer encryption, negotiated networking, and limited debugging APIs. It introduces MockRTC and describes how controlling one peer can enable interception, observation, and transformation of WebRTC traffic.

### Source excerpt

WebRTC allows two users on the web to communicate directly, sending real-time streams of video, audio & data peer-to-peer, from within a browser environment. It's exciting tech that's rapidly maturing, already forming the backbone of a huge range of video chat, screen sharing and live collaboration tools, but also as a key technology for decentralization of web apps - providing a P2P data transport layer used by everything from WebTorrent to IPFS to Yjs. Unfortunately though, it doesn't have the tooling ecosystem that developers used to networking with HTTP often expect. There's few supporting tools or libraries, inspecting raw traffic is hard or impossible, and mocking WebRTC traffic for automated testing is even harder. Even built-in low-level browser tools like chrome://webrtc-internals don't allow seeing messages sent on WebRTC data channels. It's hard to build modern secure web applications on top of protocols that you can't directly see or interact with. This doesn't just affect developers: it also seriously impacts security & privacy researchers and reverse engineers, each trying to investigate the traffic sent & received by the apps we all use. If you want to know what data a webapp you use is sending over WebRTC, right now it's very hard to find out. Intercepting WebRTC traffic to build these tools and libraries is difficult, because unlike protocols like HTTP that were designed to allow active proxying and user-configureable PKI (i.e. CA certificates) early on, WebRTC encrypts all traffic using peer-to-peer negotiated certificates for authentication without PKI, communicates in a wide variety of different negotiated ways at the network level to avoid NAT issues, and offers no convenient APIs to configure this for debugging. All of this provides some great features to the protocol as a user, but some serious challenges when building developer tools. As it turns out though, despite this, there are just enough places where we can hook into that it is possible

## Public CDNs Can Create Security, Privacy, and Stability Risks

DevFeed: [Public CDNs Can Create Security, Privacy, and Stability Risks](<https://devfeed.tech/articles/public-cdns-are-useless-and-dangerous-19093.md>)

Original publisher: [Read original article](<https://httptoolkit.com/blog/public-cdn-risks/>)

Author: HTTP Toolkit; Tim Perry

Published: 2021-07-19T14:15:00Z

Content type: opinion

Language: en

Sources: [HTTP Toolkit](<https://devfeed.tech/sources/http-toolkit.md>)

Topics: [cdnjs](<https://devfeed.tech/topics/cdnjs.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [modern web development](<https://devfeed.tech/topics/modern-web-development.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [jQuery](<https://devfeed.tech/topics/jquery.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [caching](<https://devfeed.tech/tags/caching.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [performance](<https://devfeed.tech/tags/performance.md>), [reference](<https://devfeed.tech/tags/reference.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

This article argues that using public CDNs for common scripts and styles can introduce security, privacy, and stability risks while providing limited modern benefits. It recommends self-hosting content and dependencies, with a private caching CDN placed in front of the application for performance.

### Source excerpt

Once upon a time, loading common scripts & styles from a public CDN like cdnjs or Google's Hosted Libraries was a 'best practice' - a great way to instantly speed up your page loads, optimize caching, and reduce costs. Nowadays, it's become a recipe for security, privacy & stability problems, with near-zero benefit. Just last week, a security researcher showed how this could go horribly wrong. There are ways to mitigate those risks, but in practice the best solution is to avoid them entirely: self-host your content and dependencies, and then use your own caching CDN directly in front of your application instead for performance. I'll explain what that means in a second. First though, why was this a good idea, and how has it now become such a mess? Why was this a good idea? The main benefit that public CDNs of popular libraries offered was shared caching. If you used a popular version of jQuery then you could reference it from a public CDN URL, and if a user had recently visited another site that used the same version of jQuery from the same CDN then it would load instantly, straight from their cache. In effect, sites could share resources (almost always JavaScript) between one another to improve caching, reduce load times, and save bandwidth for sites and visitors. Even in the uncached case, this still offered benefits. Browsers limit the number of simultaneous open connections by domain, which limits the performance of parallel resource downloads. By using a separate domain for some resources, resource loading could be spread across more connections, improving load times for visitors. Lastly, the main site's cookies aren't sent in requests to 3rd party domains. If you have large cookies stored for your domain, this creates a lot of unnecessary data sent in every request to your domain, again unnecessarily increasing bandwidth usage and load times (honestly I'm not sure if this overhead really had a practical impact, but it was certainly widely documented as an impor

## Includes No Dirt: Healthcare Threat Modeling (Thursday)

DevFeed: [Includes No Dirt: Healthcare Threat Modeling (Thursday)](<https://devfeed.tech/articles/includes-no-dirt-healthcare-threat-modeling-thursday-36838.md>)

Original publisher: [Read original article](<https://shostack.org/blog/includes-no-dirt-healthcare-threat-modeling-thursday/>)

Author: Adam

Published: 2019-10-31T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [development-process](<https://devfeed.tech/tags/development-process.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

A commentary on the "Includes No Dirt" threat modeling approach by William Dogherty and Patrick Curry of Omada Health. The article describes its focus on security, privacy, and compliance, outlines the NO DIRT model and supporting worksheets, and discusses its potential use in development and vendor risk management.

### Source excerpt

"Includes No Dirt" is a threat modeling approach by William Dogherty and Patrick Curry of Omada Health, and I've been meaning to write about it since it came out.

## Threat Modeling & IoT

DevFeed: [Threat Modeling & IoT](<https://devfeed.tech/articles/threat-modeling-iot-37025.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-and-iot/>)

Author: Adam

Published: 2017-05-01T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Internet of things](<https://devfeed.tech/topics/iot.md>), [Security](<https://devfeed.tech/topics/security.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [iot](<https://devfeed.tech/tags/iot.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

This article explains how threat modeling for internet-connected devices resembles threat modeling for other computers while presenting recurring IoT-specific tensions. It examines device interfaces, web servers and cloud connectivity, security and privacy tradeoffs, support and operations costs, dependency vulnerabilities, and the conflict between allowing device updates and limiting attackers' ability to install software.

### Source excerpt

[no description provided]

## Developing TextSecure iOS with the Axolotl Protocol

DevFeed: [Developing TextSecure iOS with the Axolotl Protocol](<https://devfeed.tech/articles/a-whisper-1727.md>)

Original publisher: [Read original article](<https://signal.org/blog/a-whisper/>)

Published: 2014-01-10T00:00:00Z

Content type: article

Language: en

Sources: [Signal Blog](<https://devfeed.tech/sources/signal-blog.md>)

Topics: [iOS](<https://devfeed.tech/topics/ios.md>), [Security](<https://devfeed.tech/topics/security.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [Code](<https://devfeed.tech/topics/code.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [ios](<https://devfeed.tech/tags/ios.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [usability](<https://devfeed.tech/tags/usability.md>)

### AI overview

The article describes work on TextSecure iOS, including contributions from several developers and implementation of the Axolotl protocol. It also considers usability and brand coherence as Open Whisper Systems expands across applications and devices.

### Source excerpt

Winter Break of Code, Day Four At the Open Whisper Systems spring break of code in 2013, I started work on TextSecure iOS. People are chomping at the bit to use our software on iOS. After a hiatus from the project, I've been happy to return to it over the last few months, joining some other contributors, including Frederic Jacobs as co-lead, Alban Diquet, and Claudiu-Vlad Ursache submitting pull requests, even over the holidays, with important cryptographic storage and UI-polishing contributions, and Bitcoin donations coming in from around the world. Contribute code or coins. Read more...