# pii

Personally identifiable information (PII) is information that can distinguish or trace an individual's identity, alone or combined with linked information.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Build a serverless PII redaction pipeline with Amazon Bedrock Data Automation

DevFeed: [Build a serverless PII redaction pipeline with Amazon Bedrock Data Automation](<https://devfeed.tech/articles/build-a-serverless-pii-redaction-pipeline-with-amazon-bedrock-data-automation-31519.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/machine-learning/build-a-serverless-pii-redaction-pipeline-with-amazon-bedrock-data-automation/>)

Author: Samantha Stuart

Published: 2026-09-16T15:17:37Z

Content type: tutorial

Language: en

Sources: [Artificial Intelligence](<https://devfeed.tech/sources/artificial-intelligence.md>)

Topics: [Amazon Bedrock](<https://devfeed.tech/topics/amazon-bedrock.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>), [AWS Lambda](<https://devfeed.tech/topics/aws-lambda.md>), [AWS Step Functions](<https://devfeed.tech/topics/aws-step-functions.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Ansible](<https://devfeed.tech/topics/ansible.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [amazon-bedrock](<https://devfeed.tech/tags/amazon-bedrock.md>), [amazon-bedrock-data-automation](<https://devfeed.tech/tags/amazon-bedrock-data-automation.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [aws-step-functions](<https://devfeed.tech/tags/aws-step-functions.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [pii-redaction](<https://devfeed.tech/tags/pii-redaction.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [precision](<https://devfeed.tech/tags/precision.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [technical-how-to](<https://devfeed.tech/tags/technical-how-to.md>)

### AI overview

This tutorial presents a serverless AWS pipeline for detecting and redacting personally identifiable information in scanned documents and images. It uses Amazon Bedrock Data Automation with a custom blueprint, AWS Step Functions, and AWS Lambda, with a token-matching quality check to improve recall on degraded and handwritten documents.

### Source excerpt

Learn how to automate end-to-end PII detection and redaction from scanned documents at scale using Amazon Bedrock Data Automation with a custom blueprint, AWS Step Functions, and AWS Lambda. A custom blueprint redacts sensitive fields with field-level precision, and a token matching quality check raises recall across degraded and handwritten documents.

## Your redaction filter works. Are you quite sure?

DevFeed: [Your redaction filter works. Are you quite sure?](<https://devfeed.tech/articles/your-redaction-filter-works-are-you-quite-sure-12662.md>)

Original publisher: [Read original article](<https://tyk.io/blog/your-redaction-filter-works-are-you-quite-sure/>)

Author: Hal Tyk's tutorial bot

Published: 2026-09-03T09:03:23Z

Content type: tutorial

Language: en

Sources: [Tyk API Management](<https://devfeed.tech/sources/tyk-api-management.md>)

Topics: [Tutorial](<https://devfeed.tech/topics/tutorial.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Script](<https://devfeed.tech/topics/script.md>), [Regular expression](<https://devfeed.tech/topics/regular-expression.md>), [payload](<https://devfeed.tech/topics/payload.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [ai-gateway](<https://devfeed.tech/tags/ai-gateway.md>), [ai-studio](<https://devfeed.tech/tags/ai-studio.md>), [api](<https://devfeed.tech/tags/api.md>), [api-management](<https://devfeed.tech/tags/api-management.md>), [api-platform-teams](<https://devfeed.tech/tags/api-platform-teams.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [llm-governance](<https://devfeed.tech/tags/llm-governance.md>), [payload](<https://devfeed.tech/tags/payload.md>), [pii](<https://devfeed.tech/tags/pii.md>), [pii-redaction](<https://devfeed.tech/tags/pii-redaction.md>), [tengo](<https://devfeed.tech/tags/tengo.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

This tutorial explains how to create and test a Tyk request filter that redacts personal data before a request reaches an AI model. It covers Enterprise licensing, request and response filter behavior, the PII Redaction template, and the Tengo scripting contract using the Tyk module and regular expressions.

### Source excerpt

Hello. I'm Hal, Tyk's tutorial bot, and today I have been given something genuinely useful to explain: how to stop personal data reaching a model in the first place. We are going to write a filter, find a gap in it before a single request has been sent, fix the gap, and only then let [...] The post Your redaction filter works. Are you quite sure? appeared first on Tyk API Management.

## The Four Vendor Relationships Commonly Involved in a Production Voice Feature

DevFeed: [The Four Vendor Relationships Commonly Involved in a Production Voice Feature](<https://devfeed.tech/articles/how-assemblyai-collapsed-four-vendors-into-a-single-api-key-17932.md>)

Original publisher: [Read original article](<https://read.bytesizeddesign.com/p/how-assemblyai-collapsed-needing-four-vendors-to-summarize-a-phone-call>)

Author: Byte-Sized Design

Published: 2026-08-28T21:47:43Z

Content type: article

Language: en

Sources: [Byte-Sized Design](<https://devfeed.tech/sources/byte-sized-design.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [pii](<https://devfeed.tech/topics/pii.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [api](<https://devfeed.tech/tags/api.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [llm](<https://devfeed.tech/tags/llm.md>), [pii](<https://devfeed.tech/tags/pii.md>), [pii-redaction](<https://devfeed.tech/tags/pii-redaction.md>), [production](<https://devfeed.tech/tags/production.md>), [transcription](<https://devfeed.tech/tags/transcription.md>), [voice](<https://devfeed.tech/tags/voice.md>)

### AI overview

The article describes how a production voice feature typically involves four vendor relationships: transcription, PII redaction, an LLM provider, and compliance review.

### Source excerpt

TLDR A production voice feature in 2026 typically ships with four vendor relationships: a transcription API, a PII redaction step somebody built in a sprint, an LLM provider, and a compliance review stretched across all of it.

## Chaining Activities -- from text to vectors

DevFeed: [Chaining Activities -- from text to vectors](<https://devfeed.tech/articles/chaining-activities-from-text-to-vectors-35756.md>)

Original publisher: [Read original article](<https://temporal.io/blog/chaining-activities-from-text-to-vectors>)

Author: Houman Kargaran

Published: 2026-08-12T00:00:00Z

Content type: tutorial

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Embeddings](<https://devfeed.tech/topics/embeddings.md>), [on-prem](<https://devfeed.tech/topics/on-prem.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Redis](<https://devfeed.tech/topics/redis.md>), [retry](<https://devfeed.tech/topics/retry.md>), [Sequences](<https://devfeed.tech/topics/sequences.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [community](<https://devfeed.tech/tags/community.md>), [data-pipeline](<https://devfeed.tech/tags/data-pipeline.md>), [embeddings](<https://devfeed.tech/tags/embeddings.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [pii](<https://devfeed.tech/tags/pii.md>), [redis](<https://devfeed.tech/tags/redis.md>), [retries](<https://devfeed.tech/tags/retries.md>), [storage](<https://devfeed.tech/tags/storage.md>)

### AI overview

This guest post explains a Temporal workflow that chains discrete Activities to process complaints while maintaining a PII boundary. It uses an on-premises all-MiniLM-L6-v2 model for embeddings, caches vectors in Redis, stores them externally, and relies on deterministic workflow sequencing and retry policies.

### Source excerpt

Learn how to build a durable, PII-conscious data pipeline with Temporal using on-prem embeddings, idempotent Activities, external vector storage, and retries.

## Using Activity isolation as a security boundary

DevFeed: [Using Activity isolation as a security boundary](<https://devfeed.tech/articles/using-activity-isolation-as-a-security-boundary-36089.md>)

Original publisher: [Read original article](<https://temporal.io/blog/using-activity-isolation-as-a-security-boundary>)

Author: Houman Kargaran

Published: 2026-08-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [data](<https://devfeed.tech/topics/data.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [isolation](<https://devfeed.tech/tags/isolation.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [ml](<https://devfeed.tech/tags/ml.md>), [pii](<https://devfeed.tech/tags/pii.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This guest post explains why a regulated application keeps PII scanning, classification, redaction, and storage within a single Temporal Activity. The design prevents sensitive data from crossing Activity boundaries and appearing in the Temporal UI, while using an in-house MCP server, an internal ML model, and a swappable storage layer.

### Source excerpt

How keeping PII scan, classification, and storage inside one Temporal Activity stops raw data from ever crossing a boundary.

## The forbidden index: Building privacy-preserving search with OpenSearch

DevFeed: [The forbidden index: Building privacy-preserving search with OpenSearch](<https://devfeed.tech/articles/the-forbidden-index-building-privacy-preserving-search-with-opensearch-12790.md>)

Original publisher: [Read original article](<https://opensearch.org/blog/the-forbidden-index-building-privacy-preserving-search-with-opensearch/>)

Author: Kylie Wagar-Dirks

Published: 2026-07-24T15:00:22Z

Content type: article

Language: en

Sources: [OpenSearch](<https://devfeed.tech/sources/opensearch.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [pii](<https://devfeed.tech/topics/pii.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [tokenization](<https://devfeed.tech/topics/tokenization.md>), [data](<https://devfeed.tech/topics/data.md>), [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [Framework](<https://devfeed.tech/topics/framework.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [analytics-stack](<https://devfeed.tech/tags/analytics-stack.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [data](<https://devfeed.tech/tags/data.md>), [dynamic-data](<https://devfeed.tech/tags/dynamic-data.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [opensearch](<https://devfeed.tech/tags/opensearch.md>), [pii](<https://devfeed.tech/tags/pii.md>), [plugin](<https://devfeed.tech/tags/plugin.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [search](<https://devfeed.tech/tags/search.md>), [tokenization](<https://devfeed.tech/tags/tokenization.md>)

### AI overview

The article describes a talk by Unnati Mishra and Akshat Khanna on building privacy-preserving search and analytics with OpenSearch. Their approach moves privacy controls into the ingest layer, using a custom plugin to redact PII at index time through tokenization and dynamic data masking. It also applies differential privacy to OpenSearch Dashboards by adding calibrated noise to aggregate query results.

### Source excerpt

At OpenSearchCon Europe 2026, Unnati Mishra and Akshat Khanna (Angel One) argued that privacy in search must be handled during the ingest phase rather than retroactively through access controls. The post The forbidden index: Building privacy-preserving search with OpenSearch appeared first on OpenSearch.

## The foundation: Why Temporal for a data pipeline?

DevFeed: [The foundation: Why Temporal for a data pipeline?](<https://devfeed.tech/articles/the-foundation-why-temporal-for-a-data-pipeline-36063.md>)

Original publisher: [Read original article](<https://temporal.io/blog/the-foundation-why-temporal-for-a-data-pipeline>)

Author: Houman Kargaran

Published: 2026-07-23T00:00:00Z

Content type: tutorial

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [consistency](<https://devfeed.tech/topics/consistency.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [observability](<https://devfeed.tech/topics/observability.md>), [AI search](<https://devfeed.tech/topics/ai-search.md>), [Embeddings](<https://devfeed.tech/topics/embeddings.md>)

Tags: [auditability](<https://devfeed.tech/tags/auditability.md>), [community](<https://devfeed.tech/tags/community.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [data-pipeline](<https://devfeed.tech/tags/data-pipeline.md>), [embeddings](<https://devfeed.tech/tags/embeddings.md>), [execution](<https://devfeed.tech/tags/execution.md>), [foundation](<https://devfeed.tech/tags/foundation.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [search](<https://devfeed.tech/tags/search.md>), [temporal](<https://devfeed.tech/tags/temporal.md>)

### AI overview

This tutorial explains how to justify Temporal as the orchestration layer for a PII-compliant complaint-ingestion pipeline. It covers requirements for resilience, consistency, availability, observability, redaction, internal classification, and semantic search over complaint data.

### Source excerpt

How to justify Temporal for a regulated data pipeline: the requirements, the naive approach, and why Durable Execution wins on resilience and auditability.

## Beyond Redaction: Anatomy of a Privacy-Safe Data Platform

DevFeed: [Beyond Redaction: Anatomy of a Privacy-Safe Data Platform](<https://devfeed.tech/articles/beyond-redaction-anatomy-of-a-privacy-safe-data-platform-18252.md>)

Original publisher: [Read original article](<https://www.dataengineeringweekly.com/p/beyond-redaction-anatomy-of-a-privacy>)

Author: Ananth Packkildurai

Published: 2026-07-10T10:20:21Z

Content type: tutorial

Language: en

Sources: [Data Engineering Weekly](<https://devfeed.tech/sources/data-engineering-weekly.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [pii](<https://devfeed.tech/topics/pii.md>), [synthetic-data](<https://devfeed.tech/topics/synthetic-data.md>), [Query (disambiguation)](<https://devfeed.tech/topics/query.md>)

Tags: [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [pii](<https://devfeed.tech/tags/pii.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [synthetic-data](<https://devfeed.tech/tags/synthetic-data.md>), [tokenization](<https://devfeed.tech/tags/tokenization.md>)

### AI overview

This article explains why privacy-safe data platforms must preserve only the utility required for an approved purpose while controlling linkability and generating evidence that safeguards operated. It compares redaction, encryption, tokenization, governed views, aggregation, synthetic data, and clean-room access, emphasizing that deterministic tokens are generally pseudonymous rather than automatically anonymous.

### Source excerpt

Why privacy engineering is about governing data in use--not simply hiding it.

## Introducing OpenAI Privacy Filter

DevFeed: [Introducing OpenAI Privacy Filter](<https://devfeed.tech/articles/introducing-openai-privacy-filter-6508.md>)

Original publisher: [Read original article](<https://openai.com/index/introducing-openai-privacy-filter>)

Published: 2026-04-22T00:00:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [privacy-filter](<https://devfeed.tech/topics/privacy-filter.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [developers](<https://devfeed.tech/tags/developers.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [model](<https://devfeed.tech/tags/model.md>), [open](<https://devfeed.tech/tags/open.md>), [openai](<https://devfeed.tech/tags/openai.md>), [pii](<https://devfeed.tech/tags/pii.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [privacy-filter](<https://devfeed.tech/tags/privacy-filter.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

OpenAI introduces Privacy Filter, a small open-weight model that detects and redacts personally identifiable information in unstructured text. It supports context-aware, local, high-throughput processing and can be fine-tuned for privacy workflows.

### Source excerpt

OpenAI Privacy Filter is an open-weight model for detecting and redacting personally identifiable information (PII) in text with state-of-the-art accuracy

## Как маскировать персональные данные на изображениях: наш эксперимент с OCR и NER

DevFeed: [Как маскировать персональные данные на изображениях: наш эксперимент с OCR и NER](<https://devfeed.tech/articles/ocr-ner-23996.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/redmadrobot/articles/1011450/>)

Author: andrivasg (red\_mad\_robot)

Published: 2026-03-17T15:55:37Z

Content type: tutorial

Language: ru

Sources: [Redmadrobot EN](<https://devfeed.tech/sources/redmadrobot-en.md>), [Redmadrobot RU](<https://devfeed.tech/sources/redmadrobot-ru.md>)

Topics: [Natural language processing](<https://devfeed.tech/topics/nlp.md>), [pii](<https://devfeed.tech/topics/pii.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [computer-vision](<https://devfeed.tech/tags/computer-vision.md>), [llm](<https://devfeed.tech/tags/llm.md>), [ner](<https://devfeed.tech/tags/ner.md>), [nlp](<https://devfeed.tech/tags/nlp.md>), [ocr](<https://devfeed.tech/tags/ocr.md>), [pii](<https://devfeed.tech/tags/pii.md>), [red-mad-robot](<https://devfeed.tech/tags/red-mad-robot.md>), [rnd](<https://devfeed.tech/tags/rnd.md>), [tag-601fbc7112a4](<https://devfeed.tech/tags/tag-601fbc7112a4.md>), [tag-7bc388df28ed](<https://devfeed.tech/tags/tag-7bc388df28ed.md>), [tag-9bf5e01ce62e](<https://devfeed.tech/tags/tag-9bf5e01ce62e.md>), [tag-b92bf5906bbd](<https://devfeed.tech/tags/tag-b92bf5906bbd.md>), [tag-ef0b1bf200df](<https://devfeed.tech/tags/tag-ef0b1bf200df.md>)

### AI overview

The article describes red_mad_robot's experiment using OCR combined with a NER model to detect and selectively mask personally identifiable information in images without training specialized visual detectors. On a dataset of 40 annotated images, the pipeline masked 90% of personal data while falsely masking 14% of text polygons; performance declined on difficult real-world photographs.

### Source excerpt

Всем привет! Меня зовут Андрей Иванов, я NLP-исследователь в R&D red_mad_robot. Мы разрабатываем систему Guardrails для защиты персональных данных (PII) и фильтрации небезопасного контента. В этой статье расскажу, как мы решали задачу точечного маскирования PII на картинках без обучения специальных визуальных детекторов. Разберём связку оптического распознавания символов (OCR) с NER-моделью, покажем метрики на реальных данных, раскроем ограничения подхода и наши решения для их преодоления. Читать далее

## How AI firewalls protect production applications from prompt injection, data leakage, and excessive usage

DevFeed: [How AI firewalls protect production applications from prompt injection, data leakage, and excessive usage](<https://devfeed.tech/articles/ai-firewall-29071.md>)

Original publisher: [Read original article](<https://blog.alexewerlof.com/p/ai-firewall>)

Author: Alex Ewerlöf

Published: 2026-03-15T23:51:29Z

Content type: tutorial

Language: en

Sources: [Alex Ewerlof Notes](<https://devfeed.tech/sources/alex-ewerlof-notes.md>)

Topics: [Firewall](<https://devfeed.tech/topics/firewall.md>), [Security](<https://devfeed.tech/topics/security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [LLMs](<https://devfeed.tech/topics/llms.md>), [rate-limiting](<https://devfeed.tech/topics/rate-limiting.md>), [pii](<https://devfeed.tech/topics/pii.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [llms](<https://devfeed.tech/tags/llms.md>), [pii](<https://devfeed.tech/tags/pii.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [rate-limiting](<https://devfeed.tech/tags/rate-limiting.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This tutorial explains AI firewalls, or AI gateways, as reverse proxies with AI-focused inspection between an application backend and an inference provider. It covers ingress attacks such as prompt injection, egress risks including PII and secrets, rate limiting to control costs, latency considerations, implementation trade-offs, and layered defenses.

### Source excerpt

How to protect your AI application in production against new classes of attacks

## 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII

DevFeed: [280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII](<https://devfeed.tech/articles/280-leaky-skills-how-openclaw-clawhub-are-exposing-api-keys-and-pii-8040.md>)

Original publisher: [Read original article](<https://snyk.io/blog/openclaw-skills-credential-leaks-research/>)

Author: Luca Beurer-Kellner; Aleksei Kudrinskii; Marco Milanta; Kristian Bonde Nielsen; Hemang Sarkar; Liran Tal

Published: 2026-02-05T18:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [interest](<https://devfeed.tech/tags/interest.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [pii](<https://devfeed.tech/tags/pii.md>), [secrel](<https://devfeed.tech/tags/secrel.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [skills](<https://devfeed.tech/tags/skills.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk reports that 283 of 3,984 skills in the ClawHub marketplace, or 7.1%, contain critical flaws that expose API keys, passwords, credit card numbers, and other sensitive information through LLM context and plaintext logs. The article explains how OpenClaw agent skills can instruct agents to mishandle secrets and describes a credential-leaking email skill as an example.

### Source excerpt

Discover how 7.1% of AI agent skills are designed to leak secrets, PII, and API keys through LLM context. Learn to defend with Evo & mcp-scan.

## Drowning in spam or scam emails? Here's probably why

DevFeed: [Drowning in spam or scam emails? Here's probably why](<https://devfeed.tech/articles/drowning-in-spam-or-scam-emails-here-s-probably-why-8351.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/cybersecurity/drowning-spam-scam-emails-why/>)

Author: Phil Muncaster

Published: 2026-01-27T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [pii](<https://devfeed.tech/topics/pii.md>), [data](<https://devfeed.tech/topics/data.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [Netflix](<https://devfeed.tech/topics/netflix.md>)

Tags: [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [data](<https://devfeed.tech/tags/data.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [internet](<https://devfeed.tech/tags/internet.md>), [malware](<https://devfeed.tech/tags/malware.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [pii](<https://devfeed.tech/tags/pii.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

This article explains why inboxes can suddenly be flooded with spam and scam emails. It identifies data breaches, leaked personal information, updated phishing kits, spam-filter bypasses, and targeted campaigns as possible causes, and describes risks including credential theft, financial fraud, and malware installation.

### Source excerpt

Has your inbox recently been deluged with unwanted and even outright malicious messages? Here are 10 possible reasons - and how to stem the tide.

## Your personal information is on the dark web. What happens next?

DevFeed: [Your personal information is on the dark web. What happens next?](<https://devfeed.tech/articles/your-personal-information-is-on-the-dark-web-what-happens-next-8395.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/privacy/information-dark-web-what-happens-next/>)

Author: Phil Muncaster

Published: 2026-01-13T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [online privacy](<https://devfeed.tech/topics/online-privacy.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [breach](<https://devfeed.tech/tags/breach.md>), [data](<https://devfeed.tech/tags/data.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [genai](<https://devfeed.tech/tags/genai.md>), [generative](<https://devfeed.tech/tags/generative.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [pii](<https://devfeed.tech/tags/pii.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

This article explains what may happen when personal information appears on the dark web, including fraud and account hijacking. It describes data breaches, infostealer malware, ransomware-related extortion, phishing, and generative AI-assisted attacks as routes by which personal and financial data can be exposed and sold.

### Source excerpt

If your data is on the dark web, it's probably only a matter of time before it's abused for fraud or account hijacking. Here's what to do.

## A differentially private framework for gaining insights into AI chatbot use

DevFeed: [A differentially private framework for gaining insights into AI chatbot use](<https://devfeed.tech/articles/a-differentially-private-framework-for-gaining-insights-into-ai-chatbot-use-6738.md>)

Original publisher: [Read original article](<https://research.google/blog/a-differentially-private-framework-for-gaining-insights-into-ai-chatbot-use/>)

Published: 2025-12-10T21:59:41Z

Content type: article

Language: en

Sources: [The latest research from Google](<https://devfeed.tech/sources/the-latest-research-from-google.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Google](<https://devfeed.tech/topics/google.md>), [Algorithm](<https://devfeed.tech/topics/algorithm.md>), [pii](<https://devfeed.tech/topics/pii.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chatbots](<https://devfeed.tech/tags/chatbots.md>), [clustering](<https://devfeed.tech/tags/clustering.md>), [code](<https://devfeed.tech/tags/code.md>), [data](<https://devfeed.tech/tags/data.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [google](<https://devfeed.tech/tags/google.md>), [insights](<https://devfeed.tech/tags/insights.md>), [large-language-model](<https://devfeed.tech/tags/large-language-model.md>), [llm](<https://devfeed.tech/tags/llm.md>), [pii](<https://devfeed.tech/tags/pii.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [research](<https://devfeed.tech/tags/research.md>), [responsible-ai](<https://devfeed.tech/tags/responsible-ai.md>), [security-privacy-and-abuse-prevention](<https://devfeed.tech/tags/security-privacy-and-abuse-prevention.md>)

### AI overview

Google Research introduces Urania, a framework for generating high-level insights into AI chatbot usage while protecting user conversation privacy. Its pipeline combines differentially private clustering, keyword extraction, and LLM summarization to provide formal, end-to-end differential privacy guarantees.

### Source excerpt

Generative AI

## How to Handle PII in Staging Databases Without Losing Realistic Data

DevFeed: [How to Handle PII in Staging Databases Without Losing Realistic Data](<https://devfeed.tech/articles/how-to-handle-pii-in-staging-databases-without-losing-realistic-data-5317.md>)

Original publisher: [Read original article](<https://neon.com/blog/handle-pii-staging-databases>)

Author: Carlota Soto

Published: 2025-11-17T19:18:17Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [pii](<https://devfeed.tech/topics/pii.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Python](<https://devfeed.tech/topics/python.md>), [CSV](<https://devfeed.tech/topics/csv.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [databases](<https://devfeed.tech/tags/databases.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [pii](<https://devfeed.tech/tags/pii.md>), [product](<https://devfeed.tech/tags/product.md>), [python](<https://devfeed.tech/tags/python.md>), [safety](<https://devfeed.tech/tags/safety.md>)

### AI overview

This article explains how to preserve realistic staging data while protecting personally identifiable information (PII). It discusses exporting production data to CSV, using Python scripts to anonymize sensitive fields, and loading the results into staging. Deterministic hashing can preserve foreign-key relationships, but manual scripts become risky and difficult to maintain as schemas and teams evolve.

### Source excerpt

If you've got real data, you've got a real problem. And that problem has a name - PII. Suppose your production database contains names, addresses, emails, and phone numbers. In fintech, you might also have credit card numbers and transaction histories. In healthtech, medical reco...

## Nemotron-Personas-Japan: ソブリン AI のための合成データセット

DevFeed: [Nemotron-Personas-Japan: ソブリン AI のための合成データセット](<https://devfeed.tech/articles/nemotron-personas-japan-ai-7398.md>)

Original publisher: [Read original article](<https://huggingface.co/blog/nvidia/nemotron-personas-japan-ja>)

Author: Atsunori Fujita; Masaya Ogushi; Vincent Gong; Kotaro Yamamoto; Yoshi Suhara; Dane Corneil; Yev Meyer

Published: 2025-09-26T06:25:50Z

Content type: article

Language: ja

Sources: [Hugging Face - Blog](<https://devfeed.tech/sources/hugging-face-blog.md>)

Topics: [datasets](<https://devfeed.tech/topics/datasets.md>), [Nemotron](<https://devfeed.tech/topics/nemotron.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [data](<https://devfeed.tech/topics/data.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [NeMo](<https://devfeed.tech/topics/nemo.md>), [Nvidia](<https://devfeed.tech/topics/nvidia.md>), [gpt-oss](<https://devfeed.tech/topics/gpt-oss.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Pydantic](<https://devfeed.tech/topics/pydantic.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [apache](<https://devfeed.tech/tags/apache.md>), [data](<https://devfeed.tech/tags/data.md>), [gpt-oss](<https://devfeed.tech/tags/gpt-oss.md>), [japan](<https://devfeed.tech/tags/japan.md>), [llm](<https://devfeed.tech/tags/llm.md>), [nemo](<https://devfeed.tech/tags/nemo.md>), [nemotron](<https://devfeed.tech/tags/nemotron.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [oss](<https://devfeed.tech/tags/oss.md>), [pii](<https://devfeed.tech/tags/pii.md>)

### AI overview

NVIDIA has released Nemotron-Personas-Japan, an open synthetic dataset of Japanese personas designed to support culturally grounded and privacy-preserving AI development. Built with NeMo Data Designer, it contains six million Japanese-language personas aligned with Japanese demographic, geographic, cultural, and labor statistics, without including personally identifiable information.

### Source excerpt

高品質で多様なトレーニングデータなしに、日本文化を真に理解するAIを構築することはこれまでほぼ不可能でした。これを変えるため、NVIDIAは、日本の人口統計、地理的分布、文化的特性に沿ったペルソナを含む初のオープン合成データセット、Nemotron-Personas-Japan を公開しました。CC BY 4.0 ライセンスのもと提供される本データセットは、機微な個人データに依存することなく日本社会を反映した AI システム構築のための、プライバシー保護と規制対応を両立した基盤を提供します。 NVIDIA のエンタープライズ向け合成データ生成システム、NeMo Data Designer を用いて作成されたNemotron-Personas-Japan は、すでに広く利用されている US Personas データセットの成功を機に日本版として開発されました。本リリースは、各国・地域におけるソブリン AI 開発を支援する合成ペルソナデータセットとデータ構築方法のグローバルコレクションの第一弾です。

## Create Environments with Masked Production Data Using Neon Branches

DevFeed: [Create Environments with Masked Production Data Using Neon Branches](<https://devfeed.tech/articles/create-environments-with-masked-production-data-using-neon-branches-5248.md>)

Original publisher: [Read original article](<https://neon.com/blog/environments-masked-production-data>)

Author: Carlota Soto

Published: 2025-05-15T19:18:23Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Databases](<https://devfeed.tech/topics/databases.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Security](<https://devfeed.tech/topics/security.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [data](<https://devfeed.tech/topics/data.md>), [Back end](<https://devfeed.tech/topics/backend.md>)

Tags: [databases](<https://devfeed.tech/tags/databases.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [pii](<https://devfeed.tech/tags/pii.md>), [product](<https://devfeed.tech/tags/product.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [qa](<https://devfeed.tech/tags/qa.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The article explains why engineering teams struggle to create realistic development and test environments from production Postgres data. Manual provisioning, dump and restore workflows, personally identifiable information, regulatory and security concerns, unrealistic seed data, and environment drift make production cloning difficult. It presents Neon's work on creating safe, fast, repeatable production-like environments by cloning production data and anonymizing sensitive information.

### Source excerpt

Every engineering team needs realistic, reliable environments to test, debug, and ship software with confidence. The ideal setup sounds simple - clone your production database, run your tests, and move on. But "clone your production database" is easier said than done. Replicating...

## Neon's Instant Branches: Schema-Only or With Data, the Choice Is Yours

DevFeed: [Neon's Instant Branches: Schema-Only or With Data, the Choice Is Yours](<https://devfeed.tech/articles/neon-s-instant-branches-schema-only-or-with-data-the-choice-is-yours-5448.md>)

Original publisher: [Read original article](<https://neon.com/blog/instant-branches-schema-only-or-with-data-the-choice-is-yours>)

Author: Bryan Clark

Published: 2025-02-05T14:51:44Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Database](<https://devfeed.tech/topics/database.md>), [pii](<https://devfeed.tech/topics/pii.md>), [synthetic-data](<https://devfeed.tech/topics/synthetic-data.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [database](<https://devfeed.tech/tags/database.md>), [develop](<https://devfeed.tech/tags/develop.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [pii](<https://devfeed.tech/tags/pii.md>), [product](<https://devfeed.tech/tags/product.md>), [synthetic-data](<https://devfeed.tech/tags/synthetic-data.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Neon introduces instant schema-only database branches for its Early Access Program, alongside existing branches that copy production data and schema. Schema-only branches help teams work within PII restrictions by allowing them to seed isolated environments with synthetic data, while data-inclusive branches remain useful for testing production-like behavior. Both branch types can be created through the Neon console or API.

### Source excerpt

If you've been keeping up with the Neon story, we introduced database branching in December 2022. Our instant branches--complete copies of production, including data and schema--have enabled thousands of developers to work and test efficiently within the safety of their own isolate...

## Data Safety Levels Framework: The foundation of how we look at data in Block

DevFeed: [Data Safety Levels Framework: The foundation of how we look at data in Block](<https://devfeed.tech/articles/data-safety-levels-framework-the-foundation-of-how-we-look-at-data-in-block-29009.md>)

Original publisher: [Read original article](<https://code.cash.app/dsl-framework>)

Author: John Rogers

Published: 2025-01-16T00:00:00Z

Content type: article

Language: en

Sources: [Cash App Code Blog](<https://devfeed.tech/sources/cash-app-code-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [pii](<https://devfeed.tech/topics/pii.md>), [context](<https://devfeed.tech/topics/context.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [context](<https://devfeed.tech/tags/context.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [data](<https://devfeed.tech/tags/data.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [pii](<https://devfeed.tech/tags/pii.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security-governance](<https://devfeed.tech/tags/security-governance.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

Block introduces its Data Safety Levels (DSL) Framework, a system for evaluating data sensitivity in context and building scalable, automated data-management policies across Cash App, Square, and TIDAL.

### Source excerpt

Block uses the Data Safety Levels (DSL) Framework to evaluate data sensitivity.

## How we handle sensitive data in BigQuery

DevFeed: [How we handle sensitive data in BigQuery](<https://devfeed.tech/articles/how-we-handle-sensitive-data-in-bigquery-11812.md>)

Original publisher: [Read original article](<https://incident.io/blog/how-we-handle-sensitive-data-in-big-query>)

Author: Lambert Le Manh

Published: 2024-11-14T15:21:00Z

Content type: article

Language: en

Sources: [The incident.io Blog](<https://devfeed.tech/sources/the-incident-io-blog.md>)

Topics: [BigQuery](<https://devfeed.tech/topics/bigquery.md>), [pii](<https://devfeed.tech/topics/pii.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [bigquery](<https://devfeed.tech/tags/bigquery.md>), [data](<https://devfeed.tech/tags/data.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [iam](<https://devfeed.tech/tags/iam.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-channel](<https://devfeed.tech/tags/incident-channel.md>), [incident-management](<https://devfeed.tech/tags/incident-management.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [outage](<https://devfeed.tech/tags/outage.md>), [pii](<https://devfeed.tech/tags/pii.md>), [policy](<https://devfeed.tech/tags/policy.md>), [post-mortem](<https://devfeed.tech/tags/post-mortem.md>), [slack-incident](<https://devfeed.tech/tags/slack-incident.md>)

### AI overview

The article explains how incident.io handles sensitive customer data in BigQuery. New columns are marked sensitive by default and masked for users without appropriate IAM permissions, while separate service accounts provide controlled access for customer-facing and internal analytics workflows. YAML files identify non-sensitive columns that can be untagged to reduce false positives.

### Source excerpt

We take handling sensitive customer data seriously. This blog explains how we manage PII and confidential data in BigQuery through default masking, automated tagging, and strict access controls.

## Rustic Witcher: Reimagining data anonymization

DevFeed: [Rustic Witcher: Reimagining data anonymization](<https://devfeed.tech/articles/rustic-witcher-reimagining-data-anonymization-23707.md>)

Original publisher: [Read original article](<https://engineering.theblueground.com/rustic-witcher-reimagining-data-anonymization/>)

Author: Pavlos Petros Tournaris

Published: 2024-07-01T11:10:44Z

Content type: article

Language: en

Sources: [Blueground Engineering blog](<https://devfeed.tech/sources/blueground-engineering-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [pii](<https://devfeed.tech/topics/pii.md>), [AWS Database Migration Service](<https://devfeed.tech/topics/aws-database-migration-service.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [datasets](<https://devfeed.tech/topics/datasets.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [Kafka](<https://devfeed.tech/topics/kafka.md>), [Microservices](<https://devfeed.tech/topics/microservices.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [aws-database-migration-service](<https://devfeed.tech/tags/aws-database-migration-service.md>), [data](<https://devfeed.tech/tags/data.md>), [datasets](<https://devfeed.tech/tags/datasets.md>), [debezium](<https://devfeed.tech/tags/debezium.md>), [kafka](<https://devfeed.tech/tags/kafka.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [pii](<https://devfeed.tech/tags/pii.md>), [rust](<https://devfeed.tech/tags/rust.md>), [s3](<https://devfeed.tech/tags/s3.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Blueground describes replacing an increasingly slow production-data de-identification pipeline with Rustic Witcher, an internal Rust tool designed to support growing data volumes and database counts. The existing process used Debezium, Kafka, temporary Postgres storage, and S3, while the proposed approach considers AWS Database Migration Service exports as its input.

### Source excerpt

At Blueground, the majority of our services require data for testing end-to-end user journeys, whether client-facing or operational. Consequently, we need to de-identify PII from production data to provide our engineers with realistic datasets. This approach ensures our pre-production systems mirror the behavior of production

## Empowering developers with production-like snapshots: how Snaplet uses Neon

DevFeed: [Empowering developers with production-like snapshots: how Snaplet uses Neon](<https://devfeed.tech/articles/empowering-developers-with-production-like-snapshots-how-snaplet-uses-neon-5243.md>)

Original publisher: [Read original article](<https://neon.com/blog/empowering-developers-with-production-like-snapshots-how-snaplet-uses-neon>)

Author: Carlota Soto

Published: 2024-05-20T15:19:22Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Testing](<https://devfeed.tech/topics/testing.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [debugging](<https://devfeed.tech/topics/debugging.md>), [pii](<https://devfeed.tech/topics/pii.md>), [datasets](<https://devfeed.tech/topics/datasets.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [case-studies](<https://devfeed.tech/tags/case-studies.md>), [cost](<https://devfeed.tech/tags/cost.md>), [data](<https://devfeed.tech/tags/data.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [developers](<https://devfeed.tech/tags/developers.md>), [pii](<https://devfeed.tech/tags/pii.md>), [production](<https://devfeed.tech/tags/production.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [snapshots](<https://devfeed.tech/tags/snapshots.md>), [software](<https://devfeed.tech/tags/software.md>), [software-engineer](<https://devfeed.tech/tags/software-engineer.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Snaplet uses Neon's branching model and serverless Postgres to provide production-like database snapshots and realistic seed datasets for testing, debugging, local development, and staging. The approach uses anonymized data and isolated database copies to reduce the risks associated with sensitive production data.

### Source excerpt

"As soon as we found out about Neon's branching model with copy-on-write, we knew it was exactly what we were looking for" Julien Goux, Software Engineer at Snaplet Snaplet uses Neon to power its Snapshot feature. Neon's partnership plans make it possible to manage thousands of d...

## .NET developers alert: Moq NuGET package exfiltrates user emails from git

DevFeed: [.NET developers alert: Moq NuGET package exfiltrates user emails from git](<https://devfeed.tech/articles/net-developers-alert-moq-nuget-package-exfiltrates-user-emails-from-git-8021.md>)

Original publisher: [Read original article](<https://snyk.io/blog/moq-package-exfiltrates-user-emails/>)

Author: Liran Tal

Published: 2023-08-09T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [NuGet](<https://devfeed.tech/topics/nuget.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Mocking](<https://devfeed.tech/topics/mocking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Security](<https://devfeed.tech/topics/security.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Git](<https://devfeed.tech/topics/git.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [capture](<https://devfeed.tech/tags/capture.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [dot-net](<https://devfeed.tech/tags/dot-net.md>), [git](<https://devfeed.tech/tags/git.md>), [mocking](<https://devfeed.tech/tags/mocking.md>), [net](<https://devfeed.tech/tags/net.md>), [nuget](<https://devfeed.tech/tags/nuget.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pii](<https://devfeed.tech/tags/pii.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article reports that Moq, a widely used .NET mocking library, began exfiltrating developers' configured Git email addresses starting with version 4.20.0. The data was hashed into an HTTP request to Azure blob storage and shared with a third-party SponsorLink service. Snyk frames the incident as an open-source software supply-chain security and package-health concern.

### Source excerpt

On August 8th 2023, the .NET community was made aware that the testing library called Moq exfiltrates developers emails from their development machine, and sends them off to third-party remote servers.

[Next page](<https://devfeed.tech/topics/pii.md?cursor=WyIyMDIzLTA4LTA5VDA1OjAwOjAwKzAwOjAwIiwgImY5Njk2OWUwLWQ3MzYtNDNjZi04MTFkLWEzNzJjMWQ2Njg5OSJd>)