Tag
#security
Every story tagged security, newest first.

MCP Apps put a real interface in the chat, and both ends have to opt in
An MCP server can return an interactive HTML interface that renders inside the conversation, sandboxed in an iframe. The documentation names eight hosts that support it. None of them will show your interface unless your server asks for it too.
Ahmad J · Sep 13, 2026 · 7 min read

OpenAI's cyber model has one price and no way to lower it
GPT-5.6 Cyber is absent from all four of OpenAI's rate tables. It has a single set of rates, no batch discount, and you have to be approved before you can pay them.
Ahmad J · Sep 5, 2026 · 8 min read

Mistral trains on your chats by default. Turning it off takes three separate switches
Mistral's own help centre says consumer Vibe accounts are opted in to model training by default while enterprise accounts are opted out, that the Vibe and API toggles are separate, and that the thumbs up button authorises use of your data on any plan. Here is every switch, and the one that is not a switch.
Ahmad J · Sep 2, 2026 · 6 min read

The Local Illusion: The Real Security Risks of Running a Local LLM
Running an LLM on your own hardware means the math is local, not that your data is safe. Five concrete places it still leaks or gets altered (unauthenticated localhost ports, pickle-based weights, swap files, telemetry, and shared GPU memory) and how to close each one.
Ahmad J · Aug 9, 2026 · 6 min read

The Real Privacy Audit: What Data Your AI Coding Assistant Sends Home
Stop trusting privacy policies. Put your AI coding assistant behind a proxy and watch exactly what your code transmits: what fires on every keystroke, what "local mode" really hides, and how to shut the channel.
Ahmad J · Aug 5, 2026 · 11 min read

