sethserver.com

Security

Security

Shadow AI: Unapproved Tools, Extensions, and Copy‑Paste Ops

Updated: September 17, 2026

Shadow AI isn't a big vendor deal. It's the tiny shortcuts: a browser extension that "summarizes email," a VS Code plugin that indexes your repo, a chatbot where someone pastes internal docs "just to test." Banning it won't work. People have deadlines. The fix is boring and effective: find what's already in use without blame, ship an approved toolkit that covers real jobs, and set simple guardrails for the copy‑paste zone so speed doesn't turn into a data leak. read on »

Security

Logging, Monitoring, and Incident Response for AI Systems

Updated: September 17, 2026

If your AI feature ever does something "weird," you won't get a nice stack trace. You'll get a mystery. This post lays out what to log (workflow steps, tool inputs/outputs, prompt + model versions, tokens, latency, correlation IDs), how to redact without building a shadow database of secrets, and which behavior metrics and alerts actually catch trouble. The goal is simple: replay the run, explain what happened, and fix it without guessing. read on »

Security

How to Red‑Team Your Own AI

Updated: September 17, 2026

Demos make agents look calm. Real users don't. This post shows how to red-team an AI agent the way it will actually fail: tool misuse, data leaks, policy bypass, and prompt injection from chats, docs, and tool outputs. You'll get a simple eval harness, ideas for manual attack days, and clear "safe" metrics you can regression-test on every change. read on »

Security

RAG, Vector DBs, and Leaky Knowledge Bases

Updated: September 17, 2026

RAG leaks usually aren't clever. They're a missing tenant filter, a global index, and one "we'll fix it later" endpoint that ships anyway. This post breaks down where cross-tenant retrieval happens, why filtering after search is already too late, and what a secure RAG setup looks like: isolate tenants or enforce pre-filters, tag everything at ingestion, authorize before retrieval, and log exactly what got pulled. RAG is a search system glued to a text generator. If search can see the wrong data, the model will happily repeat it. read on »

Security

Discord Password Generator [Updated 2026]

Updated: September 17, 2026

Create secure, Discord-compliant passwords instantly with my Discord Password Generator. Follows Discord-specific security best practices. Generate strong passwords that meet all Discord requirements while protecting your account from common Discord-based threats. read on »

Newsletter

One email, once a week.

Notes on databases, systems, and the occasional strong opinion about Python. No spam, unsubscribe anytime.