<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Fortus Blog — Security for AI-Built Software</title>
    <link>https://fortus.dev/blog/</link>
    <description>Practical security guides, code checks, and manual self-tests for builders shipping with AI.</description>
    <language>en</language>
    <lastBuildDate>Sat, 26 Sep 2026 12:00:00 +0000</lastBuildDate>
    <atom:link href="https://fortus.dev/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>My Users Found My Source in Their Browser: Fixing Exposed Source Maps</title>
      <link>https://fortus.dev/blog/source-maps-exposed.html</link>
      <guid isPermaLink="true">https://fortus.dev/blog/source-maps-exposed.html</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 +0000</pubDate>
      <description>Shipping .map files or unminified bundles leaks your source to anyone with DevTools. Learn the config flags and checks that keep prod builds private.</description>
    </item>
    <item>
      <title>Supabase RLS Was Off and Anyone Could Read Everything</title>
      <link>https://fortus.dev/blog/supabase-rls-off-check.html</link>
      <guid isPermaLink="true">https://fortus.dev/blog/supabase-rls-off-check.html</guid>
      <pubDate>Thu, 24 Sep 2026 12:00:00 +0000</pubDate>
      <description>With Row Level Security off, any logged-in user can read every row. Learn where RLS lives in migrations and how to verify owner-scoped policies.</description>
    </item>
    <item>
      <title>Search Your Own Bundle for sk- Before Someone Else Does</title>
      <link>https://fortus.dev/blog/devtools-api-key-search.html</link>
      <guid isPermaLink="true">https://fortus.dev/blog/devtools-api-key-search.html</guid>
      <pubDate>Tue, 22 Sep 2026 12:00:00 +0000</pubDate>
      <description>Your Stripe or OpenAI key may be sitting in client JavaScript. How to search your own bundle in 60 seconds and move keys server-side.</description>
    </item>
    <item>
      <title>Change the User ID in Your API Request: Finding IDOR Before Users Do</title>
      <link>https://fortus.dev/blog/swap-user-id-idor.html</link>
      <guid isPermaLink="true">https://fortus.dev/blog/swap-user-id-idor.html</guid>
      <pubDate>Sun, 20 Sep 2026 12:00:00 +0000</pubDate>
      <description>Change one ID in your API request and you may see another user's data. Learn why IDOR is the most common vibe-code bug and how to fix it.</description>
    </item>
    <item>
      <title>Paste Your Own URL Into a Scanner Before Launch</title>
      <link>https://fortus.dev/blog/paste-url-60-second-scan.html</link>
      <guid isPermaLink="true">https://fortus.dev/blog/paste-url-60-second-scan.html</guid>
      <pubDate>Fri, 18 Sep 2026 12:00:00 +0000</pubDate>
      <description>Bots probe for missing HTTPS, weak headers, and exposed backups first. Run a 60-second self-review of your own app before attackers — or users — do.</description>
    </item>
  </channel>
</rss>
