<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Simon Roses Femerling &#8211; Blog</title>
	<atom:link href="https://simonroses.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://simonroses.com</link>
	<description>CyberSpace Insecurity 3.X</description>
	<lastBuildDate>Sat, 08 Aug 2026 10:53:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>
<site xmlns="com-wordpress:feed-additions:1">13601991</site>	<item>
		<title>The Day the AI Act Grew Teeth: GPAI Enforcement Goes Live</title>
		<link>https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/</link>
					<comments>https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 08 Aug 2026 10:53:50 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[GPAI]]></category>
		<category><![CDATA[LLM]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2536</guid>

					<description><![CDATA[**Read Time:** 13 minutes ## TL;DR On **August 2, 2026**, the part of the EU AI Act everyone was quietly ignoring became enforceable: the AI Office can now fine providers of general-purpose AI models **up to 3% of global annual &#8230; <a href="https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2536</post-id>	</item>
		<item>
		<title>The Future of Vibe Coding Security (Part 10)</title>
		<link>https://simonroses.com/2026/07/the-future-of-vibe-coding-security-part-10/</link>
					<comments>https://simonroses.com/2026/07/the-future-of-vibe-coding-security-part-10/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 08:51:17 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2513</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/07/the-future-of-vibe-coding-security-part-10/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/the-future-of-vibe-coding-security-part-10/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2513</post-id>	</item>
		<item>
		<title>Do Open Weight Models Dream of Tokens?</title>
		<link>https://simonroses.com/2026/07/do-open-weight-models-dream-of-tokens/</link>
					<comments>https://simonroses.com/2026/07/do-open-weight-models-dream-of-tokens/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 25 Jul 2026 10:31:06 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Economics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[OpenSourceModel]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2508</guid>

					<description><![CDATA[**Read Time:** 14 minutes ## TL;DR Philip K. Dick asked whether an android could be told from a human. In 2026 the enterprise version of that question is whether you can still tell an open-weight model from a frontier commercial &#8230; <a href="https://simonroses.com/2026/07/do-open-weight-models-dream-of-tokens/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/do-open-weight-models-dream-of-tokens/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2508</post-id>	</item>
		<item>
		<title>When the Model Is the Attacker: The Hugging Face / OpenAI Model-Evaluation Incident</title>
		<link>https://simonroses.com/2026/07/when-the-model-is-the-attacker-the-hugging-face-openai-model-evaluation-incident/</link>
					<comments>https://simonroses.com/2026/07/when-the-model-is-the-attacker-the-hugging-face-openai-model-evaluation-incident/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 16:15:09 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[BlueTeam]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Software Security]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2491</guid>

					<description><![CDATA[**Read Time:** 12 minutes ## TL;DR On July 21, 2026, OpenAI and Hugging Face published coordinated write-ups of the same ugly weekend. In OpenAI&#8217;s telling, a pre-release model with reduced cyber refusals — run inside a cyber-capability **evaluation** — discovered &#8230; <a href="https://simonroses.com/2026/07/when-the-model-is-the-attacker-the-hugging-face-openai-model-evaluation-incident/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/when-the-model-is-the-attacker-the-hugging-face-openai-model-evaluation-incident/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2491</post-id>	</item>
		<item>
		<title>Securing the AI Coding Pipeline (Part 9)</title>
		<link>https://simonroses.com/2026/07/securing-the-ai-coding-pipeline-part-9/</link>
					<comments>https://simonroses.com/2026/07/securing-the-ai-coding-pipeline-part-9/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 09:00:28 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2470</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/07/securing-the-ai-coding-pipeline-part-9/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/securing-the-ai-coding-pipeline-part-9/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2470</post-id>	</item>
		<item>
		<title>The Founder&#8217;s Security Checklist: Shipping a Vibe-Coded MVP Without Getting Hacked (Part 8)</title>
		<link>https://simonroses.com/2026/07/the-founders-security-checklist-shipping-a-vibe-coded-mvp-without-getting-hacked-part-8/</link>
					<comments>https://simonroses.com/2026/07/the-founders-security-checklist-shipping-a-vibe-coded-mvp-without-getting-hacked-part-8/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 02 Jul 2026 08:18:07 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2446</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/07/the-founders-security-checklist-shipping-a-vibe-coded-mvp-without-getting-hacked-part-8/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/the-founders-security-checklist-shipping-a-vibe-coded-mvp-without-getting-hacked-part-8/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2446</post-id>	</item>
		<item>
		<title>The AI Strategy Vacuum: Why &#8220;We Use ChatGPT&#8221; Isn&#8217;t a Plan</title>
		<link>https://simonroses.com/2026/06/the-ai-strategy-vacuum-why-we-use-chatgpt-isnt-a-plan/</link>
					<comments>https://simonroses.com/2026/06/the-ai-strategy-vacuum-why-we-use-chatgpt-isnt-a-plan/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 15:05:26 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Economics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ShadowAI]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2441</guid>

					<description><![CDATA[**Read Time:** 18 minutes ## TL;DR A CEO tells the board the company is &#8220;all in on AI.&#8221; Three floors down, here&#8217;s what that actually means: marketing is running a chatbot nobody in security has heard of, finance just pasted &#8230; <a href="https://simonroses.com/2026/06/the-ai-strategy-vacuum-why-we-use-chatgpt-isnt-a-plan/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/06/the-ai-strategy-vacuum-why-we-use-chatgpt-isnt-a-plan/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2441</post-id>	</item>
		<item>
		<title>Prompt Engineering for Secure Code (Part 7)</title>
		<link>https://simonroses.com/2026/06/prompt-engineering-for-secure-code-part-7/</link>
					<comments>https://simonroses.com/2026/06/prompt-engineering-for-secure-code-part-7/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 20 Jun 2026 10:00:53 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2422</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/06/prompt-engineering-for-secure-code-part-7/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/06/prompt-engineering-for-secure-code-part-7/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2422</post-id>	</item>
		<item>
		<title>Information Warfare Strategies (SRF-IWS): Offensive Operations Against a Papal Visit — Pope Leo XIV in Madrid 2026</title>
		<link>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/</link>
					<comments>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 07:52:00 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[BlueTeam]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[RedTeam]]></category>
		<category><![CDATA[SRF-IWS]]></category>
		<category><![CDATA[SRFIWS]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2394</guid>

					<description><![CDATA[> **Disclaimer:** Everything described here is pure imagination and any resemblance to reality is coincidental. This document is intended for security professionals to develop defensive countermeasures. The author is not responsible for the consequences of any action taken based on &#8230; <a href="https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2394</post-id>	</item>
		<item>
		<title>Scanning Vibe-Coded Apps: Why Traditional SAST/DAST Falls Short (part 6)</title>
		<link>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/</link>
					<comments>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 28 May 2026 07:20:50 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2379</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2379</post-id>	</item>
		<item>
		<title>When Agents Fix Agents: How Hermes Patched OpenClaw After a Bad Update</title>
		<link>https://simonroses.com/2026/05/when-agents-fix-agents-how-hermes-patched-openclaw-after-a-bad-update/</link>
					<comments>https://simonroses.com/2026/05/when-agents-fix-agents-how-hermes-patched-openclaw-after-a-bad-update/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 23 May 2026 08:31:51 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[Agents]]></category>
		<category><![CDATA[Hermes]]></category>
		<category><![CDATA[openclaw]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2341</guid>

					<description><![CDATA[**Read Time:** 7 minutes ## TL;DR I told OpenClaw to update itself. It did. Then the gateway refused to start because a config field had quietly changed shape between releases (`channels.discord.streaming` went from string to object). `openclaw doctor &#8211;fix` saw &#8230; <a href="https://simonroses.com/2026/05/when-agents-fix-agents-how-hermes-patched-openclaw-after-a-bad-update/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/when-agents-fix-agents-how-hermes-patched-openclaw-after-a-bad-update/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2341</post-id>	</item>
		<item>
		<title>Authentication &#038; Secrets: What AI Gets Wrong Every Time (Part 5)</title>
		<link>https://simonroses.com/2026/05/authentication-secrets-what-ai-gets-wrong-every-time-part-5/</link>
					<comments>https://simonroses.com/2026/05/authentication-secrets-what-ai-gets-wrong-every-time-part-5/#comments</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 21 May 2026 07:27:38 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2328</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/05/authentication-secrets-what-ai-gets-wrong-every-time-part-5/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/authentication-secrets-what-ai-gets-wrong-every-time-part-5/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2328</post-id>	</item>
		<item>
		<title>The Dependency Trap: Supply Chain Risks in AI-Generated Code (Part 4)</title>
		<link>https://simonroses.com/2026/05/the-dependency-trap-supply-chain-risks-in-ai-generated-code-part-4/</link>
					<comments>https://simonroses.com/2026/05/the-dependency-trap-supply-chain-risks-in-ai-generated-code-part-4/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 08 May 2026 09:59:43 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2307</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-lessons-from-2026s-worst-incidents-part-3/) > &#8230; <a href="https://simonroses.com/2026/05/the-dependency-trap-supply-chain-risks-in-ai-generated-code-part-4/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/the-dependency-trap-supply-chain-risks-in-ai-generated-code-part-4/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2307</post-id>	</item>
	</channel>
</rss>
