// GUIDES AND EXPLAINERS, GROUNDED IN DATA

Blogs

Deep dives and explainers on the cybersecurity questions people actually ask. Practical, sourced, and built to answer the question, not sell you something.

//
BlogOCT 4, 2026

What Is an AI Gateway? Security Risks and Controls

What is an AI gateway? How it routes LLM requests, holds your keys and MCP tools, its top security risks (like Bifrost CVE-2026-90898), and how to lock it down.

Nexus Void Research · 8 MIN READ
What Is an AI Gateway? Security Risks and Controls// TRENDING
// 67 ENTRIES
BlogSEP 20, 2026

What Is CWE? Common Weakness Enumeration Explained

What is CWE (Common Weakness Enumeration)? How CWE differs from CVE, how the catalog and CWE Top 25 work, and why weakness types matter for prevention.

Nexus Void Research8 MIN READ
BlogSEP 16, 2026

What Is JWT Authentication? JSON Web Token Security

What is JWT authentication? How JSON Web Tokens work, the top JWT vulnerabilities (alg none, algorithm confusion, CWE-347), and how to secure them.

Nexus Void Research9 MIN READ
BlogSEP 13, 2026

CTO Guide: Securing a Startup Codebase End to End

How to secure a startup codebase end to end: source code, dependencies, secrets, third-party APIs, SBOMs, CI/CD, and a security score for every developer.

Nexus Void Research11 MIN READ
BlogSEP 13, 2026

What Is a Developer Security Score? A Team Guide

What is a developer security score? A guide to measuring security per developer: what it tracks, how to calculate it, and how to use it without it backfiring.

Nexus Void Research8 MIN READ
BlogSEP 13, 2026

How to Find and Fix Hardcoded Secrets in Your Code

How to find hardcoded secrets in code: where keys and tokens hide, how to detect them in pull requests, and how to safely remediate a leaked secret.

Nexus Void Research8 MIN READ
BlogSEP 13, 2026

How to Detect Malicious npm Packages and Slopsquatting

How to detect malicious npm packages: the signs of a poisoned dependency, what slopsquatting is, and how to catch bad packages before they install.

Nexus Void Research8 MIN READ
BlogSEP 13, 2026

SBOM for Startups: Generate and Manage a Bill of Materials

SBOM for startups: what a software bill of materials is, why buyers ask for one, the CycloneDX and SPDX formats, and how to generate and keep one current.

Nexus Void Research8 MIN READ
BlogSEP 13, 2026

How to Secure Third-Party API Integrations

How to secure third-party API integrations like Stripe and Plaid: protecting API keys, verifying webhooks, patching SDKs, and least-privilege tokens.

Nexus Void Research8 MIN READ
BlogSEP 13, 2026

How to Secure Your CI/CD Pipeline (GitHub Actions)

How to secure a CI/CD pipeline in GitHub Actions: least-privilege tokens, SHA-pinned actions, scoped secrets, and a merge gate that blocks vulnerable code.

Nexus Void Research8 MIN READ
BlogSEP 13, 2026

Securing a Node.js + AWS + GitHub Startup Stack

A Node.js startup security checklist for AWS and GitHub teams: npm dependencies, secrets, IAM, GitHub Actions, and a per-developer security score.

Nexus Void Research9 MIN READ
BlogSEP 13, 2026

Securing a Python + AWS/GCP Startup Stack

A Python startup security checklist for AWS and GCP teams: PyPI dependencies, secrets, cloud IAM, CI/CD, and a per-developer security score.

Nexus Void Research9 MIN READ
BlogSEP 13, 2026

Securing an AI-Native Startup: A Whole-Stack Playbook

A security playbook for AI-native startups on Cursor and Claude Code: guard the coding agent, verify AI-suggested dependencies, and gate merges.

Nexus Void Research9 MIN READ
PAGE 01 / 06