<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Vivecoding — Writing</title><description>Posts on AI-assisted engineering, security, and the Vivecoding methodology by Samuel Cala.</description><link>https://vivecoding.dev/</link><language>en</language><item><title>Vibecoding vs Vivecoding: A Manifesto</title><link>https://vivecoding.dev/writing/vibecoding-vs-vivecoding/</link><guid isPermaLink="true">https://vivecoding.dev/writing/vibecoding-vs-vivecoding/</guid><description>For years I pronounced it wrong. Then I looked at what I actually do — and realized the mistake had a thesis behind it. This is the case for treating AI-assisted engineering as a campaign, not a roll of the dice.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>vivecoding</category><category>ai-engineering</category><category>sdd</category><category>methodology</category><category>manifesto</category></item><item><title>Browser Extensions Are the Quiet SSO Bypass</title><link>https://itauditlabs.com/browser-extensions-are-the-quiet-sso-bypass/</link><guid isPermaLink="true">https://itauditlabs.com/browser-extensions-are-the-quiet-sso-bypass/</guid><description>108 malicious Chrome extensions hit ~20,000 users by capturing OAuth2 tokens, opening backdoor URLs, and stripping security headers — bypassing MFA, EDR, and CSP. Here&apos;s what actually defends against this.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>security</category><category>browser</category><category>sso</category><category>oauth</category><category>zero-trust</category></item></channel></rss>