Rails Security in Times of AI-Driven Scanners
AI-driven scanners now probe small Rails apps for credentials and known exploits. How I use Rack::Attack, fail2ban, Cloudflare, and AI audits to fight back.
I'm Mario Alberto, a software engineer and entrepreneur based in Colima, México. I'm the creator of Rails MCP Server and former CTO/co-founder of Aoorora, where I architected a core banking platform in Ruby on Rails that enabled lending startups to build on modern, secure infrastructure. I spend my time at the intersection of Ruby on Rails and AI—building tools that help developers work smarter. When I'm not writing code, I'm documenting territory, popular culture, and memory through photography.
AI-driven scanners now probe small Rails apps for credentials and known exploits. How I use Rack::Attack, fail2ban, Cloudflare, and AI audits to fight back.
A pause between parts 7 and 8: four places where running nexo_mail against a real inbox forced the design past what the earlier posts described.
Why the merge, dedupe and narration of three email extractions lives in a Nexo skill rather than in Ruby, and the seam for fixing model arithmetic.