DEV Community

#appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
How to Reduce Time to Revoke for Exposed Credentials

How to Reduce Time to Revoke for Exposed Credentials

5
Comments 1
8 min read
Why SAST and DAST Aren't Enough for Secrets Security

Why SAST and DAST Aren't Enough for Secrets Security

Comments
10 min read
We Built a Standardized File Format for Prompt Injection and Called It AGENTS.md

We Built a Standardized File Format for Prompt Injection and Called It AGENTS.md

1
Comments
3 min read
The LLM Isn't Your Attacker. Your eval() Statement Is.

The LLM Isn't Your Attacker. Your eval() Statement Is.

6
Comments 2
4 min read
Junior AppSec Engineer Overwhelmed by Massive Code Reviews: Strategies for Efficiency and Confidence

Junior AppSec Engineer Overwhelmed by Massive Code Reviews: Strategies for Efficiency and Confidence

Comments
11 min read
How to Measure Time to Revoke for Exposed Credentials

How to Measure Time to Revoke for Exposed Credentials

Comments
5 min read
Manually Breaking Authentication — A Full Walkthrough (CWE-307, CWE-330, CWE-640)

Manually Breaking Authentication — A Full Walkthrough (CWE-307, CWE-330, CWE-640)

Comments
3 min read
The Scanner Came Back Clean. The Discount Code Still Worked 40 Times.

The Scanner Came Back Clean. The Discount Code Still Worked 40 Times.

Comments
3 min read
Zero Permissions on Secrets Manager. Full Access to Your Secrets.

Zero Permissions on Secrets Manager. Full Access to Your Secrets.

2
Comments
9 min read
OpenAI's New Security Controls Are an Admission, Not an Innovation

OpenAI's New Security Controls Are an Admission, Not an Innovation

2
Comments
3 min read
An AI Agent Recommended a Malware Package. A Human Caught It. Next Time You Might Not Be So Lucky

An AI Agent Recommended a Malware Package. A Human Caught It. Next Time You Might Not Be So Lucky

1
Comments
6 min read
Vulnerability advisories grew 2.3x-6.6x in 5 years; open-source tool count stayed flat

Vulnerability advisories grew 2.3x-6.6x in 5 years; open-source tool count stayed flat

Comments
4 min read
CoSnitch Is a Reminder That Your Chatbot Will Tell on You If You Ask Nicely Enough

CoSnitch Is a Reminder That Your Chatbot Will Tell on You If You Ask Nicely Enough

Comments
3 min read
MCP Servers Are Just the Latest Place We Forgot to Lock the Door

MCP Servers Are Just the Latest Place We Forgot to Lock the Door

1
Comments
3 min read
OAuth Tokens Were Always the Weak Link. AI Agents Just Made It Worse

OAuth Tokens Were Always the Weak Link. AI Agents Just Made It Worse

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.