DEV Community

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub

The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub

Comments
6 min read
Claude Fable 5 Was Jailbroken in 48 Hours. Here's What Actually Stopped Nothing.

Claude Fable 5 Was Jailbroken in 48 Hours. Here's What Actually Stopped Nothing.

1
Comments
5 min read
AI Email Agents Are Phishable: How OpenClaw Spilled User Data to Social Engineering Attacks

AI Email Agents Are Phishable: How OpenClaw Spilled User Data to Social Engineering Attacks

2
Comments
4 min read
The Invisible Breach: Why Modern Web Frameworks Aren't Immune to LFI

The Invisible Breach: Why Modern Web Frameworks Aren't Immune to LFI

Comments
8 min read
OpenAI Built a Lockdown Mode Because Tool-Based Data Exfiltration Is Real — Here's What Catches It Earlier

OpenAI Built a Lockdown Mode Because Tool-Based Data Exfiltration Is Real — Here's What Catches It Earlier

1
Comments
5 min read
Python’s Private Variables Aren't Private: An AppSec Reality Check

Python’s Private Variables Aren't Private: An AppSec Reality Check

Comments
2 min read
Notification Hijacking: How WhatsApp and Slack Content Could Weaponize Google Gemini

Notification Hijacking: How WhatsApp and Slack Content Could Weaponize Google Gemini

1
Comments
5 min read
Hidden in Plain Sight: How Notification Prompt Injection Can Hijack Your AI Assistant

Hidden in Plain Sight: How Notification Prompt Injection Can Hijack Your AI Assistant

1
Comments
4 min read
How Meta's AI Support Bot Got Tricked Into Hijacking Instagram Accounts

How Meta's AI Support Bot Got Tricked Into Hijacking Instagram Accounts

1
Comments
5 min read
When Your Background AI Agent Becomes a C2 Server

When Your Background AI Agent Becomes a C2 Server

2
Comments
4 min read
Dangerous MCP OAuth Shortcuts are Ruining Security

Dangerous MCP OAuth Shortcuts are Ruining Security

1
Comments
1 min read
GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

Comments
8 min read
The Business Context Problem: Why Vulnerability Severity Scores Lie

The Business Context Problem: Why Vulnerability Severity Scores Lie

Comments
4 min read
RAMPART Tests Your AI Agents in Dev. What Catches Malicious Tool Calls in Production?

RAMPART Tests Your AI Agents in Dev. What Catches Malicious Tool Calls in Production?

2
Comments
5 min read
The Ghost Platforms That Broke Our Payment Rails and How We Unchained Ourselves

The Ghost Platforms That Broke Our Payment Rails and How We Unchained Ourselves

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.