DEV Community

Cybersecurity

Articles related to cybersecurity and much more

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
How ClawMoat Would Have Prevented ClawHavoc

How ClawMoat Would Have Prevented ClawHavoc

Comments
5 min read
CVE-2026-27206: The Zumba Class Dance: RCE via PHP Object Injection in json-serializer

CVE-2026-27206: The Zumba Class Dance: RCE via PHP Object Injection in json-serializer

Comments
2 min read
Anthropic Just Published a Kill Chain for AI Model Theft. Let's Break It Down.

Anthropic Just Published a Kill Chain for AI Model Theft. Let's Break It Down.

Comments 4
7 min read
Lazarus Group Evolves: From Fake token coins to Fake CVEs — New GitHub Phishing Wave

Lazarus Group Evolves: From Fake token coins to Fake CVEs — New GitHub Phishing Wave

17
Comments
5 min read
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer

Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer

Comments 1
1 min read
EDR/XDR Bypass and Detection Evasion Techniques: An Investigation of Advanced Evasion Strategies from a Red Team Perspective

EDR/XDR Bypass and Detection Evasion Techniques: An Investigation of Advanced Evasion Strategies from a Red Team Perspective

7
Comments
40 min read
I Let Users Write HTML Templates - Here Are 6 Security Holes I Had to Patch

I Let Users Write HTML Templates - Here Are 6 Security Holes I Had to Patch

4
Comments
6 min read
Shadow API Risks: The Hidden Cybersecurity Threat Most U.S. Small Businesses Miss

Shadow API Risks: The Hidden Cybersecurity Threat Most U.S. Small Businesses Miss

3
Comments
2 min read
GHSA-6QR9-G2XW-CW92: Dagu: The Friendly Ghost that Runs Your Malware (GHSA-6QR9-G2XW-CW92)

GHSA-6QR9-G2XW-CW92: Dagu: The Friendly Ghost that Runs Your Malware (GHSA-6QR9-G2XW-CW92)

Comments
2 min read
SeeTheSharpFlag — Hack The Box Mobile Challenge Write-up

SeeTheSharpFlag — Hack The Box Mobile Challenge Write-up

Comments
2 min read
I Found a SQL Injection in an AI Agent. It Taught Me That We Broke the First Rule of Database Security.

I Found a SQL Injection in an AI Agent. It Taught Me That We Broke the First Rule of Database Security.

1
Comments
9 min read
GHSA-GV8R-9RW9-9697: The Ghost in the Handshake: Traefik & Go mTLS Bypass in HTTP/3

GHSA-GV8R-9RW9-9697: The Ghost in the Handshake: Traefik & Go mTLS Bypass in HTTP/3

Comments
2 min read
CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK

CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK

Comments
2 min read
The twist: AI is a tool, not the operator

The twist: AI is a tool, not the operator

2
Comments
5 min read
CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the <

CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the <

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.