DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
How we built Afina and why WebRTC + QUIC actually matter

How we built Afina and why WebRTC + QUIC actually matter

Comments
2 min read
The "Kernel" release of the Agent Control Plane is finally here.

The "Kernel" release of the Agent Control Plane is finally here.

Comments
3 min read
GHSA-38CW-85XC-XR9X: Identity Crisis: Dumping Veramo's Digital Wallets via SQL Injection

GHSA-38CW-85XC-XR9X: Identity Crisis: Dumping Veramo's Digital Wallets via SQL Injection

Comments
2 min read
CVE-2026-23735: Singleton Roulette: Racing for Context in GraphQL Modules

CVE-2026-23735: Singleton Roulette: Racing for Context in GraphQL Modules

Comments
2 min read
Why your JSON formatter shouldn't have a backend

Why your JSON formatter shouldn't have a backend

2
Comments 4
3 min read
Your Java Regex Can Be Weaponized (And How To Stop It)

Your Java Regex Can Be Weaponized (And How To Stop It)

1
Comments
3 min read
Limiting GraphQL Query Depth the Right Way

Limiting GraphQL Query Depth the Right Way

Comments
3 min read
Your Java Regex Can Be Weaponized (And How To Stop It)

Your Java Regex Can Be Weaponized (And How To Stop It)

Comments
3 min read
Stop Zipping Folders: How I Built a Zero-Trust Tunnel to Share Files Instantly (in Go)

Stop Zipping Folders: How I Built a Zero-Trust Tunnel to Share Files Instantly (in Go)

Comments
3 min read
GHSA-GW32-9RMW-QWWW: Svelte SSR XSS: The Textarea Trap

GHSA-GW32-9RMW-QWWW: Svelte SSR XSS: The Textarea Trap

Comments
2 min read
GHSA-5882-5RX9-XGXP: Crawl4AI RCE: Hook, Line, and Sinker into Your Docker Container

GHSA-5882-5RX9-XGXP: Crawl4AI RCE: Hook, Line, and Sinker into Your Docker Container

Comments
2 min read
Physical Proof of Proximity (PoPI): Making Sybil Attacks Physically Expensive

Physical Proof of Proximity (PoPI): Making Sybil Attacks Physically Expensive

1
Comments
3 min read
Sharing my hands-on Enterprise Cloud Platform project

Sharing my hands-on Enterprise Cloud Platform project

Comments
2 min read
Why Sovereignty fails when it isn’t measurable and what AWS tries to fix with ESC-SRF

Why Sovereignty fails when it isn’t measurable and what AWS tries to fix with ESC-SRF

Comments
12 min read
How to create OTP flow system on Node.js (step-by- step)

How to create OTP flow system on Node.js (step-by- step)

1
Comments
3 min read
CVE-2025-8217: Amazon Q's Self-Sabotage: The Backdoor That Couldn't Code

CVE-2025-8217: Amazon Q's Self-Sabotage: The Backdoor That Couldn't Code

Comments
2 min read
CVE-2026-23745: Tar-pit of Doom: Escaping the Root in node-tar

CVE-2026-23745: Tar-pit of Doom: Escaping the Root in node-tar

Comments 1
2 min read
CVE-2026-23535: Trust Issues: Arbitrary File Write in Weblate CLI (CVE-2026-23535)

CVE-2026-23535: Trust Issues: Arbitrary File Write in Weblate CLI (CVE-2026-23535)

Comments
2 min read
Security news weekly round-up - 16th January 2026

Security news weekly round-up - 16th January 2026

Comments
3 min read
How to Find Your Real Origin IP Behind Cloudflare, Safely (and How to Fix Leaks)

How to Find Your Real Origin IP Behind Cloudflare, Safely (and How to Fix Leaks)

Comments
5 min read
SSH Hardening on Linux: A Practical Step-by-Step Guide

SSH Hardening on Linux: A Practical Step-by-Step Guide

1
Comments
3 min read
5 Security Chores You Should Offload to Cloud Agents (Before They Burn You Out)

5 Security Chores You Should Offload to Cloud Agents (Before They Burn You Out)

1
Comments
4 min read
Building Privacy-First PDF Tools That Run Entirely in the Browser

Building Privacy-First PDF Tools That Run Entirely in the Browser

Comments
1 min read
Secure file upload validation in .NET: A layered approach

Secure file upload validation in .NET: A layered approach

Comments
8 min read
CVE-2026-23527: Case Sensitivity Kills: HTTP Request Smuggling in H3

CVE-2026-23527: Case Sensitivity Kills: HTTP Request Smuggling in H3

Comments
2 min read
loading...