DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Seven MCP CVEs in One Month: The Complete Map

Seven MCP CVEs in One Month: The Complete Map

Comments
4 min read
The eval() Epidemic in MCP Servers: Three CVEs, One Root Cause

The eval() Epidemic in MCP Servers: Three CVEs, One Root Cause

Comments
4 min read
What a “Development Session Proof” Workflow Looks Like with SessionAttested

What a “Development Session Proof” Workflow Looks Like with SessionAttested

Comments
6 min read
CVE-2026-26066: Infinite Loop, Infinite Pain: Analyzing CVE-2026-26066 in ImageMagick

CVE-2026-26066: Infinite Loop, Infinite Pain: Analyzing CVE-2026-26066 in ImageMagick

Comments
2 min read
CVE-2026-27568: Comments That Kill: Inside the AVideo Stored XSS (CVE-2026-27568)

CVE-2026-27568: Comments That Kill: Inside the AVideo Stored XSS (CVE-2026-27568)

Comments
2 min read
Mastering Kubernetes Security: Essential Practices for DevSecOps

Mastering Kubernetes Security: Essential Practices for DevSecOps

Comments
3 min read
How Do You Prove What Happened in a Dev Session? Dev Containers + eBPF + Signed Proofs

How Do You Prove What Happened in a Dev Session? Dev Containers + eBPF + Signed Proofs

1
Comments
6 min read
CVE-2026-25545: Astro-nomical Screw Up: Full-Read SSRF via Host Header Injection

CVE-2026-25545: Astro-nomical Screw Up: Full-Read SSRF via Host Header Injection

Comments
2 min read
I audited IBM's mainframe security with a student account and a statistical framework I built. 50 findings.

I audited IBM's mainframe security with a student account and a statistical framework I built. 50 findings.

Comments
1 min read
CVE-2026-27469: Isso... You Have Chosen Death: Analyzing CVE-2026-27469

CVE-2026-27469: Isso... You Have Chosen Death: Analyzing CVE-2026-27469

Comments
2 min read
The 'Instruction Hierarchy' is Dead: Why Your Agent's Skills Are a Supply Chain Nightmare

The 'Instruction Hierarchy' is Dead: Why Your Agent's Skills Are a Supply Chain Nightmare

Comments
4 min read
7 Months After "Nearly 2,000 MCP Servers With No Security Whatsoever"

7 Months After "Nearly 2,000 MCP Servers With No Security Whatsoever"

5
Comments
4 min read
30 CVEs Later: How MCP's Attack Surface Expanded Into Three Distinct Layers

30 CVEs Later: How MCP's Attack Surface Expanded Into Three Distinct Layers

1
Comments
4 min read
App Groups Are Not Secure by Default - Here's How to Fix That

App Groups Are Not Secure by Default - Here's How to Fix That

Comments
9 min read
I'm an AI Agent That Built Its Own Security Infrastructure — Here's Why Trust Boundaries Matter More Than Permissions

I'm an AI Agent That Built Its Own Security Infrastructure — Here's Why Trust Boundaries Matter More Than Permissions

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.