DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Security Monday #3: Two Security Issues Found in ClickMigrate

Security Monday #3: Two Security Issues Found in ClickMigrate

Comments
3 min read
Next.js Server Actions Are Public Endpoints: How I Lock Them Down

Next.js Server Actions Are Public Endpoints: How I Lock Them Down

1
Comments
3 min read
Building a tamper-evident audit log in NestJS with hash chains

Building a tamper-evident audit log in NestJS with hash chains

Comments 2
11 min read
Your JWT expiry check is off by 1000x — the NumericDate gotcha

Your JWT expiry check is off by 1000x — the NumericDate gotcha

1
Comments 1
3 min read
Preparing Enterprise Systems for the Post-Quantum Encryption Shift

Preparing Enterprise Systems for the Post-Quantum Encryption Shift

Comments
2 min read
I Built a Free Shadow API Scanner and Found 269 Forgotten Routes in Ghost CMS

I Built a Free Shadow API Scanner and Found 269 Forgotten Routes in Ghost CMS

Comments 1
5 min read
Stop Logging OTP Secrets in Auth Events

Stop Logging OTP Secrets in Auth Events

1
Comments
4 min read
The handshake is the easy part. Agent payments still haven't named the custody split.

The handshake is the easy part. Agent payments still haven't named the custody split.

Comments
2 min read
WooCommerce failed orders — what a spike, a stall and a silence each mean

WooCommerce failed orders — what a spike, a stall and a silence each mean

Comments
7 min read
MCP Observatory: Scan, Test, and Secure MCP Servers Before Agents Depend on Them

MCP Observatory: Scan, Test, and Secure MCP Servers Before Agents Depend on Them

Comments
1 min read
Malicious 'jscrambler' NPM Package Versions Deploy Cross-Platform Infostealer

Malicious 'jscrambler' NPM Package Versions Deploy Cross-Platform Infostealer

Comments
4 min read
An LLM agent just ran a full ransomware attack. No human operator.

An LLM agent just ran a full ransomware attack. No human operator.

Comments
2 min read
Read a JWT without guessing what's inside

Read a JWT without guessing what's inside

Comments
2 min read
qchem-leak-screen v0.1.0: sanity-check físico de propiedades cuánticas predichas por IA en CPU

qchem-leak-screen v0.1.0: sanity-check físico de propiedades cuánticas predichas por IA en CPU

1
Comments
3 min read
ATC is now real: Ed25519-signed agent trust cards with working verify + revoke

ATC is now real: Ed25519-signed agent trust cards with working verify + revoke

1
Comments 2
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.