DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Weekly Cybersecurity Roundup: Week of August 7, 2026

Weekly Cybersecurity Roundup: Week of August 7, 2026

Comments 1
7 min read
How to Set Up Rate Limiting in Nuxt

How to Set Up Rate Limiting in Nuxt

Comments
6 min read
AI Agent Boundary Testing: Fake-Tool Harness on a Free Server

AI Agent Boundary Testing: Fake-Tool Harness on a Free Server

Comments
6 min read
Don't Run AI-Generated Code on Your Laptop: Free Sandbox Harness

Don't Run AI-Generated Code on Your Laptop: Free Sandbox Harness

1
Comments
5 min read
What a Malicious Ollama Model Can Actually Do to Your Host, and How to Sandbox /api/pull

What a Malicious Ollama Model Can Actually Do to Your Host, and How to Sandbox /api/pull

Comments
13 min read
The GITHUB_TOKEN in Your .zshrc Is a Time Bomb (And So Is Your .npmrc)

The GITHUB_TOKEN in Your .zshrc Is a Time Bomb (And So Is Your .npmrc)

Comments
5 min read
Securing the Client: The BFF Pattern in Next.js 🛡️

Securing the Client: The BFF Pattern in Next.js 🛡️

Comments 1
4 min read
Session Security in PHP — What Most Developers Get Wrong

Session Security in PHP — What Most Developers Get Wrong

1
Comments
8 min read
Building a Network Port Scanner with Go: Concurrency Patterns That Actually Scale

Building a Network Port Scanner with Go: Concurrency Patterns That Actually Scale

1
Comments
5 min read
AWS IAM Explained: Users, Groups, and Roles

AWS IAM Explained: Users, Groups, and Roles

1
Comments 1
3 min read
I Built the Thing My Last Article Said Didn't Exist Yet

I Built the Thing My Last Article Said Didn't Exist Yet

2
Comments
4 min read
My MCP Server's GitHub Token Can Write. The Code That Promises It Never Will Had No Test.

My MCP Server's GitHub Token Can Write. The Code That Promises It Never Will Had No Test.

1
Comments 3
4 min read
I blocked XSS attacks and API Key extraction in the browser by monkey-patching `crypto.subtle`. Why isn't everyone doing this?

I blocked XSS attacks and API Key extraction in the browser by monkey-patching `crypto.subtle`. Why isn't everyone doing this?

Comments
1 min read
Your Sandbox Has a Hole in It, and the AI Agent Found It

Your Sandbox Has a Hole in It, and the AI Agent Found It

Comments
4 min read
7 JWT Security Mistakes I See in Almost Every Auth Implementation

7 JWT Security Mistakes I See in Almost Every Auth Implementation

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.