DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Claude Code Has Been Embedding Steganographic Markers in Your Prompts — Here’s the Full Story

Claude Code Has Been Embedding Steganographic Markers in Your Prompts — Here’s the Full Story

1
Comments
4 min read
My Self-Hosted AI Assistant Kept Overwriting Its Own API Keys: A Zero-Trust Postmortem

My Self-Hosted AI Assistant Kept Overwriting Its Own API Keys: A Zero-Trust Postmortem

Comments 2
5 min read
Every per-IP control we shipped was bypassable with one header

Every per-IP control we shipped was bypassable with one header

2
Comments
4 min read
Running Untrusted Code Safely: A Field Guide for AI and CI Pipelines

Running Untrusted Code Safely: A Field Guide for AI and CI Pipelines

Comments
6 min read
KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise

KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise

Comments 1
6 min read
When Your AI Coding Tool Reads Your Code, Where Does It Actually Go

When Your AI Coding Tool Reads Your Code, Where Does It Actually Go

1
Comments
4 min read
Surgical SEO: Automating WordPress Metadata without giving AI full access

Surgical SEO: Automating WordPress Metadata without giving AI full access

Comments 1
4 min read
I denied 7 dangerous commands. My agent deleted the files anyway

I denied 7 dangerous commands. My agent deleted the files anyway

1
Comments 1
5 min read
From CORS to RCE: WordPress Bug Bounty Chains

From CORS to RCE: WordPress Bug Bounty Chains

Comments
12 min read
How to vet an MCP server before you install it (I graded 130,000 to find out)

How to vet an MCP server before you install it (I graded 130,000 to find out)

1
Comments
3 min read
How I built a lightweight standalone behavioral anti-stealer to protect my Windows environment

How I built a lightweight standalone behavioral anti-stealer to protect my Windows environment

Comments
2 min read
The Downstream Trap: Why Patching the Entry Point Never Stops the Credential

The Downstream Trap: Why Patching the Entry Point Never Stops the Credential

Comments
2 min read
resk-llm-ts: Open Source TypeScript Security Toolkit for LLM Applications

resk-llm-ts: Open Source TypeScript Security Toolkit for LLM Applications

1
Comments
2 min read
I replaced a 4.8 MB payment library with 200 lines - building a paid API for AI agents with x402

I replaced a 4.8 MB payment library with 200 lines - building a paid API for AI agents with x402

Comments
6 min read
From Optimization to Protection: Adding a Security and Governance Agent to Your Snowflake Multi-Agent Team (Part 3)

From Optimization to Protection: Adding a Security and Governance Agent to Your Snowflake Multi-Agent Team (Part 3)

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.