DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CORS Explained: Why Your Browser Blocks Your API

CORS Explained: Why Your Browser Blocks Your API

Comments
3 min read
The Guard That Counts the Wrong Thing

The Guard That Counts the Wrong Thing

Comments 1
4 min read
The Permanent Halt That Lasts Until the Next Restart

The Permanent Halt That Lasts Until the Next Restart

Comments 1
4 min read
Boston Cancelled Its License Plate Cameras. The Cameras Didn't Leave.

Boston Cancelled Its License Plate Cameras. The Cameras Didn't Leave.

Comments
3 min read
The VSIX Packaging Trap: How I Eliminated Embedded Client Secrets from a VS Code Extension

The VSIX Packaging Trap: How I Eliminated Embedded Client Secrets from a VS Code Extension

Comments
7 min read
Your SVG Has No Scripts. Is It Safe to Process?

Your SVG Has No Scripts. Is It Safe to Process?

Comments
3 min read
A crawler name in your logs is a claim: 38% of requests naming a known bot from one Google Cloud network asked for .env files

A crawler name in your logs is a claim: 38% of requests naming a known bot from one Google Cloud network asked for .env files

Comments 1
4 min read
Ransomware Detection for Windows and Linux using ETW and eBPF

Ransomware Detection for Windows and Linux using ETW and eBPF

Comments 1
2 min read
Thirty-Four Out of Thirty-Four. Then Zero Out of Ten.

Thirty-Four Out of Thirty-Four. Then Zero Out of Ten.

Comments
6 min read
WebSocket subscribe is still authorization

WebSocket subscribe is still authorization

Comments 1
1 min read
Marketplace API Key Identity and Scope — Credential Lifetime Management Explained

Marketplace API Key Identity and Scope — Credential Lifetime Management Explained

Comments
6 min read
Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query

Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query

1
Comments
5 min read
SolarWinds Observability Self-Hosted: Two Pre-Authentication RCE Vulnerabilities Fixed with Different Configuration Requirements

SolarWinds Observability Self-Hosted: Two Pre-Authentication RCE Vulnerabilities Fixed with Different Configuration Requirements

1
Comments
6 min read
OAuth client_credentials in Spring Boot for Prometheus Scrapes

OAuth client_credentials in Spring Boot for Prometheus Scrapes

Comments
10 min read
CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

1
Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.