DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
THE DARK SIDE OF DNS: WEAPONIZING RECURSIVE RESOLVERS FOR STEALTH DATA EXFILTRATION

THE DARK SIDE OF DNS: WEAPONIZING RECURSIVE RESOLVERS FOR STEALTH DATA EXFILTRATION

1
Comments
8 min read
Wall-Clock Budgets for Local Agents: Sleep, Heat, and Public Spillover

Wall-Clock Budgets for Local Agents: Sleep, Heat, and Public Spillover

Comments
7 min read
Harden & Lockdown RKE2 Cluster with a 4-Layer DevSecOps Stack

Harden & Lockdown RKE2 Cluster with a 4-Layer DevSecOps Stack

Comments 1
20 min read
Build a Lightweight Web Security Scanner with Next.js: Meet WafyShield 🛡️

Build a Lightweight Web Security Scanner with Next.js: Meet WafyShield 🛡️

Comments
2 min read
Same curl, two verdicts: taint tracking for coding agents

Same curl, two verdicts: taint tracking for coding agents

Comments 1
2 min read
Giving an AI Agent a Real Sandbox: Filesystem and Network Jail, in Java

Giving an AI Agent a Real Sandbox: Filesystem and Network Jail, in Java

Comments 1
6 min read
What is SSRF? How Can a Server Be Tricked Into Attacking Its Own Network?

What is SSRF? How Can a Server Be Tricked Into Attacking Its Own Network?

1
Comments
5 min read
How Node Diversity Keeps a Bridge Censorship-Resistant

How Node Diversity Keeps a Bridge Censorship-Resistant

Comments
3 min read
Spatie Permission vs Bouncer: One Question Decides Which One You Need

Spatie Permission vs Bouncer: One Question Decides Which One You Need

1
Comments
7 min read
CTF Defcon 2019 — CaptureTheCoin Write-up — Linkable payment 300

CTF Defcon 2019 — CaptureTheCoin Write-up — Linkable payment 300

Comments
5 min read
Audit Agent File Reads Before a Remote Model Sees Your kubeconfig

Audit Agent File Reads Before a Remote Model Sees Your kubeconfig

Comments
7 min read
Passkeys for Non-Technical Users

Passkeys for Non-Technical Users

Comments
3 min read
Patch Tuesday September 2026: 2 Zero-Days, 119 Critical Fixes Among 1186 CVEs

Patch Tuesday September 2026: 2 Zero-Days, 119 Critical Fixes Among 1186 CVEs

Comments
3 min read
SSRF in PyTorch: How a Missing URL Validation in Dataset Loading Could Leak Cloud Credentials

SSRF in PyTorch: How a Missing URL Validation in Dataset Loading Could Leak Cloud Credentials

Comments
2 min read
The Auth Template That Trusted Its Caller: AccessKeyID Injection in EKS

The Auth Template That Trusted Its Caller: AccessKeyID Injection in EKS

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.