DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I got tired of juggling 15 browser tabs during engagements, so I built this

I got tired of juggling 15 browser tabs during engagements, so I built this

Comments
3 min read
Politeness vs Enforcement: Why "Set HTTPS_PROXY" Isn't a Security Control

Politeness vs Enforcement: Why "Set HTTPS_PROXY" Isn't a Security Control

1
Comments
6 min read
What Building a SAST Tool Taught Me About AppSec That 13 Years of Software Engineering Didn't

What Building a SAST Tool Taught Me About AppSec That 13 Years of Software Engineering Didn't

Comments
8 min read
The Shadow API Crisis: How Unmonitored Endpoints Break CORS & Auth

The Shadow API Crisis: How Unmonitored Endpoints Break CORS & Auth

Comments 1
3 min read
What Pipelock Inspects, And What Tool Policy Inspects Instead

What Pipelock Inspects, And What Tool Policy Inspects Instead

Comments
6 min read
The Three-UID Containment Pattern for AI Agents on Linux

The Three-UID Containment Pattern for AI Agents on Linux

Comments
6 min read
Block-Reason Headers: Make Your Security Proxy Tell You Why

Block-Reason Headers: Make Your Security Proxy Tell You Why

Comments
6 min read
subPath ConfigMap Mounts Don't Hot-Reload: Silent Drift in Kubernetes

subPath ConfigMap Mounts Don't Hot-Reload: Silent Drift in Kubernetes

Comments
6 min read
Built a Multi-Account Zero-Trust Governance Architecture in AWS using Terraform, AWS Organisations, SCPs, and CloudTrail.

Built a Multi-Account Zero-Trust Governance Architecture in AWS using Terraform, AWS Organisations, SCPs, and CloudTrail.

Comments
1 min read
Part 5: Securing a Homelab with Cloudflare Tunnels and Zero Trust

Part 5: Securing a Homelab with Cloudflare Tunnels and Zero Trust

Comments
6 min read
How to Check if You're Affected by CVE-2026-26268 in Cursor (and What to Do)

How to Check if You're Affected by CVE-2026-26268 in Cursor (and What to Do)

Comments
3 min read
One Receipt, Nine Regulators

One Receipt, Nine Regulators

Comments
2 min read
Why I Stopped Using Random Online JSON Formatters (And Why You Should Too)

Why I Stopped Using Random Online JSON Formatters (And Why You Should Too)

1
Comments
2 min read
AI-Driven Kernel LPE Discovery, ChromaDB Memory Poisoning & JDownloader Supply Chain Attack

AI-Driven Kernel LPE Discovery, ChromaDB Memory Poisoning & JDownloader Supply Chain Attack

Comments
3 min read
Role-based access in a MERN e-commerce app

Role-based access in a MERN e-commerce app

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.