DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I scanned two popular open-source repos with an AI code scanner. Here's what I found.

I scanned two popular open-source repos with an AI code scanner. Here's what I found.

Comments
1 min read
My Webhooks Were Sending Data Anyone Could Fake. HMAC Signing Fixed That.

My Webhooks Were Sending Data Anyone Could Fake. HMAC Signing Fixed That.

Comments
6 min read
AI Red-Teaming Techniques: A Practical Starting Point for Security Teams

AI Red-Teaming Techniques: A Practical Starting Point for Security Teams

Comments 1
4 min read
Your Okta Is Only As Strong As Your SIM Card

Your Okta Is Only As Strong As Your SIM Card

Comments
3 min read
CSRF Protection That Actually Works in a Next.js 16 + React 19 App

CSRF Protection That Actually Works in a Next.js 16 + React 19 App

Comments
3 min read
Built an API Fraud Detector After Getting Scammed — Here's How It Works

Built an API Fraud Detector After Getting Scammed — Here's How It Works

Comments
2 min read
Racing a Next.js API route: coupon abuse with Prisma and SQLite

Racing a Next.js API route: coupon abuse with Prisma and SQLite

Comments 1
7 min read
I analyzed stripe.com and github.com — their DNS reveals their email provider, hiring tools, and security posture

I analyzed stripe.com and github.com — their DNS reveals their email provider, hiring tools, and security posture

1
Comments
3 min read
Raw AI models are a fundamental security risk.

Raw AI models are a fundamental security risk.

4
Comments
1 min read
Modernising a 6-Year-Old Spring Boot Project Without Breaking Everything

Modernising a 6-Year-Old Spring Boot Project Without Breaking Everything

Comments
8 min read
I Dusted Off a 6-Year-Old Java Project and Ran Snyk Against It — Here's What I Found

I Dusted Off a 6-Year-Old Java Project and Ran Snyk Against It — Here's What I Found

Comments
9 min read
Rethinking Trust Boundaries in Auth and Billing Flows

Rethinking Trust Boundaries in Auth and Billing Flows

Comments 1
6 min read
Armorer Guard: runtime control should start at the tool call

Armorer Guard: runtime control should start at the tool call

Comments
1 min read
Lattice-Based vs. Code-Based Cryptography: What's the Difference?

Lattice-Based vs. Code-Based Cryptography: What's the Difference?

Comments
2 min read
Precision Loss and Rounding Exploits in Financial Smart Contracts

Precision Loss and Rounding Exploits in Financial Smart Contracts

1
Comments
14 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.