DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
12 things to check before you ship your vibe-coded app

12 things to check before you ship your vibe-coded app

Comments 2
5 min read
We called AVE "the CVE for AI agents." A Reddit commenter told us that was wrong. They were right

We called AVE "the CVE for AI agents." A Reddit commenter told us that was wrong. They were right

1
Comments
4 min read
Who holds the key, and why it's the whole game

Who holds the key, and why it's the whole game

1
Comments
6 min read
Stopping WooCommerce Card Testing Bots with Edge Cryptography

Stopping WooCommerce Card Testing Bots with Edge Cryptography

Comments
3 min read
citefid 0.1.0: verificar la fidelidad de citas en wikis OKF con NLI (AUC 0.7029 sobre cĂłdigo)

citefid 0.1.0: verificar la fidelidad de citas en wikis OKF con NLI (AUC 0.7029 sobre cĂłdigo)

11
Comments
5 min read
Why Every CISO Needs an AIBOM in 2026 — And What Most Vendors Miss

Why Every CISO Needs an AIBOM in 2026 — And What Most Vendors Miss

1
Comments
9 min read
Building Fast with Claude Code Is Easy. Securing the App Is the Hard Part

Building Fast with Claude Code Is Easy. Securing the App Is the Hard Part

16
Comments 2
6 min read
LLM Audits and Guardrails Are Not Enough: Why You Must Filter at the Logit Level

LLM Audits and Guardrails Are Not Enough: Why You Must Filter at the Logit Level

Comments
1 min read
Your Supabase notifications table has RLS on. Anyone signed in can still write into someone else's inbox.

Your Supabase notifications table has RLS on. Anyone signed in can still write into someone else's inbox.

Comments 6
4 min read
A payment gateway for MCP servers, and the security bugs I found in my own code first

A payment gateway for MCP servers, and the security bugs I found in my own code first

1
Comments 3
6 min read
Vaultwarden-Plus v1.36.3: Organization Account Recovery — without breaking zero-knowledge

Vaultwarden-Plus v1.36.3: Organization Account Recovery — without breaking zero-knowledge

1
Comments
2 min read
Your CORS proxy is an SSRF engine: how to harden a URL fetcher

Your CORS proxy is an SSRF engine: how to harden a URL fetcher

Comments
3 min read
From Passwords to Token-based Authentication

From Passwords to Token-based Authentication

Comments
7 min read
6 Security Holes We Keep Finding in Vibe-Coded Apps

6 Security Holes We Keep Finding in Vibe-Coded Apps

Comments
4 min read
Why Your SAST Scanner Misses 86% of Real Vulnerabilities

Why Your SAST Scanner Misses 86% of Real Vulnerabilities

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.