DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Giving an AI Agent a Real Sandbox: Filesystem and Network Jail, in Java

Giving an AI Agent a Real Sandbox: Filesystem and Network Jail, in Java

Comments 1
6 min read
Same curl, two verdicts: taint tracking for coding agents

Same curl, two verdicts: taint tracking for coding agents

Comments 1
2 min read
What is SSRF? How Can a Server Be Tricked Into Attacking Its Own Network?

What is SSRF? How Can a Server Be Tricked Into Attacking Its Own Network?

1
Comments
5 min read
How Node Diversity Keeps a Bridge Censorship-Resistant

How Node Diversity Keeps a Bridge Censorship-Resistant

Comments
3 min read
CTF Defcon 2019 — CaptureTheCoin Write-up — Linkable payment 300

CTF Defcon 2019 — CaptureTheCoin Write-up — Linkable payment 300

Comments
5 min read
Spatie Permission vs Bouncer: One Question Decides Which One You Need

Spatie Permission vs Bouncer: One Question Decides Which One You Need

1
Comments
7 min read
Audit Agent File Reads Before a Remote Model Sees Your kubeconfig

Audit Agent File Reads Before a Remote Model Sees Your kubeconfig

Comments
7 min read
Passkeys for Non-Technical Users

Passkeys for Non-Technical Users

Comments
3 min read
Patch Tuesday September 2026: 2 Zero-Days, 119 Critical Fixes Among 1186 CVEs

Patch Tuesday September 2026: 2 Zero-Days, 119 Critical Fixes Among 1186 CVEs

Comments
3 min read
SSRF in PyTorch: How a Missing URL Validation in Dataset Loading Could Leak Cloud Credentials

SSRF in PyTorch: How a Missing URL Validation in Dataset Loading Could Leak Cloud Credentials

Comments
2 min read
The Auth Template That Trusted Its Caller: AccessKeyID Injection in EKS

The Auth Template That Trusted Its Caller: AccessKeyID Injection in EKS

Comments
6 min read
Password reset doesn't log the attacker out. Test yours in 10 minutes.

Password reset doesn't log the attacker out. Test yours in 10 minutes.

Comments
6 min read
Sign it without leaving the page

Sign it without leaving the page

1
Comments
5 min read
Por Que uma Transação com Chip é Mais Segura

Por Que uma Transação com Chip é Mais Segura

Comments
3 min read
Claude Code Token Compromise & Hook Hijacking: Auditing CVE-2026-21852

Claude Code Token Compromise & Hook Hijacking: Auditing CVE-2026-21852

Comments 1
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.