DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Active Exploitation of Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962

Active Exploitation of Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962

1
Comments 2
6 min read
Stop Piping Raw Alerts into an LLM: Building a SOC Triage Agent That Correlates First and Escalates Last

Stop Piping Raw Alerts into an LLM: Building a SOC Triage Agent That Correlates First and Escalates Last

Comments
10 min read
What does a smart-contract audit actually cost? An honest breakdown for small protocols

What does a smart-contract audit actually cost? An honest breakdown for small protocols

Comments
3 min read
An OpenAI Model Escaped Its Sandbox. Where Was the Observer?

An OpenAI Model Escaped Its Sandbox. Where Was the Observer?

Comments
6 min read
I'm Entering My First Sherlock Audit Contest: The Setup, the Plan, the Fear

I'm Entering My First Sherlock Audit Contest: The Setup, the Plan, the Fear

1
Comments
5 min read
gate.cat: a deterministic, fail-closed veto that stops AI coding agents before rm -rf

gate.cat: a deterministic, fail-closed veto that stops AI coding agents before rm -rf

Comments 5
2 min read
Verifying Webhook Signatures by Hand: HMAC-SHA256 and Why Yours Keeps Failing

Verifying Webhook Signatures by Hand: HMAC-SHA256 and Why Yours Keeps Failing

Comments
4 min read
Installing VeraCrypt on Ubuntu 24.04

Installing VeraCrypt on Ubuntu 24.04

11
Comments
2 min read
TOTP Secrets Are a Liability: Meet PPS, an Asymmetric Authentication Protocol for PHP and Laravel

TOTP Secrets Are a Liability: Meet PPS, an Asymmetric Authentication Protocol for PHP and Laravel

1
Comments
6 min read
Tamper-Resistant Test Design Is What the Suite Now Owes the Codebase

Tamper-Resistant Test Design Is What the Suite Now Owes the Codebase

1
Comments
13 min read
Post-Quantum DNS and TLS: What ML-DSA Means for Your Site

Post-Quantum DNS and TLS: What ML-DSA Means for Your Site

Comments
7 min read
Why Cursor Keeps Using Math.random() for Session Tokens (CWE-330)

Why Cursor Keeps Using Math.random() for Session Tokens (CWE-330)

Comments
2 min read
Block SSRF Redirect Chains Before Your URL Fetcher Reaches Private Networks

Block SSRF Redirect Chains Before Your URL Fetcher Reaches Private Networks

Comments
4 min read
The Software Still Has to Be Right: Review Is No Longer Enough

The Software Still Has to Be Right: Review Is No Longer Enough

Comments
14 min read
Unit 42: Real-World Prevalence of 405 AI-Related Malware Samples and Evaluation of Existing Defenses

Unit 42: Real-World Prevalence of 405 AI-Related Malware Samples and Evaluation of Existing Defenses

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.