DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Blocking `<script>` Won't Stop innerHTML XSS. `setHTML()` Will.

Blocking `<script>` Won't Stop innerHTML XSS. `setHTML()` Will.

8
Comments
7 min read
Vaults, Brokers, and Sandboxes: What Each One Stops, and What None of Them See

Vaults, Brokers, and Sandboxes: What Each One Stops, and What None of Them See

3
Comments 7
5 min read
Customer Domains and DNS Records: Signed URLs for Secure Asset Delivery

Customer Domains and DNS Records: Signed URLs for Secure Asset Delivery

Comments 1
5 min read
Building a Privacy-First Market Layer on Zcash: What ZECpad Is Testing Before Launch

Building a Privacy-First Market Layer on Zcash: What ZECpad Is Testing Before Launch

Comments
2 min read
Three MCP attacks, refused, and you can run it yourself

Three MCP attacks, refused, and you can run it yourself

Comments 2
3 min read
TruffleHog vs Gitleaks vs GitHub Secret Scanning: Why Most CI Scanners Fail (2026)

TruffleHog vs Gitleaks vs GitHub Secret Scanning: Why Most CI Scanners Fail (2026)

Comments
7 min read
Daily Dose of DevOps — Secrets management: for cloud-native infrastructure

Daily Dose of DevOps — Secrets management: for cloud-native infrastructure

1
Comments
2 min read
Why XopProtector Is the Best Android App Protection Tool I’ve Used

Why XopProtector Is the Best Android App Protection Tool I’ve Used

Comments
5 min read
How to Remove GPS Metadata from Photos and Verify the Result

How to Remove GPS Metadata from Photos and Verify the Result

Comments
3 min read
Understanding Vulnerabilities Through Ethical Exploitation: A Foundation for Stronger Application Security

Understanding Vulnerabilities Through Ethical Exploitation: A Foundation for Stronger Application Security

Comments
5 min read
The Chat Panel Is Not the Record

The Chat Panel Is Not the Record

Comments
8 min read
I Built a Tool That Verifies What AI Agents Actually Did

I Built a Tool That Verifies What AI Agents Actually Did

Comments 1
1 min read
TypeScript SDK for autonomous Solidity security auditing — 7 breach scenarios, LangChain.js + Vercel AI SDK integration

TypeScript SDK for autonomous Solidity security auditing — 7 breach scenarios, LangChain.js + Vercel AI SDK integration

Comments
3 min read
Custom ID-JAG on PingFederate, Part 1: Can PingFederate 12.3.3 Issue an ID-JAG?

Custom ID-JAG on PingFederate, Part 1: Can PingFederate 12.3.3 Issue an ID-JAG?

Comments
4 min read
Custom ID-JAG on PingFederate, Part 3: Managing the Integration with Terraform

Custom ID-JAG on PingFederate, Part 3: Managing the Integration with Terraform

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.