DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass

BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass

Comments
2 min read
Resilience and Recovery in Security Architecture: Why They Matter for Future DoD Cyber Professionals

Resilience and Recovery in Security Architecture: Why They Matter for Future DoD Cyber Professionals

Comments
4 min read
OpenAI Responses API `user` Migration: Split Safety from Prompt Caching

OpenAI Responses API `user` Migration: Split Safety from Prompt Caching

5
Comments
4 min read
Securing the Mission: Applying Security Techniques to Computing Resources

Securing the Mission: Applying Security Techniques to Computing Resources

Comments
4 min read
CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files

CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files

Comments
4 min read
The Phishing Site Tried to Talk to My AI. That Became the Evidence.

The Phishing Site Tried to Talk to My AI. That Became the Evidence.

1
Comments
7 min read
Self-Hosted IAM: Roles, Policies, and Instance Profiles Without AWS

Self-Hosted IAM: Roles, Policies, and Instance Profiles Without AWS

Comments
5 min read
Refresh Token Rotation Under the Hood: How Auth0 Catches a Stolen Token Before It's Ever Replayed

Refresh Token Rotation Under the Hood: How Auth0 Catches a Stolen Token Before It's Ever Replayed

Comments
4 min read
Claude Sessions Are Being Stolen by Common Infostealer Malware

Claude Sessions Are Being Stolen by Common Infostealer Malware

Comments
3 min read
Tool Poisoning Isn't Code, It's Text: How MCP Tool Descriptions Smuggle Prompt Injection

Tool Poisoning Isn't Code, It's Text: How MCP Tool Descriptions Smuggle Prompt Injection

Comments
4 min read
The Wildcard Scope Problem: Why MCP Configs Default to admin:* Instead of Least Privilege

The Wildcard Scope Problem: Why MCP Configs Default to admin:* Instead of Least Privilege

Comments
3 min read
A GitHub token is not an agent permission model

A GitHub token is not an agent permission model

Comments
4 min read
Superior: Crypto and Credential Theft via Browser Extension Acquisition and Malicious Updates

Superior: Crypto and Credential Theft via Browser Extension Acquisition and Malicious Updates

Comments
8 min read
WebMCP: Give Browser Agents Tools Instead of Buttons

WebMCP: Give Browser Agents Tools Instead of Buttons

Comments
4 min read
Shift Left: Why Security Mindset is a Non-Negotiable Developer Skill

Shift Left: Why Security Mindset is a Non-Negotiable Developer Skill

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.