DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Bulletproof React: Strict Content Security Policies in Next.js 🛡️

Bulletproof React: Strict Content Security Policies in Next.js 🛡️

1
Comments
3 min read
Ollama Out-of-Bounds Read, Docker UFW Bypass, & EagleSpy RAT Analysis

Ollama Out-of-Bounds Read, Docker UFW Bypass, & EagleSpy RAT Analysis

Comments
4 min read
QR Code Security Best Practices for Platforms

QR Code Security Best Practices for Platforms

Comments
11 min read
Deep inside the COM: Reading Windows ROT Without Asking Permission. Detective story

Deep inside the COM: Reading Windows ROT Without Asking Permission. Detective story

Comments
4 min read
Pipelock Agent Egress Control: the missing CI primitive for AI agents

Pipelock Agent Egress Control: the missing CI primitive for AI agents

Comments
3 min read
LangChain ChromaDB Metadata Priority Injection — RAG Poisoning Vulnerability

LangChain ChromaDB Metadata Priority Injection — RAG Poisoning Vulnerability

Comments
1 min read
Why I stopped hardcoding AI API keys in my frontend

Why I stopped hardcoding AI API keys in my frontend

2
Comments
4 min read
Why I Built an ML-Powered Secrets Detector Instead of Just Using Regex

Why I Built an ML-Powered Secrets Detector Instead of Just Using Regex

Comments
8 min read
How to Build a Secure Audit Trail in Your Web App (No Third-Party Tools)

How to Build a Secure Audit Trail in Your Web App (No Third-Party Tools)

Comments
6 min read
I Built My Own Config Format for Node.js That Separates Server and Client Secrets

I Built My Own Config Format for Node.js That Separates Server and Client Secrets

1
Comments 2
5 min read
Google's Dev Signal is brilliant. It's also a security nightmare waiting to happen.

Google's Dev Signal is brilliant. It's also a security nightmare waiting to happen.

Comments 2
3 min read
I built 14 VS Code extensions to fix the workflows developers quietly suffer through

I built 14 VS Code extensions to fix the workflows developers quietly suffer through

Comments
2 min read
Three prompt injection stories from this week that your guardrail probably missed

Three prompt injection stories from this week that your guardrail probably missed

Comments 2
6 min read
Why the Pentagon blocks Fable 5, and how I built a <1ms guard for local agents

Why the Pentagon blocks Fable 5, and how I built a <1ms guard for local agents

Comments 1
3 min read
"Secure Financial Workflows: Key Lessons from the Trenches"

"Secure Financial Workflows: Key Lessons from the Trenches"

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.