DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
How many npm packages actually run code when you `npm install`? I measured a sample.

How many npm packages actually run code when you `npm install`? I measured a sample.

1
Comments 5
4 min read
SynkLoader Deploying Multi-Stage Modules via Teams Phishing

SynkLoader Deploying Multi-Stage Modules via Teams Phishing

Comments
5 min read
I almost reported a critical bug that didn't exist. One constant saved me.

I almost reported a critical bug that didn't exist. One constant saved me.

Comments
4 min read
JWT auth without the confusion

JWT auth without the confusion

Comments 2
3 min read
UFW says the port is closed. Docker published it to your whole network anyway.

UFW says the port is closed. Docker published it to your whole network anyway.

Comments
5 min read
JavaScript Sandbox Escape via Type Confusion in isolated-vm

JavaScript Sandbox Escape via Type Confusion in isolated-vm

Comments
5 min read
An AI agent exported a patient record. Your logs can't say who told it to.

An AI agent exported a patient record. Your logs can't say who told it to.

Comments 2
6 min read
My app's anti-theft feature locked every user out

My app's anti-theft feature locked every user out

1
Comments 1
4 min read
My Router Was a Buffet for Bots. So I Built It a Bouncer.

My Router Was a Buffet for Bots. So I Built It a Bouncer.

4
Comments
7 min read
Unguarded, Sonnet 5 read another customer's order 100/100 times. Guarded: zero.

Unguarded, Sonnet 5 read another customer's order 100/100 times. Guarded: zero.

Comments 9
4 min read
I scanned GitLab's source code and found 2,449 undocumented API routes

I scanned GitLab's source code and found 2,449 undocumented API routes

Comments
4 min read
0.2.0: I shipped the coverage my own page had already promised

0.2.0: I shipped the coverage my own page had already promised

Comments
7 min read
OpenAI ships GPT-Red to automate prompt-injection testing against AI agents

OpenAI ships GPT-Red to automate prompt-injection testing against AI agents

Comments
2 min read
Hardcoded Secrets: Why AI Code Fails Your First SOC 2 Audit

Hardcoded Secrets: Why AI Code Fails Your First SOC 2 Audit

Comments 1
3 min read
How to Scan Your Codebase for Quantum-Vulnerable Cryptography (Free Open Source Tool)

How to Scan Your Codebase for Quantum-Vulnerable Cryptography (Free Open Source Tool)

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.