DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
API key design: entropy math, prefixes, and why sk_live_ is genius

API key design: entropy math, prefixes, and why sk_live_ is genius

Comments
2 min read
I built a tool that refuses to let AI security reviewers agree with each other

I built a tool that refuses to let AI security reviewers agree with each other

Comments
2 min read
WordPress Website Security: A Practical Checklist for Small Businesses

WordPress Website Security: A Practical Checklist for Small Businesses

Comments
11 min read
Finding Exposed Services (and Vulnerabilities) with Programmatic Network Searches

Finding Exposed Services (and Vulnerabilities) with Programmatic Network Searches

Comments
4 min read
What SHAP Can't Explain About Agentic AI Fraud

What SHAP Can't Explain About Agentic AI Fraud

Comments 2
3 min read
How to verify a file checksum on macOS, Linux, and Windows (and why you should)

How to verify a file checksum on macOS, Linux, and Windows (and why you should)

Comments
2 min read
pg_anon caught 1 of my 8 PII columns. My schema isn't in English.

pg_anon caught 1 of my 8 PII columns. My schema isn't in English.

Comments
3 min read
Silica: Testing Every AArch64 Instruction Encoding

Silica: Testing Every AArch64 Instruction Encoding

Comments 1
1 min read
Hermes Agent Security: What Can Your MCP Tools Reach?

Hermes Agent Security: What Can Your MCP Tools Reach?

Comments
5 min read
DoS vs DDoS: One Attacker, Many Machines, Same Goal

DoS vs DDoS: One Attacker, Many Machines, Same Goal

Comments
3 min read
StyleSmuggler: Unpatched Magento Zero-Day Is Backdooring Stores Right Now

StyleSmuggler: Unpatched Magento Zero-Day Is Backdooring Stores Right Now

Comments
5 min read
OVERPASS CVE-2026-44756: Pre-Authentication SAP Kernel RCE Across Multiple Protocols

OVERPASS CVE-2026-44756: Pre-Authentication SAP Kernel RCE Across Multiple Protocols

1
Comments 1
5 min read
Agentic AI Credential Harvesting: An Attack Built in Under Six Hours and the Separate Recon Case

Agentic AI Credential Harvesting: An Attack Built in Under Six Hours and the Separate Recon Case

1
Comments 1
6 min read
PoisonedRefresh: A Linux Rootkit Injecting an In-Memory Web Shell into BIG-IP APM

PoisonedRefresh: A Linux Rootkit Injecting an In-Memory Web Shell into BIG-IP APM

Comments 1
6 min read
Browser-Based ClickFix: Google Sheets C2 and Tampermonkey Manipulate Cryptocurrency Transactions

Browser-Based ClickFix: Google Sheets C2 and Tampermonkey Manipulate Cryptocurrency Transactions

1
Comments 1
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.