DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Building CSRF Double-Submit Cookie Protection in PHP Video Admin Panels

Building CSRF Double-Submit Cookie Protection in PHP Video Admin Panels

Comments
9 min read
Metabase Zero-Day Hits CVSS 10.0: Unauthenticated SQL Injection Gives Full Admin

Metabase Zero-Day Hits CVSS 10.0: Unauthenticated SQL Injection Gives Full Admin

Comments
4 min read
CĂłmo solucionar el error \"Enable JavaScript and cookies to continue\"

CĂłmo solucionar el error \"Enable JavaScript and cookies to continue\"

Comments
2 min read
Learning prompt injection by attacking a deliberately vulnerable AI

Learning prompt injection by attacking a deliberately vulnerable AI

Comments 1
5 min read
My repository health tool gave Chromium a score. It had only seen part of it.

My repository health tool gave Chromium a score. It had only seen part of it.

Comments
5 min read
Linux Kernel CVEs: What to Patch by Device (2 – 8 Aug 2026)

Linux Kernel CVEs: What to Patch by Device (2 – 8 Aug 2026)

1
Comments
7 min read
Week 6: Signing the State, and Closing My Own Pull Requests

Week 6: Signing the State, and Closing My Own Pull Requests

Comments
4 min read
Hardware Backdoors in x86 CPUs: The 2026 Hacker News Wake-Up Call

Hardware Backdoors in x86 CPUs: The 2026 Hacker News Wake-Up Call

Comments
4 min read
Beyond the Password: How Passkeys Work Under the Hood

Beyond the Password: How Passkeys Work Under the Hood

1
Comments
3 min read
VMware ESX Shell Obfuscation: 21 Techniques Work with BusyBox and Bypass Plaintext Keyword Detection

VMware ESX Shell Obfuscation: 21 Techniques Work with BusyBox and Bypass Plaintext Keyword Detection

Comments
7 min read
Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data Theft

Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data Theft

Comments
7 min read
Scrubbing secrets from logs: patterns catch what you didn't issue, literals catch the rest

Scrubbing secrets from logs: patterns catch what you didn't issue, literals catch the rest

Comments
5 min read
Model Extraction and Distillation Attacks

Model Extraction and Distillation Attacks

Comments
4 min read
AI Transparency Obligations and User Disclosure

AI Transparency Obligations and User Disclosure

5
Comments
4 min read
Direct vs Indirect Prompt Injection: The One That Matters Is the One You Never Typed

Direct vs Indirect Prompt Injection: The One That Matters Is the One You Never Typed

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.