DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Model Distillation Is Just Espionage With Better PR

Model Distillation Is Just Espionage With Better PR

1
Comments 1
3 min read
Seven ways a remote MCP server gets authorization wrong

Seven ways a remote MCP server gets authorization wrong

Comments
5 min read
The confused deputy, or why "just forward the token" breaks your MCP server

The confused deputy, or why "just forward the token" breaks your MCP server

Comments
3 min read
My AI security tool caught 2 out of 14 real attacks. Here's what I learned.

My AI security tool caught 2 out of 14 real attacks. Here's what I learned.

1
Comments 1
4 min read
My "reproducible" build kept returning the same hash after the code changed. That was the bug.

My "reproducible" build kept returning the same hash after the code changed. That was the bug.

Comments
8 min read
I built a Linux Security Module that lives in-tree and boots from upstream

I built a Linux Security Module that lives in-tree and boots from upstream

Comments
3 min read
That Time Someone Exploited a Git Hook to Root Your Homelab

That Time Someone Exploited a Git Hook to Root Your Homelab

Comments
3 min read
OAuth 2.1 for MCP servers, done properly

OAuth 2.1 for MCP servers, done properly

Comments
4 min read
BlueMoon: A Shared Exploit Kit Chaining Chrome RCE, Sandbox Escape, and Windows Privilege Escalation

BlueMoon: A Shared Exploit Kit Chaining Chrome RCE, Sandbox Escape, and Windows Privilege Escalation

1
Comments
8 min read
Giving AI Agents Capabilities Without Giving Them Unrestricted Authority

Giving AI Agents Capabilities Without Giving Them Unrestricted Authority

1
Comments
3 min read
Access Tokens v/s Refresh Tokens Explained: How Authentication Really Works

Access Tokens v/s Refresh Tokens Explained: How Authentication Really Works

1
Comments
6 min read
Daily Dose of DevOps — GitHub Actions basics for DevOps

Daily Dose of DevOps — GitHub Actions basics for DevOps

Comments
2 min read
I Built a Windows Security Tool in Python

I Built a Windows Security Tool in Python

Comments
1 min read
Why command allowlists don't protect your AI coding agent

Why command allowlists don't protect your AI coding agent

Comments
2 min read
33 Seconds After Publish: Anatomy of a Comment-Phishing Campaign

33 Seconds After Publish: Anatomy of a Comment-Phishing Campaign

Comments 1
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.