DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Claude Code Has Been Reading Your Database Password This Whole Time

Claude Code Has Been Reading Your Database Password This Whole Time

Comments
3 min read
5 MCP Servers for Agent Identity — And Why the Problem Is Harder Than Any of Them Solve

5 MCP Servers for Agent Identity — And Why the Problem Is Harder Than Any of Them Solve

1
Comments
2 min read
How I Built a Secure Reverse Proxy with Nginx

How I Built a Secure Reverse Proxy with Nginx

Comments
3 min read
The 5 Security Holes in Almost Every MCP Server (And How to Find Them)

The 5 Security Holes in Almost Every MCP Server (And How to Find Them)

Comments
3 min read
Your AI agent sandbox has no gate

Your AI agent sandbox has no gate

1
Comments
5 min read
Claude Managed Agents Has Built-in Tracing. Here's What It Can't Do.

Claude Managed Agents Has Built-in Tracing. Here's What It Can't Do.

Comments
4 min read
A Deny Read Bug in Claude Code's Bubblewrap Sandbox

A Deny Read Bug in Claude Code's Bubblewrap Sandbox

1
Comments
2 min read
Is Your Crypto Bounty Token a Security? A Developer's Guide to the Howey Test

Is Your Crypto Bounty Token a Security? A Developer's Guide to the Howey Test

1
Comments
8 min read
SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

Comments
3 min read
I built a CI/CD tool that auto-heals broken pipelines, runs 6 security scans, and works from your IDE via MCP

I built a CI/CD tool that auto-heals broken pipelines, runs 6 security scans, and works from your IDE via MCP

1
Comments
2 min read
hash23 - A constexpr implementation of different hashing algorithms

hash23 - A constexpr implementation of different hashing algorithms

2
Comments
1 min read
SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

Comments
3 min read
SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

Comments
3 min read
SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

Comments
3 min read
Your VS Code Extensions Are a Supply Chain Attack Surface

Your VS Code Extensions Are a Supply Chain Attack Surface

4
Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.