DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Security Bite: Package Hallucination — What It Is and How to Fix It

Security Bite: Package Hallucination — What It Is and How to Fix It

Comments
2 min read
How Attackers Exploit Trust Signals Like HTTPS and UI Design

How Attackers Exploit Trust Signals Like HTTPS and UI Design

Comments
10 min read
GHSA-XJVP-7243-RG9H: GHSA-xjvp-7243-rg9h: Critical Path Traversal in Wish SCP Middleware Allows Arbitrary File Read/Write

GHSA-XJVP-7243-RG9H: GHSA-xjvp-7243-rg9h: Critical Path Traversal in Wish SCP Middleware Allows Arbitrary File Read/Write

Comments
2 min read
How AI Agents Are Finding Smart Contract Vulnerabilities That Humans Miss

How AI Agents Are Finding Smart Contract Vulnerabilities That Humans Miss

3
Comments
2 min read
Firebase AI Logic's Template-Only Mode Is the Security Feature We Actually Needed

Google I/O Writing Challenge Submission

Firebase AI Logic's Template-Only Mode Is the Security Feature We Actually Needed

3
Comments
5 min read
53% of AI Agents Exceed Their Permissions. That's an Architecture Problem.

53% of AI Agents Exceed Their Permissions. That's an Architecture Problem.

Comments
8 min read
MCP security has 4 layers. Most teams have 2.

MCP security has 4 layers. Most teams have 2.

1
Comments
4 min read
Data Privacy in Regulated Applications: What Developers Need to Know

Data Privacy in Regulated Applications: What Developers Need to Know

Comments
7 min read
Running a Full Multi-Stage Intrusion Simulation. Every Detection Fired.

Running a Full Multi-Stage Intrusion Simulation. Every Detection Fired.

9
Comments 2
6 min read
Your Emails Go to Spam Because of Three DNS Records You Never Set Up

Your Emails Go to Spam Because of Three DNS Records You Never Set Up

Comments
5 min read
CSP for Third Party Scripts: The Practical Cheat Sheet for GA, Stripe, Intercom, and More

CSP for Third Party Scripts: The Practical Cheat Sheet for GA, Stripe, Intercom, and More

1
Comments
6 min read
IDOR in AI-Generated APIs: What Cursor Won't Check for You

IDOR in AI-Generated APIs: What Cursor Won't Check for You

3
Comments 2
3 min read
Building SystemGuard: Why I'm Writing an Open-Source CrowdStrike Alternative in Rust

Building SystemGuard: Why I'm Writing an Open-Source CrowdStrike Alternative in Rust

1
Comments
2 min read
We Had Secrets in Kubernetes. Then We Got Audited.

We Had Secrets in Kubernetes. Then We Got Audited.

1
Comments
6 min read
5 ways subdomain enumeration breaks (and how to handle each)

5 ways subdomain enumeration breaks (and how to handle each)

3
Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.