DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Why I built a post-quantum signing API (and why JWT is on borrowed time)

Why I built a post-quantum signing API (and why JWT is on borrowed time)

3
Comments
2 min read
$60K Billed in 13 Hours: Why Leaked Firebase Keys Keep Killing AI-Built Apps

$60K Billed in 13 Hours: Why Leaked Firebase Keys Keep Killing AI-Built Apps

Comments
5 min read
PostgreSQL Row Level Security: A Complete Guide

PostgreSQL Row Level Security: A Complete Guide

1
Comments
2 min read
Vercel Hack: Why You Need to Rotate Your "Non-Sensitive" Environment Variables Today

Vercel Hack: Why You Need to Rotate Your "Non-Sensitive" Environment Variables Today

14
Comments 1
2 min read
A 300-Line GitHub Actions Security Linter: Five Rules That Catch the CVE Patterns

A 300-Line GitHub Actions Security Linter: Five Rules That Catch the CVE Patterns

Comments
7 min read
Beyond Vibe-Coding: Why we built a "Stripe for App-Security" using LightRAG

Beyond Vibe-Coding: Why we built a "Stripe for App-Security" using LightRAG

Comments 2
2 min read
CAPTCHA without cookies: a proof-of-work approach

CAPTCHA without cookies: a proof-of-work approach

2
Comments
9 min read
CVE-2026-34197: el bug de ActiveMQ que vivió 13 años y ahora CISA obliga a parchar

CVE-2026-34197: el bug de ActiveMQ que vivió 13 años y ahora CISA obliga a parchar

Comments
8 min read
I Read the Devenex Launch Yesterday - Here's the Policy File Your Agent Repo Is Still Missing

I Read the Devenex Launch Yesterday - Here's the Policy File Your Agent Repo Is Still Missing

11
Comments 5
4 min read
The Real Reason People Reuse Passwords (And What I Built Instead)

The Real Reason People Reuse Passwords (And What I Built Instead)

1
Comments
6 min read
HTTP desync: el bug que permitió espiar Discord en tiempo real

HTTP desync: el bug que permitió espiar Discord en tiempo real

Comments
9 min read
DNS security in 2026: 10 things developers get wrong

DNS security in 2026: 10 things developers get wrong

Comments
5 min read
API Authentication: What It Is, Why It Matters, and Which Method to Use

API Authentication: What It Is, Why It Matters, and Which Method to Use

Comments 1
6 min read
Security Checks with Local LLMs

Security Checks with Local LLMs

4
Comments 5
6 min read
Stop Blindly Trusting MCP Servers — Add a Trust Gate to Your AI Agent in 5 Lines

Stop Blindly Trusting MCP Servers — Add a Trust Gate to Your AI Agent in 5 Lines

1
Comments
2 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.