DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
What Was on This Machine? Answering the Blast Radius Question After a Laptop Compromise

What Was on This Machine? Answering the Blast Radius Question After a Laptop Compromise

Comments
10 min read
Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation

Valid provenance is not valid code: a supply-chain worm shipped with a valid SLSA attestation

Comments
5 min read
HTTP Security Headers Explained: A Practical Guide for Developers

HTTP Security Headers Explained: A Practical Guide for Developers

2
Comments
9 min read
Your AI Coding Agent Can Be Attacked by the Repository It Opens

Automatic workspace scans trigger risks instantly

Your AI Coding Agent Can Be Attacked by the Repository It Opens

69
Picked as gem Comments 66
5 min read
CrackMe Level 6

CrackMe Level 6

Comments
14 min read
F*ck CTF: Can a Multi-Agent LLM really play Capture The Flag?

F*ck CTF: Can a Multi-Agent LLM really play Capture The Flag?

Comments
2 min read
A security checklist my coding agent has to run

A security checklist my coding agent has to run

Comments 1
7 min read
No benchmark scores what a coding agent does when the normal path is blocked

No benchmark scores what a coding agent does when the normal path is blocked

Comments
5 min read
An AI Agent Found Admin Access to a $13B Startup in 25 Minutes. Here's the Free Tool It Used, and the Docker Mistake That Made It Possible

An AI Agent Found Admin Access to a $13B Startup in 25 Minutes. Here's the Free Tool It Used, and the Docker Mistake That Made It Possible

1
Comments
7 min read
Why an AppSec agent should try to disprove its own findings

Why an AppSec agent should try to disprove its own findings

Comments
6 min read
I Used to Use Splunk. Here’s Why My Team Switched

I Used to Use Splunk. Here’s Why My Team Switched

Comments
6 min read
Gas Optimization Audit: Venus Core Pool

Gas Optimization Audit: Venus Core Pool

Comments
6 min read
Building a Secure "Personal Gemini Journal" — Gen AI Academy APAC C3

Building a Secure "Personal Gemini Journal" — Gen AI Academy APAC C3

Comments
2 min read
OpenID Foundation Wants to Standardize US mDLs as Verifiable Credentials: What It Means for KYC Teams

OpenID Foundation Wants to Standardize US mDLs as Verifiable Credentials: What It Means for KYC Teams

4
Comments
4 min read
Identity and Access Management: Controlling Who Gets Access and Why It Matters

Identity and Access Management: Controlling Who Gets Access and Why It Matters

1
Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.