DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The sandbox had no internet. The AI agent got out through DNS anyway.

The sandbox had no internet. The AI agent got out through DNS anyway.

Comments
3 min read
CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

Comments
2 min read
Introduction to Network-Based Exploit Development

Introduction to Network-Based Exploit Development

Comments
13 min read
Detecting unexpected custom attributes after CVE-2026-96367

Detecting unexpected custom attributes after CVE-2026-96367

1
Comments
2 min read
Put Splunk Search Results in Your Own App's Data Grid

Put Splunk Search Results in Your Own App's Data Grid

Comments 1
5 min read
QR ticket check-in for a WordPress event, without a scanner app

QR ticket check-in for a WordPress event, without a scanner app

Comments
4 min read
PicoCTF Buffer Overflow 0 Writeup — Overwrite a Variable to Unlock the Flag

PicoCTF Buffer Overflow 0 Writeup — Overwrite a Variable to Unlock the Flag

Comments
3 min read
Teaching an Incident Response Agent to Remember What Happened Last Time

Teaching an Incident Response Agent to Remember What Happened Last Time

Comments
7 min read
Nearly 11 Million Submission Endpoints on Port 587: The Mail Path That Is Rarely Reviewed

Nearly 11 Million Submission Endpoints on Port 587: The Mail Path That Is Rarely Reviewed

Comments
3 min read
I built a cryptographic protocol for agent memory — and an auditor found my tests were lying

I built a cryptographic protocol for agent memory — and an auditor found my tests were lying

Comments
2 min read
Why stored XSS in Drupal Webform (CVE-2026-96367) reaches other users

Why stored XSS in Drupal Webform (CVE-2026-96367) reaches other users

Comments
2 min read
Java 27 e a criptografia pós-quântica: o que muda para quem programa (e onde a AWS entra nisso)

Java 27 e a criptografia pós-quântica: o que muda para quem programa (e onde a AWS entra nisso)

Comments
5 min read
Responsible AI by Design: How Much Access Should an AI Agent Really Have?

Responsible AI by Design: How Much Access Should an AI Agent Really Have?

Comments
4 min read
How LLMs Are Creating New Security Risks in CI/CD Pipelines

How LLMs Are Creating New Security Risks in CI/CD Pipelines

Comments
14 min read
If you got a 'DEV Support: verify your account in 12 hours' comment — stop. It's a phishing scam.

If you got a 'DEV Support: verify your account in 12 hours' comment — stop. It's a phishing scam.

5
Comments 1
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.