DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
nginx is not the bug. Two lines of your config are. CVE-2026-42945 on a live stand

nginx is not the bug. Two lines of your config are. CVE-2026-42945 on a live stand

1
Comments
17 min read
Trust Is an Engineering Output

Trust Is an Engineering Output

Comments
8 min read
Claude Code Has Been Embedding Steganographic Markers in Your Prompts — Here’s the Full Story

Claude Code Has Been Embedding Steganographic Markers in Your Prompts — Here’s the Full Story

1
Comments
4 min read
Every per-IP control we shipped was bypassable with one header

Every per-IP control we shipped was bypassable with one header

2
Comments
4 min read
Running Untrusted Code Safely: A Field Guide for AI and CI Pipelines

Running Untrusted Code Safely: A Field Guide for AI and CI Pipelines

Comments
6 min read
KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise

KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise

Comments 1
6 min read
When Your AI Coding Tool Reads Your Code, Where Does It Actually Go

When Your AI Coding Tool Reads Your Code, Where Does It Actually Go

1
Comments
4 min read
Surgical SEO: Automating WordPress Metadata without giving AI full access

Surgical SEO: Automating WordPress Metadata without giving AI full access

Comments 1
4 min read
Put the Security Check Inside the Query, Not After It

Put the Security Check Inside the Query, Not After It

Comments
5 min read
From CORS to RCE: WordPress Bug Bounty Chains

From CORS to RCE: WordPress Bug Bounty Chains

Comments
12 min read
I denied 7 dangerous commands. My agent deleted the files anyway

I denied 7 dangerous commands. My agent deleted the files anyway

1
Comments 1
5 min read
How to vet an MCP server before you install it (I graded 130,000 to find out)

How to vet an MCP server before you install it (I graded 130,000 to find out)

1
Comments
3 min read
How I built a lightweight standalone behavioral anti-stealer to protect my Windows environment

How I built a lightweight standalone behavioral anti-stealer to protect my Windows environment

Comments
2 min read
Building a Production AI Agent in Spring Boot: The Append-Only Audit Trail (Part 13)

Building a Production AI Agent in Spring Boot: The Append-Only Audit Trail (Part 13)

Comments
8 min read
The 40-Minute Supply Chain Attack That Leaked Microsoft, Amazon and Cisco Secrets

The 40-Minute Supply Chain Attack That Leaked Microsoft, Amazon and Cisco Secrets

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.