DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Securing the Mission: Applying Security Techniques to Computing Resources

Securing the Mission: Applying Security Techniques to Computing Resources

Comments
4 min read
OpenAI Responses API `user` Migration: Split Safety from Prompt Caching

OpenAI Responses API `user` Migration: Split Safety from Prompt Caching

5
Comments
4 min read
Resilience and Recovery in Security Architecture: Why They Matter for Future DoD Cyber Professionals

Resilience and Recovery in Security Architecture: Why They Matter for Future DoD Cyber Professionals

Comments
4 min read
Agents already found their forum. We built the better one.

Agents already found their forum. We built the better one.

Comments
3 min read
SC-900 Part 3: Microsoft Security Solutions (the biggest domain, decoded)

SC-900 Part 3: Microsoft Security Solutions (the biggest domain, decoded)

Comments
6 min read
The Phishing Site Tried to Talk to My AI. That Became the Evidence.

The Phishing Site Tried to Talk to My AI. That Became the Evidence.

1
Comments
7 min read
I Gave ChatGPT My Full Codebase. The Results Scared Me — But Not for the Reason You Think.

AI maps code well but writes plausible errors

I Gave ChatGPT My Full Codebase. The Results Scared Me — But Not for the Reason You Think.

23
Comments 14
7 min read
All 4052 if_sid anchors in the Wazuh ruleset resolve, so that's not why your rule is silent

All 4052 if_sid anchors in the Wazuh ruleset resolve, so that's not why your rule is silent

1
Comments 2
2 min read
Self-Hosted IAM: Roles, Policies, and Instance Profiles Without AWS

Self-Hosted IAM: Roles, Policies, and Instance Profiles Without AWS

Comments
5 min read
CVE-2026-32475: Unauthenticated RCE in Elementor Pro via File Upload Validation Bypass

CVE-2026-32475: Unauthenticated RCE in Elementor Pro via File Upload Validation Bypass

Comments 2
3 min read
Refresh Token Rotation Under the Hood: How Auth0 Catches a Stolen Token Before It's Ever Replayed

Refresh Token Rotation Under the Hood: How Auth0 Catches a Stolen Token Before It's Ever Replayed

Comments
4 min read
The Wildcard Scope Problem: Why MCP Configs Default to admin:* Instead of Least Privilege

The Wildcard Scope Problem: Why MCP Configs Default to admin:* Instead of Least Privilege

Comments
3 min read
Tool Poisoning Isn't Code, It's Text: How MCP Tool Descriptions Smuggle Prompt Injection

Tool Poisoning Isn't Code, It's Text: How MCP Tool Descriptions Smuggle Prompt Injection

Comments
4 min read
A GitHub token is not an agent permission model

A GitHub token is not an agent permission model

Comments
4 min read
I audited 50 projects built with Cursor & Claude. Here are the 4 security traps they all had

I audited 50 projects built with Cursor & Claude. Here are the 4 security traps they all had

Comments 2
1 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.