DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Session Security in PHP — What Most Developers Get Wrong

Session Security in PHP — What Most Developers Get Wrong

1
Comments
8 min read
The GITHUB_TOKEN in Your .zshrc Is a Time Bomb (And So Is Your .npmrc)

The GITHUB_TOKEN in Your .zshrc Is a Time Bomb (And So Is Your .npmrc)

Comments
5 min read
Building a Network Port Scanner with Go: Concurrency Patterns That Actually Scale

Building a Network Port Scanner with Go: Concurrency Patterns That Actually Scale

1
Comments
5 min read
I Built the Thing My Last Article Said Didn't Exist Yet

I Built the Thing My Last Article Said Didn't Exist Yet

2
Comments
4 min read
My MCP Server's GitHub Token Can Write. The Code That Promises It Never Will Had No Test.

My MCP Server's GitHub Token Can Write. The Code That Promises It Never Will Had No Test.

1
Comments 3
4 min read
I blocked XSS attacks and API Key extraction in the browser by monkey-patching `crypto.subtle`. Why isn't everyone doing this?

I blocked XSS attacks and API Key extraction in the browser by monkey-patching `crypto.subtle`. Why isn't everyone doing this?

Comments
1 min read
7 JWT Security Mistakes I See in Almost Every Auth Implementation

7 JWT Security Mistakes I See in Almost Every Auth Implementation

Comments
2 min read
Your Sandbox Has a Hole in It, and the AI Agent Found It

Your Sandbox Has a Hole in It, and the AI Agent Found It

Comments
4 min read
Common Cryptographic Anti-Patterns to Avoid in Modern APIs

Common Cryptographic Anti-Patterns to Avoid in Modern APIs

Comments
3 min read
Disruption of Polish CHP: Wind Farm to OT via Private APN

Disruption of Polish CHP: Wind Farm to OT via Private APN

Comments 2
8 min read
Product Leadership in the AI Era: Intent Governance and Token Economics

Product Leadership in the AI Era: Intent Governance and Token Economics

Comments 1
1 min read
Secure Code Review Challenge #2: Professional — Solution (Clean Code Can Still Be Vulnerable)

Secure Code Review Challenge #2: Professional — Solution (Clean Code Can Still Be Vulnerable)

Comments 2
11 min read
When ‘Are We Affected?’ Requires Reconstructing Yesterday’s npm Install

When ‘Are We Affected?’ Requires Reconstructing Yesterday’s npm Install

1
Comments
3 min read
Security news weekly round-up - 7th August 2026

Security news weekly round-up - 7th August 2026

1
Comments
4 min read
How to Block SQL Injection Attacks with a Free WAF

How to Block SQL Injection Attacks with a Free WAF

5
Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.