DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Email Verification Threat Models for OAuth Apps

Email Verification Threat Models for OAuth Apps

1
Comments
4 min read
I Can't Read Code. I Had Claude Code Build a Vulnerability Triage CLI Anyway.

I Can't Read Code. I Had Claude Code Build a Vulnerability Triage CLI Anyway.

Comments
5 min read
The Night Gemini Summoned a Choir of Ghosts in My YouTube Sidebar !! A Software Engineer’s Post-Mortem

The Night Gemini Summoned a Choir of Ghosts in My YouTube Sidebar !! A Software Engineer’s Post-Mortem

Comments 1
3 min read
Automated secret rotation with a 24-hour grace window — done right in NestJS + Postgres

Automated secret rotation with a 24-hour grace window — done right in NestJS + Postgres

Comments
8 min read
Plan your roadmap the way an attacker plans an intrusion

Plan your roadmap the way an attacker plans an intrusion

Comments
4 min read
I Put AI-Generated Code Through a PR Security Check. Here’s What It Caught.

I Put AI-Generated Code Through a PR Security Check. Here’s What It Caught.

Comments
3 min read
The 5 Cloud Migration Mistakes That Actually Cause Outages

The 5 Cloud Migration Mistakes That Actually Cause Outages

Comments
4 min read
I mapped every WordPress plugin CVE since 2023. Here's what the data says — and how I built it.

I mapped every WordPress plugin CVE since 2023. Here's what the data says — and how I built it.

Comments
3 min read
White Text, Real Instructions: How Invisible HTML Hijacks AI Email Summaries

White Text, Real Instructions: How Invisible HTML Hijacks AI Email Summaries

1
Comments
5 min read
We Built a Standardized File Format for Prompt Injection and Called It AGENTS.md

We Built a Standardized File Format for Prompt Injection and Called It AGENTS.md

1
Comments
3 min read
Inside APK Malware Detection: What Actually Works (And Why We Built Scandroid)

Inside APK Malware Detection: What Actually Works (And Why We Built Scandroid)

Comments
3 min read
Don't buy the hype around the Hugging Face incident

Don't buy the hype around the Hugging Face incident

Comments
5 min read
Exfiltrating a Hidden Secret Through a Search Bar with UNION SELECT

Exfiltrating a Hidden Secret Through a Search Bar with UNION SELECT

Comments
5 min read
OWASP A05 & A06: When Injection and Insecure Design Meet an Incomplete Application

OWASP A05 & A06: When Injection and Insecure Design Meet an Incomplete Application

1
Comments
8 min read
Row-level multi-tenancy in Go: the rule, the middleware and the test that proves it

Row-level multi-tenancy in Go: the rule, the middleware and the test that proves it

3
Comments 2
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.