DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I tried to obfuscate my Java code before sending it to AI — here's what broke

I tried to obfuscate my Java code before sending it to AI — here's what broke

1
Comments 5
7 min read
Stop Duplicate Charges: API Idempotency in Laravel 🛡️

Stop Duplicate Charges: API Idempotency in Laravel 🛡️

Comments
2 min read
Triaging a Suspicious Indicator in One Command

Triaging a Suspicious Indicator in One Command

1
Comments
5 min read
Web Security Basics: Every Developer Must Know (2026)

Web Security Basics: Every Developer Must Know (2026)

Comments
8 min read
Can You Trust Your AI Agents? Why “Security” Is the Missing Layer

Can You Trust Your AI Agents? Why “Security” Is the Missing Layer

Comments
3 min read
You're probably leaking production tokens into jwt.io

You're probably leaking production tokens into jwt.io

1
Comments
3 min read
pip install provedex: a tamper-evident black box for your Python AI agent

pip install provedex: a tamper-evident black box for your Python AI agent

3
Comments
4 min read
StablR Stablecoin Hack - EURR/USDR Admin Key Attack

StablR Stablecoin Hack - EURR/USDR Admin Key Attack

Comments
4 min read
CWU Token On-Chain Investigation - $7.3M Commonwealth Rug Pull

CWU Token On-Chain Investigation - $7.3M Commonwealth Rug Pull

Comments
4 min read
Web Security Basics Every Developer Must Know (2026)

Web Security Basics Every Developer Must Know (2026)

Comments
6 min read
5 Supabase mistakes we catch in every vibecoded app audit at Inithouse

5 Supabase mistakes we catch in every vibecoded app audit at Inithouse

1
Comments
3 min read
The Bot that Never Was, Part 2 (Miasma worm): how a GitHub token survived and hijacked my repos from an Azure IP

The Bot that Never Was, Part 2 (Miasma worm): how a GitHub token survived and hijacked my repos from an Azure IP

Comments 2
10 min read
HalluSquatting: How Attackers Turn AI Coding Agents Into a Botnet Without Touching a Single Victim

HalluSquatting: How Attackers Turn AI Coding Agents Into a Botnet Without Touching a Single Victim

1
Comments 1
5 min read
HashiCorp Vault in Docker Compose fails with "address already in use" on port 8200 and IPC_LOCK warning

HashiCorp Vault in Docker Compose fails with "address already in use" on port 8200 and IPC_LOCK warning

1
Comments
3 min read
How I Built a Secure Mobile Login System with Python and Pydroid 3

How I Built a Secure Mobile Login System with Python and Pydroid 3

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.