DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Your API Is Leaking Its Server Version. Yes, That’s Still a Thing

Your API Is Leaking Its Server Version. Yes, That’s Still a Thing

1
Comments 1
1 min read
Building Secure Blockchain Bridges: Common Vulnerabilities and Solutions.

Building Secure Blockchain Bridges: Common Vulnerabilities and Solutions.

4
Comments
5 min read
APRA CPS 234 and AI Agents: What Australian Financial Institutions Need to Do Now

APRA CPS 234 and AI Agents: What Australian Financial Institutions Need to Do Now

Comments
2 min read
The Unseen Math Behind Your SAST Tool: How Static Analysis Works Its Magic

The Unseen Math Behind Your SAST Tool: How Static Analysis Works Its Magic

2
Comments
4 min read
Proving What AI Didn't Generate: Building Cryptographic Refusal Logs with CAP-SRP

Proving What AI Didn't Generate: Building Cryptographic Refusal Logs with CAP-SRP

1
Comments
14 min read
CVE-2025-69202: The Shared Hallucination: Authorization Bypass in axios-cache-interceptor

CVE-2025-69202: The Shared Hallucination: Authorization Bypass in axios-cache-interceptor

Comments
2 min read
CVE-2025-69256: Serverless Command Injection: When 'Experimental' Means 'Remote Shell'

CVE-2025-69256: Serverless Command Injection: When 'Experimental' Means 'Remote Shell'

Comments
2 min read
CVE-2026-21446: Bagisto's Open House: How an AJAX Header Stole the Admin Panel

CVE-2026-21446: Bagisto's Open House: How an AJAX Header Stole the Admin Panel

Comments
2 min read
CVE-2017-5638: The Billion Dollar Header: Inside the Apache Struts 2 'Equifax' RCE

CVE-2017-5638: The Billion Dollar Header: Inside the Apache Struts 2 'Equifax' RCE

Comments
2 min read
CVE-2025-69223: Puff, The Magic Dragon: Exploding RAM with aiohttp Zip Bombs

CVE-2025-69223: Puff, The Magic Dragon: Exploding RAM with aiohttp Zip Bombs

Comments
2 min read
CVE-2025-69224: Absolute Zero Security: Smuggling Requests into aiohttp with the Kelvin Sign

CVE-2025-69224: Absolute Zero Security: Smuggling Requests into aiohttp with the Kelvin Sign

Comments
2 min read
CVE-2025-69226: AIOHTTP Side-Channel: When 403 Means 'I See You'

CVE-2025-69226: AIOHTTP Side-Channel: When 403 Means 'I See You'

Comments
2 min read
Week 8 Challenge: Use ELK for Port Scan Detection

Week 8 Challenge: Use ELK for Port Scan Detection

2
Comments
11 min read
CVE-2025-65091: Calendar of Doom: A Critical HQL Injection in XWiki

CVE-2025-65091: Calendar of Doom: A Critical HQL Injection in XWiki

Comments
2 min read
GHSA-MQQF-5WVP-8FH8: Slashing Through the Safety Nets: The go-chi Open Redirect

GHSA-MQQF-5WVP-8FH8: Slashing Through the Safety Nets: The go-chi Open Redirect

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.