DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
From Vulnerable to Distroless: Auditing Docker Images with Trivy in CI

From Vulnerable to Distroless: Auditing Docker Images with Trivy in CI

Comments
11 min read
Injection Attacks Are Not Dead: SQL, NoSQL, ORM, and Command Injection — How to Actually Fix Them (2026)

Injection Attacks Are Not Dead: SQL, NoSQL, ORM, and Command Injection — How to Actually Fix Them (2026)

6
Comments
5 min read
OWASP Top 10 for Developers (2026 Edition) — How to Actually Fix the Most Dangerous Web Vulnerabilities

OWASP Top 10 for Developers (2026 Edition) — How to Actually Fix the Most Dangerous Web Vulnerabilities

11
Comments 1
6 min read
AWS IAM Roles Explained - A Beginner's Guide (With Real Examples)

AWS IAM Roles Explained - A Beginner's Guide (With Real Examples)

Comments
11 min read
What Is a Sandbox? How to Safely Run and Analyze Any Unknown .exe

What Is a Sandbox? How to Safely Run and Analyze Any Unknown .exe

12
Comments 1
5 min read
Auditing Windows security from a Python script, no pip install needed

Auditing Windows security from a Python script, no pip install needed

Comments
3 min read
AWS Frontier Agents: What $50/Hour Pen Testing and $30/Hour SRE Means for Platform Teams

AWS Frontier Agents: What $50/Hour Pen Testing and $30/Hour SRE Means for Platform Teams

Comments
4 min read
The Axios Breach Started with a Plaintext Token — Here's How I Keep Zero Secrets in My Repos

The Axios Breach Started with a Plaintext Token — Here's How I Keep Zero Secrets in My Repos

Comments
5 min read
FastAPI + MCP: Adding Real OAuth 2.1 Auth to Your Python MCP Server

FastAPI + MCP: Adding Real OAuth 2.1 Auth to Your Python MCP Server

Comments 1
9 min read
Every agent trust proposal is building the wrong thing

Every agent trust proposal is building the wrong thing

Comments
3 min read
The Claude Code Leak Changed the Threat Model. Here's How to Defend Your AI Agents.

The Claude Code Leak Changed the Threat Model. Here's How to Defend Your AI Agents.

Comments
11 min read
Why We Built a Local-First iPhone Authenticator Instead of Another Cloud-Synced 2FA App

Why We Built a Local-First iPhone Authenticator Instead of Another Cloud-Synced 2FA App

Comments
1 min read
DevSecOps in Practice: Tools That Actually Catch Vulnerabilities - Part 3 - SCA with pip-audit

DevSecOps in Practice: Tools That Actually Catch Vulnerabilities - Part 3 - SCA with pip-audit

1
Comments 1
3 min read
HTTP/3 Fingerprints: Identifying Clients in the QUIC Era

HTTP/3 Fingerprints: Identifying Clients in the QUIC Era

1
Comments
3 min read
Cookie based authentication & authorization in ASP.NET Core explained

Cookie based authentication & authorization in ASP.NET Core explained

1
Comments 1
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.