DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
What do you actually check before shipping a vibe-coded app?

What do you actually check before shipping a vibe-coded app?

1
Comments
1 min read
If you got a 'DEV Support: verify your account in 12 hours' comment — stop. It's a phishing scam.

If you got a 'DEV Support: verify your account in 12 hours' comment — stop. It's a phishing scam.

5
Comments 3
3 min read
Manually Breaking Authentication — A Full Walkthrough (CWE-307, CWE-330, CWE-640)

Manually Breaking Authentication — A Full Walkthrough (CWE-307, CWE-330, CWE-640)

Comments
3 min read
Build Secure AI Agents with Microsoft Agent Framework and Auth0

Build Secure AI Agents with Microsoft Agent Framework and Auth0

1
Comments
6 min read
A Redis Lua Rate Limiter for FastAPI That Returns Useful 429 Headers

A Redis Lua Rate Limiter for FastAPI That Returns Useful 429 Headers

Comments
6 min read
AI Can Make Every Local Decision Look Reasonable — While Making the System Worse

AI Can Make Every Local Decision Look Reasonable — While Making the System Worse

11
Comments 4
6 min read
Password Manager Breaches: What Happened and Why Your Data Stayed Safe (Or Didn't)

Password Manager Breaches: What Happened and Why Your Data Stayed Safe (Or Didn't)

Comments
5 min read
Five PRs, four merges, and four real bugs in agent infrastructure

Five PRs, four merges, and four real bugs in agent infrastructure

2
Comments 3
7 min read
How Can AI/ML Help in DevSecOps Pipelines?

How Can AI/ML Help in DevSecOps Pipelines?

5
Comments
9 min read
I built an eBPF ransomware detector in Rust

I built an eBPF ransomware detector in Rust

Comments
4 min read
My prompt-injection fix caught 0 of 20 attacks. The part I almost didn't build caught all of them.

Judges can't spot manipulation if facts look right

My prompt-injection fix caught 0 of 20 attacks. The part I almost didn't build caught all of them.

5
Comments 8
5 min read
Security When You're a Two-Person Infrastructure Company

Security When You're a Two-Person Infrastructure Company

Comments
4 min read
adagents.json does not audit schain. Those two trust files do not talk.

adagents.json does not audit schain. Those two trust files do not talk.

Comments
2 min read
Your AI-Generated App Is Leaking API Keys - Here's How to Check

Your AI-Generated App Is Leaking API Keys - Here's How to Check

1
Comments 1
6 min read
Free Tokens, Paid Secrets: A Threat Model for AI-Assisted Development

Free Tokens, Paid Secrets: A Threat Model for AI-Assisted Development

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.