DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Postman Variable Mistake That Leaks Tokens (and the 5-Scope Model That Prevents It)

The Postman Variable Mistake That Leaks Tokens (and the 5-Scope Model That Prevents It)

Comments
3 min read
We Built an AI Agent That Intentionally Breaks Code to Fix It Before Hackers Do

We Built an AI Agent That Intentionally Breaks Code to Fix It Before Hackers Do

5
Comments 2
1 min read
Authentication Audit Trails: Correlating Risk Events with Session Lifecycle Actions

Authentication Audit Trails: Correlating Risk Events with Session Lifecycle Actions

Comments
7 min read
From community review to a shipped security hardening with Codex

From community review to a shipped security hardening with Codex

1
Comments
3 min read
Manually Proving and Documenting an IDOR (CWE-639) — A Full Walkthrough

Manually Proving and Documenting an IDOR (CWE-639) — A Full Walkthrough

Comments
2 min read
Securing a RAG Pipeline — The Threats I Designed Against and the Ones I Didn't

Securing a RAG Pipeline — The Threats I Designed Against and the Ones I Didn't

1
Comments 1
8 min read
sbx: a disposable Docker sandbox for opening untrusted repos in your own IDE

sbx: a disposable Docker sandbox for opening untrusted repos in your own IDE

1
Comments
2 min read
A Backup You Have Never Restored Is a Wish

A Backup You Have Never Restored Is a Wish

Comments
2 min read
What does "verified" actually mean in your stack?

What does "verified" actually mean in your stack?

Comments
1 min read
Plugin4Shell Hit 26,000 Agents Before Anyone Noticed. Your Coding Agent’s Plugin Store Is the New npm.

Plugin4Shell Hit 26,000 Agents Before Anyone Noticed. Your Coding Agent’s Plugin Store Is the New npm.

5
Comments 2
7 min read
qm Gives Every Employee Their Own Agent Sandbox Instead of One Shared Brain

qm Gives Every Employee Their Own Agent Sandbox Instead of One Shared Brain

Comments
4 min read
Who does open source actually depend on? I scanned the 433 most-starred JS repos

Who does open source actually depend on? I scanned the 433 most-starred JS repos

1
Comments
4 min read
The Perimeter Moved to the Laptop: From Network, to Identity, to the Developer Endpoint

The Perimeter Moved to the Laptop: From Network, to Identity, to the Developer Endpoint

Comments
8 min read
Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins

Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins

Comments
5 min read
Customizing Keycloak: Themes, Login Flows, and Disabled-User Handling

Customizing Keycloak: Themes, Login Flows, and Disabled-User Handling

5
Comments 2
19 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.