DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Everyone Greps for SQL Injection. Nobody Greps for the Other Eight.

Everyone Greps for SQL Injection. Nobody Greps for the Other Eight.

3
Comments 2
4 min read
The filter missed. The schema held. Neither is where the guarantee lives.

The filter missed. The schema held. Neither is where the guarantee lives.

Comments
5 min read
The Real Risk of Ignoring API Security (And What the Data Actually Shows)

The Real Risk of Ignoring API Security (And What the Data Actually Shows)

5
Comments
4 min read
Google SAM (Sovereign Agent Mesh): The Secure Networking Layer for AI Agents

Google SAM (Sovereign Agent Mesh): The Secure Networking Layer for AI Agents

1
Comments
5 min read
Dictionary Pattern Matching in Some Languages Ignores Unspecified Keys, Risks Unexpected Bugs

Dictionary Pattern Matching in Some Languages Ignores Unspecified Keys, Risks Unexpected Bugs

Comments
10 min read
Marketplace SaaS Exports: Object Storage Signed URL Expiration After User Authorization

Marketplace SaaS Exports: Object Storage Signed URL Expiration After User Authorization

Comments
7 min read
AI Safety Is a Zero Trust Problem, Not a Philosophy Debate

AI Safety Is a Zero Trust Problem, Not a Philosophy Debate

4
Comments 3
2 min read
reCAPTCHA: It’s Not Just “I’m Not a Robot”

reCAPTCHA: It’s Not Just “I’m Not a Robot”

Comments
9 min read
Tool Evidence Guard v0.1.0: verificar datos antes de responder con un agente

Tool Evidence Guard v0.1.0: verificar datos antes de responder con un agente

6
Comments
5 min read
The Postman Variable Mistake That Leaks Tokens (and the 5-Scope Model That Prevents It)

The Postman Variable Mistake That Leaks Tokens (and the 5-Scope Model That Prevents It)

Comments
3 min read
DeviceCheck and App Attest: Stopping Fraud in iOS Apps

DeviceCheck and App Attest: Stopping Fraud in iOS Apps

6
Comments
7 min read
We Built an AI Agent That Intentionally Breaks Code to Fix It Before Hackers Do

We Built an AI Agent That Intentionally Breaks Code to Fix It Before Hackers Do

5
Comments 2
1 min read
Authentication Audit Trails: Correlating Risk Events with Session Lifecycle Actions

Authentication Audit Trails: Correlating Risk Events with Session Lifecycle Actions

Comments
7 min read
Manually Proving and Documenting an IDOR (CWE-639) — A Full Walkthrough

Manually Proving and Documenting an IDOR (CWE-639) — A Full Walkthrough

Comments
2 min read
From community review to a shipped security hardening with Codex

From community review to a shipped security hardening with Codex

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.