DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Indirect prompt injection in a RAG pipeline: one attack, step by step, and what actually stopped it

Indirect prompt injection in a RAG pipeline: one attack, step by step, and what actually stopped it

2
Comments 4
5 min read
The fake browser extension playbook is back. This time it ships as agent skills

The fake browser extension playbook is back. This time it ships as agent skills

1
Comments 2
5 min read
JFrog Artifactory CVE-2026-82329: The Default Join Key as an Authentication Bypass

JFrog Artifactory CVE-2026-82329: The Default Join Key as an Authentication Bypass

Comments 1
3 min read
CVE-2026-73228: Request Parsing Size-Limit Bypass in Django REST Framework

CVE-2026-73228: Request Parsing Size-Limit Bypass in Django REST Framework

Comments
5 min read
mcp-drift-monitor: detecciĂłn continua de cambios no autorizados en servidores MCP

mcp-drift-monitor: detecciĂłn continua de cambios no autorizados en servidores MCP

Comments
3 min read
The Docker Layer Duplication Penalty: Why Modifying Files in Old Layers Costs You Twice

The Docker Layer Duplication Penalty: Why Modifying Files in Old Layers Costs You Twice

Comments
6 min read
x402 + MCP: where does the budget check go?

x402 + MCP: where does the budget check go?

3
Comments 1
10 min read
Cookie Consent Banners: Why Missing One Risks $20M Fines

Cookie Consent Banners: Why Missing One Risks $20M Fines

Comments
3 min read
Django OTP Verification: 4 Security Mistakes Most Tutorials Get Wrong

Django OTP Verification: 4 Security Mistakes Most Tutorials Get Wrong

Comments
3 min read
[ES] Nunca confĂ­es, siempre verifica: Arquitectura Zero Trust para Hyperledger Fabric

[ES] Nunca confĂ­es, siempre verifica: Arquitectura Zero Trust para Hyperledger Fabric

Comments 1
1 min read
I found a confirmed bug in the official MCP SDK while building a red-team tool for it

I found a confirmed bug in the official MCP SDK while building a red-team tool for it

Comments 1
3 min read
The Benchmark That's Half Traps — and Why That's Brilliant

The Benchmark That's Half Traps — and Why That's Brilliant

11
Comments
9 min read
How We Verify DSH Plugins

How We Verify DSH Plugins

Comments
4 min read
Building a Community Plugin Marketplace for OWASP OWTF (GSoC 2026)

Building a Community Plugin Marketplace for OWASP OWTF (GSoC 2026)

Comments
6 min read
Checking whether an npm package "exists" stopped working

Checking whether an npm package "exists" stopped working

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.