DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Prompt Injection Isn’t Going Away — Jason Haddix on the Architecture Problem Nobody Wants to Admit

Prompt Injection Isn’t Going Away — Jason Haddix on the Architecture Problem Nobody Wants to Admit

5
Comments 1
3 min read
The Habit That Was The Bug

The Habit That Was The Bug

Comments
9 min read
Test a DNS Leak in 2 Minutes: Complete Methodology + Per-OS Fixes (2026)

Test a DNS Leak in 2 Minutes: Complete Methodology + Per-OS Fixes (2026)

Comments
5 min read
I Built a Signal Protocol Messenger from Scratch with X3DH, Double Ratchet, Safety Numbers, P2P File Transfer

Prevents server-side public key substitution

I Built a Signal Protocol Messenger from Scratch with X3DH, Double Ratchet, Safety Numbers, P2P File Transfer

7
Comments 11
6 min read
MP3 - SQLi, XSS, and CSRF WriteUp

MP3 - SQLi, XSS, and CSRF WriteUp

Comments
7 min read
Codex Got Blocked by macOS. I Reinstalled Instead of Bypassing It.

Codex Got Blocked by macOS. I Reinstalled Instead of Bypassing It.

3
Comments
3 min read
Your AI agent has a master key to everything. Here's why that's a problem.

Your AI agent has a master key to everything. Here's why that's a problem.

Comments
2 min read
Reconnaissance Is Not Hacking (And That's Why It's So Powerful)

Reconnaissance Is Not Hacking (And That's Why It's So Powerful)

Comments
2 min read
What Is Steganography? How It Works, Types, and Why It Matters

What Is Steganography? How It Works, Types, and Why It Matters

5
Comments 1
4 min read
How to sandbox an MCP server with Docker (--network none is your best friend)

How to sandbox an MCP server with Docker (--network none is your best friend)

Comments 2
3 min read
How to Decode JWT Tokens Without a Backend

How to Decode JWT Tokens Without a Backend

1
Comments 4
3 min read
Anthropic just published a jailbreak severity scale. Here's what it means.

Anthropic just published a jailbreak severity scale. Here's what it means.

Comments
3 min read
I built an offline threat-hunting CLI in python because spinning up a SIEM for one log file is overkill

I built an offline threat-hunting CLI in python because spinning up a SIEM for one log file is overkill

1
Comments 2
4 min read
Why `async def` without `await` is the #1 vibe-coding bug (and how to catch it)

Why `async def` without `await` is the #1 vibe-coding bug (and how to catch it)

1
Comments
2 min read
Making a local-first tool's CSV export audit-ready (and why charts don't belong in a CSV)

Making a local-first tool's CSV export audit-ready (and why charts don't belong in a CSV)

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.