DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
How a Single Unauthenticated POST Turns Langflow Into a Public Python Shell

How a Single Unauthenticated POST Turns Langflow Into a Public Python Shell

Comments 1
4 min read
How a web agency keeps every client site secure

How a web agency keeps every client site secure

Comments
2 min read
Two Retailers, One Attack: What Really Decides Who Survives a Breach

Two Retailers, One Attack: What Really Decides Who Survives a Breach

Comments
7 min read
89 drones hit the water simultaneously: the RF failure mode every event tech operator should model for

89 drones hit the water simultaneously: the RF failure mode every event tech operator should model for

1
Comments
5 min read
Why I built tmpdrop: a self-hosted, expiring file drop

Why I built tmpdrop: a self-hosted, expiring file drop

Comments
4 min read
Agent payment standards are standardizing the cap, not the binding

Agent payment standards are standardizing the cap, not the binding

Comments 17
1 min read
How to triage Java memory-shell clues without unsafe default heap dumps

How to triage Java memory-shell clues without unsafe default heap dumps

Comments
3 min read
The Fine-Tuning Trap: How Enterprises Are Accidentally Handing Their IP to AI Providers

The Fine-Tuning Trap: How Enterprises Are Accidentally Handing Their IP to AI Providers

Comments
7 min read
Your AI Vendor's "Zero Data Training" Clause Won't Hold Up. Here's What the Contract Actually Says.

Your AI Vendor's "Zero Data Training" Clause Won't Hold Up. Here's What the Contract Actually Says.

Comments
6 min read
I scanned a "vibe-coded" Python repo. Found 137 security bugs.

I scanned a "vibe-coded" Python repo. Found 137 security bugs.

Comments
3 min read
How to triage a suspected WebShell without giving AI a shell

How to triage a suspected WebShell without giving AI a shell

Comments
3 min read
What safety boundary should an AI incident investigation tool have?

What safety boundary should an AI incident investigation tool have?

Comments
3 min read
How to investigate a suspicious IP on a Linux server with read-only evidence

How to investigate a suspicious IP on a Linux server with read-only evidence

Comments
3 min read
NIS2 for developers: translate 66 pages of EU regulation into 10 technical controls

NIS2 for developers: translate 66 pages of EU regulation into 10 technical controls

Comments
5 min read
Single-Prompt Safety Scores Are Measuring the Wrong Thing

Single-Prompt Safety Scores Are Measuring the Wrong Thing

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.