DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
We built ATTP -- HTTP for AI agents. Here's why.

We built ATTP -- HTTP for AI agents. Here's why.

Comments
2 min read
Axios was compromised for 3 hours - how to find it in your running Kubernetes clusters

Axios was compromised for 3 hours - how to find it in your running Kubernetes clusters

Comments
5 min read
We Scanned the Top 50 ClawHub Skills — Here's What We Found

We Scanned the Top 50 ClawHub Skills — Here's What We Found

1
Comments
3 min read
Claude Code Leak: Lessons in npm Security, TypeScript Analysis, and AI Tool Architecture

Claude Code Leak: Lessons in npm Security, TypeScript Analysis, and AI Tool Architecture

1
Comments
9 min read
The Claude Code Leak Proved What We've Been Building For

The Claude Code Leak Proved What We've Been Building For

Comments
3 min read
How to Secure GitHub Actions: OIDC Authentication, Least Privilege, and Supply Chain Attack Prevention

How to Secure GitHub Actions: OIDC Authentication, Least Privilege, and Supply Chain Attack Prevention

1
Comments
18 min read
IAM Access Analyzer nuked our prod hotfix because I fundamentally misunderstood how Zelkova evaluates wildcards

IAM Access Analyzer nuked our prod hotfix because I fundamentally misunderstood how Zelkova evaluates wildcards

Comments
2 min read
what if MCP servers had a Lighthouse-style security score?

what if MCP servers had a Lighthouse-style security score?

1
Comments
2 min read
SecureWipe: ANSSI and NIST-compliant secure disk erasure, because rm -rf isn't enough

SecureWipe: ANSSI and NIST-compliant secure disk erasure, because rm -rf isn't enough

Comments
3 min read
CVE-2025-53521: F5 BIG-IP APM RCE — CISA Deadline Is March 30

CVE-2025-53521: F5 BIG-IP APM RCE — CISA Deadline Is March 30

Comments
9 min read
Your AI agent can read every credential on your machine

Your AI agent can read every credential on your machine

1
Comments
3 min read
What Is 2FA with an Authenticator App, and Why Your JWT Login Flow Needs to Change

What Is 2FA with an Authenticator App, and Why Your JWT Login Flow Needs to Change

12
Comments
4 min read
The LiteLLM Supply Chain Attack Changed How We Think About AI Cost Monitoring

The LiteLLM Supply Chain Attack Changed How We Think About AI Cost Monitoring

Comments
2 min read
GitHub Access Persists After AI Coding Tool Subscription Cancellation: How to Revoke Access

GitHub Access Persists After AI Coding Tool Subscription Cancellation: How to Revoke Access

Comments
9 min read
Why Privacy Matters in Developer Tools

Why Privacy Matters in Developer Tools

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.