DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
MCP Tool Poisoning: A Name Allowlist Is Not Enough

MCP Tool Poisoning: A Name Allowlist Is Not Enough

1
Comments 2
7 min read
Why 'monitoring' isn't enough for AI agents — and how I made delegation cryptographically verifiable

Why 'monitoring' isn't enough for AI agents — and how I made delegation cryptographically verifiable

2
Comments 5
4 min read
The LiteLLM Supply Chain Backdoor: What 3 Hours Means for Your AI Agent Gateway

The LiteLLM Supply Chain Backdoor: What 3 Hours Means for Your AI Agent Gateway

7
Comments 2
5 min read
Governance Attack Surface Review: Bybit

Governance Attack Surface Review: Bybit

Comments
6 min read
Your Self-Hosted AI Stack Just Landed on CISA's Exploited Vulnerabilities List

Your Self-Hosted AI Stack Just Landed on CISA's Exploited Vulnerabilities List

7
Comments 2
6 min read
Authorizer 2.4: Open-source auth for AI agents and modern enterprise apps

Authorizer 2.4: Open-source auth for AI agents and modern enterprise apps

1
Comments 1
5 min read
Gas Optimization Audit: Gauntlet

Gas Optimization Audit: Gauntlet

Comments
6 min read
A credential fetch is a read: the containment guard your write-target sandbox was missing

A credential fetch is a read: the containment guard your write-target sandbox was missing

1
Comments
3 min read
Exploitation of Langflow CVE-2026-0768: From Unauthenticated Root RCE to Secret Theft and Lateral Movement

Exploitation of Langflow CVE-2026-0768: From Unauthenticated Root RCE to Secret Theft and Lateral Movement

1
Comments
5 min read
AI Experiment: Porting a PLC Exploit Takes Hours and Hundreds of Dollars

AI Experiment: Porting a PLC Exploit Takes Hours and Hundreds of Dollars

1
Comments
5 min read
Patch Tuesday as a weapon: what Nightmare Eclipse exposed about the disclosure model

Patch Tuesday as a weapon: what Nightmare Eclipse exposed about the disclosure model

Comments
6 min read
Your camera roll is part of your developer threat model

Your camera roll is part of your developer threat model

Comments 1
3 min read
We Put Localhost on the Internet and Watched Who Turned Up

We Put Localhost on the Internet and Watched Who Turned Up

5
Comments 1
6 min read
One storage security audit suite for Azure, AWS, and GCP

One storage security audit suite for Azure, AWS, and GCP

Comments
3 min read
OpenAI Rogue Hacker Agent Claim Sparks Automation Safety Concerns

OpenAI Rogue Hacker Agent Claim Sparks Automation Safety Concerns

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.