DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
OpenAI Shipped a Cyber Model That Writes Exploits. The Vetting Is the Point.

OpenAI Shipped a Cyber Model That Writes Exploits. The Vetting Is the Point.

Comments
3 min read
Zero-Install Tunneling in 2026: The Developer's Complete Guide to Agentless Localhost Proxies

Zero-Install Tunneling in 2026: The Developer's Complete Guide to Agentless Localhost Proxies

Comments
11 min read
I got nervous about installing MCP servers, so I built a scanner for them

I got nervous about installing MCP servers, so I built a scanner for them

4
Comments 4
3 min read
Audited a Popular Python Automation Project. The Biggest Risks Weren't What I Expected.

Audited a Popular Python Automation Project. The Biggest Risks Weren't What I Expected.

Comments
1 min read
Don't use an LLM to decide what your AI agent is allowed to do

Soft intelligence vs hard enforcement

Don't use an LLM to decide what your AI agent is allowed to do

13
Comments 15
4 min read
Your Database Will Be Breached Someday. The Question Is: Will Passwords Be Inside?

Your Database Will Be Breached Someday. The Question Is: Will Passwords Be Inside?

2
Comments
3 min read
pfSense vs commercial firewalls: what I learned auditing 200+ networks

pfSense vs commercial firewalls: what I learned auditing 200+ networks

Comments
4 min read
Performance tuning in progress

Performance tuning in progress

Comments
1 min read
System prompts are not a security boundary for AI agents

System prompts are not a security boundary for AI agents

1
Comments 1
2 min read
De CSRF a RCE: una visita web cuesta una shell en OpenYak

De CSRF a RCE: una visita web cuesta una shell en OpenYak

Comments
9 min read
Dev Log: 2026-06-24 — agent guardrails and runtime LDAP config

Dev Log: 2026-06-24 — agent guardrails and runtime LDAP config

Comments
3 min read
Microsoft Defender Zero-Days, GitHub Supply Chain Breaches, and Python Package Compromises

Microsoft Defender Zero-Days, GitHub Supply Chain Breaches, and Python Package Compromises

Comments
3 min read
Security Controls in Enterprise RAG: Keys, Audit Logs, and the Hierarchy That Prevents Role Elevation

Security Controls in Enterprise RAG: Keys, Audit Logs, and the Hierarchy That Prevents Role Elevation

Comments
5 min read
Connecting an MCP server gives your agent hands. It also gives a stranger a way in.

Distinguishing agent actions from beliefs

Connecting an MCP server gives your agent hands. It also gives a stranger a way in.

18
Comments 29
5 min read
CrimsonOS: Building a Mobile OS from the Firmware Up

CrimsonOS: Building a Mobile OS from the Firmware Up

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.