DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Prompt injection: your customer-facing AI is an attack surface

Prompt injection: your customer-facing AI is an attack surface

Comments
7 min read
Prompt Injection Is a Permissions Problem, Not a Model Problem

Prompt Injection Is a Permissions Problem, Not a Model Problem

Comments
6 min read
I built a static + runtime security scanner for MCP servers (Rust)

I built a static + runtime security scanner for MCP servers (Rust)

Comments
4 min read
Stop Trusting the App: Enforcing Append-Only at the Database Layer

Stop Trusting the App: Enforcing Append-Only at the Database Layer

1
Comments 1
4 min read
OAuth scopes are not your app's authorization model

OAuth scopes are not your app's authorization model

Comments 1
1 min read
Decode JWT Payloads Locally: What the Claims Tell You (and Don't)

Decode JWT Payloads Locally: What the Claims Tell You (and Don't)

Comments
2 min read
IdentityServer4 Is End-of-Life — Your Options in 2026

IdentityServer4 Is End-of-Life — Your Options in 2026

1
Comments 3
7 min read
The Ghost in the Machine: Unraveling Persistent Git Compromises Beyond Your Control

The Ghost in the Machine: Unraveling Persistent Git Compromises Beyond Your Control

Comments
5 min read
I built a WordPress site with AI. What should I check before launch?

I built a WordPress site with AI. What should I check before launch?

Comments
3 min read
Implementing Secure Configuration Management with Vault and Go

Implementing Secure Configuration Management with Vault and Go

Comments
6 min read
A blended recall number hid an entire class of leak

A blended recall number hid an entire class of leak

Comments 1
3 min read
What Happens If Your Password Manager’s Master Password Is Compromised?

What Happens If Your Password Manager’s Master Password Is Compromised?

Comments
4 min read
Slopsquatting: Why Cursor Recommends Packages Attackers Own

Slopsquatting: Why Cursor Recommends Packages Attackers Own

1
Comments
4 min read
Your sysctl says one thing, the kernel says another

Your sysctl says one thing, the kernel says another

Comments
2 min read
My robots.txt check passed for six days on an attacker's robots.txt

My robots.txt check passed for six days on an attacker's robots.txt

Comments 1
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.