DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-23498: Shopware 6: Mapping Your Way to RCE via Twig Type Juggling

CVE-2026-23498: Shopware 6: Mapping Your Way to RCE via Twig Type Juggling

Comments
2 min read
Modeling identity and access hierarchy in Postgres with ltree

Modeling identity and access hierarchy in Postgres with ltree

Comments
7 min read
Building Cryptographically Secure Random Number Generators for High-Stakes Distributed Systems

Building Cryptographically Secure Random Number Generators for High-Stakes Distributed Systems

Comments
7 min read
Tu Nube como una Base de Datos: Guía Práctica de Steampipe para AWS

Tu Nube como una Base de Datos: Guía Práctica de Steampipe para AWS

Comments
4 min read
CVE-2025-66648: Vega's Visual Betrayal: Leaking the Window via Internal Functions

CVE-2025-66648: Vega's Visual Betrayal: Leaking the Window via Internal Functions

Comments
2 min read
CVE-2026-24785: The Sound of Silence: Breaking Clatter's Post-Quantum Promises (CVE-2026-24785)

CVE-2026-24785: The Sound of Silence: Breaking Clatter's Post-Quantum Promises (CVE-2026-24785)

Comments
2 min read
When macOS Gatekeeper Blocks a Legit App: Fixing Launch Errors in AzkaOS (app) on Sonoma

When macOS Gatekeeper Blocks a Legit App: Fixing Launch Errors in AzkaOS (app) on Sonoma

Comments
3 min read
MCP vs CLI Tools: Which is best for production applications?

MCP vs CLI Tools: Which is best for production applications?

Comments 1
6 min read
Your API Is Leaking Its Server Version. Yes, That’s Still a Thing

Your API Is Leaking Its Server Version. Yes, That’s Still a Thing

1
Comments 1
1 min read
Building Secure Blockchain Bridges: Common Vulnerabilities and Solutions.

Building Secure Blockchain Bridges: Common Vulnerabilities and Solutions.

4
Comments
5 min read
Securing Claude Code with Pipelock

Securing Claude Code with Pipelock

5
Comments
4 min read
Proving What AI Didn't Generate: Building Cryptographic Refusal Logs with CAP-SRP

Proving What AI Didn't Generate: Building Cryptographic Refusal Logs with CAP-SRP

1
Comments
14 min read
CVE-2025-69202: The Shared Hallucination: Authorization Bypass in axios-cache-interceptor

CVE-2025-69202: The Shared Hallucination: Authorization Bypass in axios-cache-interceptor

Comments
2 min read
CVE-2025-69256: Serverless Command Injection: When 'Experimental' Means 'Remote Shell'

CVE-2025-69256: Serverless Command Injection: When 'Experimental' Means 'Remote Shell'

Comments
2 min read
CVE-2026-21446: Bagisto's Open House: How an AJAX Header Stole the Admin Panel

CVE-2026-21446: Bagisto's Open House: How an AJAX Header Stole the Admin Panel

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.