DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I built an audit-friendly SQLite viewer for VSCode because I stopped trusting marketplace extensions

I built an audit-friendly SQLite viewer for VSCode because I stopped trusting marketplace extensions

2
Comments
5 min read
MCP SEP-2468: RFC 9207 Iss Parameter for OAuth Mix-Up Defense

MCP SEP-2468: RFC 9207 Iss Parameter for OAuth Mix-Up Defense

1
Comments
8 min read
AI Agent Safety in Production: Why Trust and Safety Infrastructure Isn't Optional Anymore

AI Agent Safety in Production: Why Trust and Safety Infrastructure Isn't Optional Anymore

1
Comments 1
3 min read
OWASP Secure Coding Checklist for Node Express APIs 2026

OWASP Secure Coding Checklist for Node Express APIs 2026

13
Comments
11 min read
How to Stop Accidentally Committing AWS Keys to GitHub

How to Stop Accidentally Committing AWS Keys to GitHub

Comments
5 min read
The Three-Body Problem: AI Code, Supply Chain Attacks, and the Talent Exodus

The Three-Body Problem: AI Code, Supply Chain Attacks, and the Talent Exodus

2
Comments
7 min read
Top 10 Free Cybersecurity Tools You Should Be Using in 2026

Top 10 Free Cybersecurity Tools You Should Be Using in 2026

11
Comments
7 min read
The OAuth Tunnel Trap: Preventing Subdomain Hijacking in Local Development

The OAuth Tunnel Trap: Preventing Subdomain Hijacking in Local Development

Comments
12 min read
Three Incidents. Four Layers. One Week.

Three Incidents. Four Layers. One Week.

Comments
4 min read
Istio 1.30 Deep Dive — Agentgateway, Ambient Multicluster, TrafficExtension API, and 4 CVE Patches (JWKS RSA Leak, XDS Debug Auth)

Istio 1.30 Deep Dive — Agentgateway, Ambient Multicluster, TrafficExtension API, and 4 CVE Patches (JWKS RSA Leak, XDS Debug Auth)

Comments
11 min read
SylvaCrypt E2E Encrypted Messaging platform for the Privacy-Conscious

SylvaCrypt E2E Encrypted Messaging platform for the Privacy-Conscious

3
Comments
2 min read
Stop Running LLM Workloads on Vanilla Kubernetes

Stop Running LLM Workloads on Vanilla Kubernetes

Comments
4 min read
The pgAudit Attribution Gap: Why Role-Level Logging Fails GDPR and How to Close It

The pgAudit Attribution Gap: Why Role-Level Logging Fails GDPR and How to Close It

Comments 1
5 min read
Stop Guessing What’s Public: Automating Attack Surface Discovery

Stop Guessing What’s Public: Automating Attack Surface Discovery

2
Comments
4 min read
When a patched CVE comes back: detecting silent driver regressions

When a patched CVE comes back: detecting silent driver regressions

1
Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.