DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
A fake MCP server spent three months earning trust. The tells were there

A fake MCP server spent three months earning trust. The tells were there

1
Comments 14
3 min read
Day 37: The Role Is Not What You Attach, and the Bucket Is Not the Objects

Day 37: The Role Is Not What You Attach, and the Bucket Is Not the Objects

10
Comments
5 min read
The Gemini breakout verdict has to come from the boundary, not the model's mouth

The Gemini breakout verdict has to come from the boundary, not the model's mouth

1
Comments 1
5 min read
Nodos distribuidos a prueba de manipulación: Integridad de código SHA-256.

Nodos distribuidos a prueba de manipulación: Integridad de código SHA-256.

Comments 1
1 min read
Agent Injection Corpus: instruction/data channel confusion across programming languages. #Astra #Devin

Agent Injection Corpus: instruction/data channel confusion across programming languages. #Astra #Devin

2
Comments 4
2 min read
Capbroker: I gave an AI agent a fake GitHub key, then watched it get tricked into trying to delete a repo anyway

Deterministic brokers stop rogue tool calls

Capbroker: I gave an AI agent a fake GitHub key, then watched it get tricked into trying to delete a repo anyway

4
Comments 14
7 min read
I scanned 55 public Lovable apps — all 55 had a GDPR or security finding

I scanned 55 public Lovable apps — all 55 had a GDPR or security finding

Comments
4 min read
Your AI Agent Is a Confused Deputy

Your AI Agent Is a Confused Deputy

1
Comments 1
5 min read
An AI agent is just a while loop. I built one in 70 lines of Python, then tricked it into leaking my .env

Fixing security in runtime code, not prompts

An AI agent is just a while loop. I built one in 70 lines of Python, then tricked it into leaking my .env

33
Picked as gem Comments 23
15 min read
How to Protect an API From DDoS Attacks: A Complete Guide

How to Protect an API From DDoS Attacks: A Complete Guide

Comments
11 min read
The Only Container Orchestrator with Built-In Compliance: How Gubernator Enforces ENS, NIS 2, DORA, CIS Benchmark, and ISO 27001

The Only Container Orchestrator with Built-In Compliance: How Gubernator Enforces ENS, NIS 2, DORA, CIS Benchmark, and ISO 27001

11
Comments 1
10 min read
Stop Hosting Client WordPress Sites in One Shared Account

Stop Hosting Client WordPress Sites in One Shared Account

Comments
8 min read
Auditing AI agent activity: structured logs for credential access

Auditing AI agent activity: structured logs for credential access

Comments
2 min read
AI Made Bugs Cheap to Find

AI Made Bugs Cheap to Find

Comments 1
6 min read
OAuth device flow explained: how CLIs and AI agents approve access

OAuth device flow explained: how CLIs and AI agents approve access

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.