DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I Tried to Poison My Agent's Rule Store. It Produced 20 Triggers. Zero Got In.

I Tried to Poison My Agent's Rule Store. It Produced 20 Triggers. Zero Got In.

13
Comments 1
9 min read
From a Steganography Toolkit to Revealien

From a Steganography Toolkit to Revealien

Comments
1 min read
ShinyHunters Hacks Clop Leak Site: Claims an Unauthenticated File Upload Led to Tor Private Key Theft

ShinyHunters Hacks Clop Leak Site: Claims an Unauthenticated File Upload Led to Tor Private Key Theft

1
Comments
6 min read
The Gemini breakout is a judge problem, not a jailbreak problem

The Gemini breakout is a judge problem, not a jailbreak problem

Comments
5 min read
Security questions every senior backend engineer should handle

Security questions every senior backend engineer should handle

Comments
5 min read
A fake MCP server spent three months earning trust. The tells were there

A fake MCP server spent three months earning trust. The tells were there

1
Comments 14
3 min read
Day 37: The Role Is Not What You Attach, and the Bucket Is Not the Objects

Day 37: The Role Is Not What You Attach, and the Bucket Is Not the Objects

10
Comments
5 min read
Nodos distribuidos a prueba de manipulaciĂłn: Integridad de cĂłdigo SHA-256.

Nodos distribuidos a prueba de manipulaciĂłn: Integridad de cĂłdigo SHA-256.

Comments 1
1 min read
The Gemini breakout verdict has to come from the boundary, not the model's mouth

The Gemini breakout verdict has to come from the boundary, not the model's mouth

1
Comments 1
5 min read
Agent Injection Corpus: instruction/data channel confusion across programming languages. #Astra #Devin

Agent Injection Corpus: instruction/data channel confusion across programming languages. #Astra #Devin

2
Comments 4
2 min read
Capbroker: I gave an AI agent a fake GitHub key, then watched it get tricked into trying to delete a repo anyway

Deterministic brokers stop rogue tool calls

Capbroker: I gave an AI agent a fake GitHub key, then watched it get tricked into trying to delete a repo anyway

4
Comments 14
7 min read
I scanned 55 public Lovable apps — all 55 had a GDPR or security finding

I scanned 55 public Lovable apps — all 55 had a GDPR or security finding

Comments
4 min read
Your AI Agent Is a Confused Deputy

Your AI Agent Is a Confused Deputy

1
Comments 1
5 min read
Observability — Logs, Metrics, Tracing

Observability — Logs, Metrics, Tracing

1
Comments
3 min read
An AI agent is just a while loop. I built one in 70 lines of Python, then tricked it into leaking my .env

Fixing security in runtime code, not prompts

An AI agent is just a while loop. I built one in 70 lines of Python, then tricked it into leaking my .env

33
Picked as gem Comments 23
15 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.