DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Treat AI-Suggested Shell Commands Like a Merge Request, Not a Copy-Paste

Treat AI-Suggested Shell Commands Like a Merge Request, Not a Copy-Paste

Comments
5 min read
Designing a Privacy-Safe Gift Card Image Submission Pipeline

Designing a Privacy-Safe Gift Card Image Submission Pipeline

Comments
8 min read
Multidisipliner Bir Yaklaşım: Linux Sistem Güvenliğinde 'Maker' Bakış Açısı

Multidisipliner Bir Yaklaşım: Linux Sistem Güvenliğinde 'Maker' Bakış Açısı

1
Comments
3 min read
How to Build a Minimal SIEM with Python, SQLite and Telegram Alerts

How to Build a Minimal SIEM with Python, SQLite and Telegram Alerts

2
Comments
5 min read
How a database password ends up in git history, and why rotating it is not enough

How a database password ends up in git history, and why rotating it is not enough

8
Comments
4 min read
How to Give AI Better Evidence: Lessons From a Security Investigation That Almost Failed

How to Give AI Better Evidence: Lessons From a Security Investigation That Almost Failed

Comments
6 min read
Secrets management that developers do not route around

Secrets management that developers do not route around

Comments
6 min read
We let an autonomous agent spend real money for a week. The first thing I added wasn't a feature — it was a spending firewall.

We let an autonomous agent spend real money for a week. The first thing I added wasn't a feature — it was a spending firewall.

Comments 3
1 min read
Three agent message boards found mine overnight. They all asked the same question in a different way.

Three agent message boards found mine overnight. They all asked the same question in a different way.

4
Comments 1
6 min read
One Ciphertext, Two Valid Plaintexts: Why AEAD Needs Key Commitment

One Ciphertext, Two Valid Plaintexts: Why AEAD Needs Key Commitment

Comments
5 min read
Catching "invoice.pdf.exe" before you open it: a tool that identifies a file's real type from its first bytes

Catching "invoice.pdf.exe" before you open it: a tool that identifies a file's real type from its first bytes

Comments 4
21 min read
Machine-Speed Credential Abuse: What the ChainDrop npm Worm Changes

Machine-Speed Credential Abuse: What the ChainDrop npm Worm Changes

Comments 2
9 min read
Content Security Policy in the Next.js App Router: Field Notes on Nonces, strict-dynamic, and the Middleware That Made Every Page Dynamic

Content Security Policy in the Next.js App Router: Field Notes on Nonces, strict-dynamic, and the Middleware That Made Every Page Dynamic

Comments
8 min read
Use 1Password service accounts for automation, not shared logins

Use 1Password service accounts for automation, not shared logins

Comments
4 min read
Fail-closed npm and PyPI vulnerability checks in n8n

Fail-closed npm and PyPI vulnerability checks in n8n

Comments
2 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.