DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Building Role-Based Access Control for Enterprise Systems: Lessons from Banking Software

Building Role-Based Access Control for Enterprise Systems: Lessons from Banking Software

2
Comments 2
6 min read
Rebuilding a HIPAA CI/CD pipeline: signed promotion, OPA admission, and audit-grade evidence

Rebuilding a HIPAA CI/CD pipeline: signed promotion, OPA admission, and audit-grade evidence

Comments
5 min read
Katana BadUSB Exploit, VSCode GitHub Token Stealing, and mimalloc Hardening

Katana BadUSB Exploit, VSCode GitHub Token Stealing, and mimalloc Hardening

Comments
3 min read
SQL Injection Basics: My First Experience Testing SQLi in Real Applications

SQL Injection Basics: My First Experience Testing SQLi in Real Applications

Comments
3 min read
Differential Testing Revealed What Conformance Testing Missed: A Case Study with Open-Source eMRTD Libraries

Differential Testing Revealed What Conformance Testing Missed: A Case Study with Open-Source eMRTD Libraries

2
Comments 3
7 min read
Check If a Password Was Breached Without Sending It (HIBP k-Anonymity)

Check If a Password Was Breached Without Sending It (HIBP k-Anonymity)

5
Comments 1
4 min read
Startup Security Guide & LLM CISO

Startup Security Guide & LLM CISO

3
Comments 1
11 min read
A Deep Dive into Cleaning Persistent WordPress Malware and Hardening the REST API

A Deep Dive into Cleaning Persistent WordPress Malware and Hardening the REST API

Comments
5 min read
CSIRT: O Time Que Transforma Incidente Em Controle

CSIRT: O Time Que Transforma Incidente Em Controle

Comments
5 min read
Giving LLMs access to a bash terminal is terrifying

Giving LLMs access to a bash terminal is terrifying

1
Comments 1
5 min read
My menu bar clock disappeared after a macOS update. I wrote a 50-line VS Code extension instead of trusting a marketplace one.

My menu bar clock disappeared after a macOS update. I wrote a 50-line VS Code extension instead of trusting a marketplace one.

Comments
5 min read
The difference between "this shouldn't happen" and "this cannot happen" in AI content pipelines

The difference between "this shouldn't happen" and "this cannot happen" in AI content pipelines

1
Comments
4 min read
21 SaaS tools that won't sign a HIPAA BAA — at any plan (2026)

21 SaaS tools that won't sign a HIPAA BAA — at any plan (2026)

Comments
3 min read
The Duck Stops Here: Building hid_guard — Catching Keystroke Injection at the Kernel Level

The Duck Stops Here: Building hid_guard — Catching Keystroke Injection at the Kernel Level

7
Comments 4
5 min read
A signed BAA doesn't make your AI feature HIPAA-compliant: the half developers keep skipping

A signed BAA doesn't make your AI feature HIPAA-compliant: the half developers keep skipping

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.