DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Your AI Coding Agent Has Access to Your SSH Keys Right Now

Your AI Coding Agent Has Access to Your SSH Keys Right Now

Comments
3 min read
Find Plaintext Secrets Hiding in Your .env Files

Find Plaintext Secrets Hiding in Your .env Files

Comments
4 min read
The Foom Cash Exploit: How a Skipped CLI Step in a Groth16 Trusted Setup Turned a $2.3M Privacy Protocol Into an ATM

The Foom Cash Exploit: How a Skipped CLI Step in a Groth16 Trusted Setup Turned a $2.3M Privacy Protocol Into an ATM

1
Comments
5 min read
Calldata Injection: The $17M Vulnerability Pattern Hiding in Every DeFi Router

Calldata Injection: The $17M Vulnerability Pattern Hiding in Every DeFi Router

Comments
6 min read
The Phantom Challenge: How a Missing Hash Input in Solana's ZK Proofs Could Have Minted Unlimited Tokens

The Phantom Challenge: How a Missing Hash Input in Solana's ZK Proofs Could Have Minted Unlimited Tokens

Comments
5 min read
The Step Finance Autopsy: Why $27M in Audited Contracts Died From a Phishing Email

The Step Finance Autopsy: Why $27M in Audited Contracts Died From a Phishing Email

Comments
7 min read
How to Scan File Uploads in Express

How to Scan File Uploads in Express

1
Comments
6 min read
I Built a Clipboard Manager for Linux with AES-256 Encryption — DotGhostBoard v1.4.0 Eclipse

I Built a Clipboard Manager for Linux with AES-256 Encryption — DotGhostBoard v1.4.0 Eclipse

3
Comments
9 min read
The Litellm Supply Chain Attack: What Developers Need to Know About Package Security

The Litellm Supply Chain Attack: What Developers Need to Know About Package Security

Comments
3 min read
We Stopped Bolting Security onto MCP. We Built It In.

We Stopped Bolting Security onto MCP. We Built It In.

Comments
5 min read
NH:STA S01E01 Sequoia-PGP

NH:STA S01E01 Sequoia-PGP

1
Comments
3 min read
How to Implement HMAC Request Signing for Secure API Authentication in Node.js (2026 Guide)

How to Implement HMAC Request Signing for Secure API Authentication in Node.js (2026 Guide)

Comments
8 min read
The LiteLLM Attack Exposed a Bigger Problem: Your Vibe-Coded App Probably Has the Same Vulnerabilities

The LiteLLM Attack Exposed a Bigger Problem: Your Vibe-Coded App Probably Has the Same Vulnerabilities

Comments
4 min read
I scanned Google.com for quantum vulnerabilities — they're already deploying post-quantum crypto (but it's not enough)

I scanned Google.com for quantum vulnerabilities — they're already deploying post-quantum crypto (but it's not enough)

1
Comments
1 min read
EVMbench: OpenAI and Paradigm's New Benchmark Proves AI Agents Can Exploit 71% of Smart Contract Vulns

EVMbench: OpenAI and Paradigm's New Benchmark Proves AI Agents Can Exploit 71% of Smart Contract Vulns

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.