DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Frontend route guards are not authorization

Frontend route guards are not authorization

1
Comments
1 min read
Suffix Matching Is Not Authorization: Lessons from CVE-2026-49869 in Kestra

Suffix Matching Is Not Authorization: Lessons from CVE-2026-49869 in Kestra

Comments
3 min read
I built a small Instagram OSINT checker for public profiles

I built a small Instagram OSINT checker for public profiles

Comments
3 min read
Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

Comments
3 min read
The Offence Is the Listening, Not the Recording: A Real Estate Commission's Own Answer on Cameras During a Showing

The Offence Is the Listening, Not the Recording: A Real Estate Commission's Own Answer on Cameras During a Showing

Comments
9 min read
Layered Abuse Control for Self-Hosted Laravel Admins

Layered Abuse Control for Self-Hosted Laravel Admins

Comments
5 min read
The Management Plane Is the Attack Plane: What Three Clusters on One Cisco FMC Tell Defenders

The Management Plane Is the Attack Plane: What Three Clusters on One Cisco FMC Tell Defenders

Comments
4 min read
The day a script needs changing everywhere

The day a script needs changing everywhere

Comments
6 min read
Exposed GitLab Incoming Email Tokens Allow Unauthorized Code Modifications and CI Execution

Exposed GitLab Incoming Email Tokens Allow Unauthorized Code Modifications and CI Execution

1
Comments 1
8 min read
A package labelled itself "SECURITY RESEARCH." GitHub flagged it as malware anyway.

A package labelled itself "SECURITY RESEARCH." GitHub flagged it as malware anyway.

Comments
4 min read
I'm Building a Post-Quantum Bitcoin in Rust — and a Test Caught a Real Consensus Bug Tonight

I'm Building a Post-Quantum Bitcoin in Rust — and a Test Caught a Real Consensus Bug Tonight

Comments
3 min read
The AI Liability Fight Nobody Wants

The AI Liability Fight Nobody Wants

1
Comments
9 min read
Post-Quantum Cryptography: Separating the Real Deadline from the Marketing Deadline

Post-Quantum Cryptography: Separating the Real Deadline from the Marketing Deadline

Comments
8 min read
Why a licensing API is only half of the product

Why a licensing API is only half of the product

Comments
2 min read
indexed-btree: npm Supply Chain Malware Executes at Runtime and Uses a Smart Contract on Ethereum Sepolia for C2

indexed-btree: npm Supply Chain Malware Executes at Runtime and Uses a Smart Contract on Ethereum Sepolia for C2

1
Comments
8 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.