DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
8 Kubernetes Security Misconfigurations That Make It to Production (And How to Fix Them)

8 Kubernetes Security Misconfigurations That Make It to Production (And How to Fix Them)

1
Comments
2 min read
Try to Hack My AI-Agent Workflow: GitHub Issues as a Control Surface

Try to Hack My AI-Agent Workflow: GitHub Issues as a Control Surface

2
Comments
7 min read
I Ran a Subdomain Takeover Checker on GitHub.com and Found a Vulnerable Subdomain

I Ran a Subdomain Takeover Checker on GitHub.com and Found a Vulnerable Subdomain

2
Comments
2 min read
CONTRACT_WHITELIST: Lock Your AI Agent to Pre-Approved Smart Contracts Only

CONTRACT_WHITELIST: Lock Your AI Agent to Pre-Approved Smart Contracts Only

1
Comments
5 min read
Why I built a post-quantum signing API (and why JWT is on borrowed time)

Why I built a post-quantum signing API (and why JWT is on borrowed time)

3
Comments
2 min read
$60K Billed in 13 Hours: Why Leaked Firebase Keys Keep Killing AI-Built Apps

$60K Billed in 13 Hours: Why Leaked Firebase Keys Keep Killing AI-Built Apps

Comments
5 min read
Vercel Hack: Why You Need to Rotate Your "Non-Sensitive" Environment Variables Today

Vercel Hack: Why You Need to Rotate Your "Non-Sensitive" Environment Variables Today

14
Comments 1
2 min read
The First Agent-Centric Cloud Security Platform — And Why We Didn't Build It That Way On Purpose

The First Agent-Centric Cloud Security Platform — And Why We Didn't Build It That Way On Purpose

1
Comments
7 min read
Building a Secure Real-Time Messaging App with .NET 8 and Angular 18

Building a Secure Real-Time Messaging App with .NET 8 and Angular 18

Comments
9 min read
A 300-Line GitHub Actions Security Linter: Five Rules That Catch the CVE Patterns

A 300-Line GitHub Actions Security Linter: Five Rules That Catch the CVE Patterns

Comments
7 min read
npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

npm Supply Chain Audit: The Checklist Most Teams Stop Too Early

Comments
6 min read
Beyond Vibe-Coding: Why we built a "Stripe for App-Security" using LightRAG

Beyond Vibe-Coding: Why we built a "Stripe for App-Security" using LightRAG

Comments 2
2 min read
CVE-2026-34197: el bug de ActiveMQ que vivió 13 años y ahora CISA obliga a parchar

CVE-2026-34197: el bug de ActiveMQ que vivió 13 años y ahora CISA obliga a parchar

Comments
8 min read
I Read the Devenex Launch Yesterday - Here's the Policy File Your Agent Repo Is Still Missing

I Read the Devenex Launch Yesterday - Here's the Policy File Your Agent Repo Is Still Missing

11
Comments 5
4 min read
HTTP desync: el bug que permitió espiar Discord en tiempo real

HTTP desync: el bug que permitió espiar Discord en tiempo real

Comments
9 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.