DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
User Enumeration: How One Leaky Error Message Lets Attackers Find Valid Usernames and Crack Your Passwords

User Enumeration: How One Leaky Error Message Lets Attackers Find Valid Usernames and Crack Your Passwords

Comments
3 min read
The Identity Gap in Agentic AI

The Identity Gap in Agentic AI

Comments
4 min read
Hardening an Express API: URL Validation, Error Handling, and Tests in One Session

Hardening an Express API: URL Validation, Error Handling, and Tests in One Session

Comments
2 min read
I Ran My ML Secrets Detector Against My Own Repositories — Here's What It Found

I Ran My ML Secrets Detector Against My Own Repositories — Here's What It Found

Comments
10 min read
Gmail OAuth client_id is not a secret â design notes for self-host Actors

Gmail OAuth client_id is not a secret â design notes for self-host Actors

Comments
5 min read
APPROVED_SPENDERS Policy: Control Which Contracts Your AI Agent Can Approve

APPROVED_SPENDERS Policy: Control Which Contracts Your AI Agent Can Approve

Comments
4 min read
AI Agents Are Your Enterprise's Newest Security Blind Spot

AI Agents Are Your Enterprise's Newest Security Blind Spot

Comments
4 min read
The Compliance Case for Machine Identity

The Compliance Case for Machine Identity

Comments
4 min read
I just hardened my OSS release pipeline to 11 layers of security — here's the playbook

I just hardened my OSS release pipeline to 11 layers of security — here's the playbook

Comments
7 min read
Automated Advanced Analytics: An Unexpected Tool in the Cyber Arsenal

Automated Advanced Analytics: An Unexpected Tool in the Cyber Arsenal

Comments 1
2 min read
Building HIPAA-Compliant Healthcare Software: Lessons from PSI Nest

Building HIPAA-Compliant Healthcare Software: Lessons from PSI Nest

Comments
2 min read
AI & Supply Chain Security: Prompt Injection Suite, Nginx CVE, & Rockstar Breach

AI & Supply Chain Security: Prompt Injection Suite, Nginx CVE, & Rockstar Breach

Comments
3 min read
How I Built a 3-Tier Approval Engine with Spring Boot and Spring Security

How I Built a 3-Tier Approval Engine with Spring Boot and Spring Security

1
Comments 1
5 min read
When a Git Branch Name Becomes a Weapon: The Codex Command Injection That Could Steal Your GitHub Token

When a Git Branch Name Becomes a Weapon: The Codex Command Injection That Could Steal Your GitHub Token

Comments
6 min read
Multi-Tenant AI Agent Architectures: Isolation, Routing, and Data Safety

Multi-Tenant AI Agent Architectures: Isolation, Routing, and Data Safety

1
Comments
13 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.