DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Anatomy of a GitHub Actions Supply Chain Attack Targeting MCP Repos

Anatomy of a GitHub Actions Supply Chain Attack Targeting MCP Repos

Comments
7 min read
When Your CI/CD Pipeline Becomes an Agent: Governing AI That Touches IAM

When Your CI/CD Pipeline Becomes an Agent: Governing AI That Touches IAM

Comments
5 min read
AI's Spear and Shield

AI's Spear and Shield

Comments
5 min read
What Wrong API Docs Cost Identity Verification Teams

What Wrong API Docs Cost Identity Verification Teams

1
Comments
5 min read
Malicious `axios@1.14.1` Published: Exfiltrated CI/CD Secrets; Pin Dependency Versions to Mitigate

Malicious `axios@1.14.1` Published: Exfiltrated CI/CD Secrets; Pin Dependency Versions to Mitigate

Comments
12 min read
Node.js 18 is a year past EOL and Node.js 20 just hit EOL — is your stack exposed?

Node.js 18 is a year past EOL and Node.js 20 just hit EOL — is your stack exposed?

1
Comments
2 min read
We scanned 26,302 x402 endpoints. 0.41% implement the protocol correctly.

We scanned 26,302 x402 endpoints. 0.41% implement the protocol correctly.

Comments
3 min read
Building autonomous AI agents is fun. Securing their access in production is a nightmare.

Building autonomous AI agents is fun. Securing their access in production is a nightmare.

Comments
3 min read
I Built a Free Smart Contract Scanner

I Built a Free Smart Contract Scanner

Comments
1 min read
Authenticated, Authorized, and Still Unsafe: The Missing Layer in Agent Security

Authenticated, Authorized, and Still Unsafe: The Missing Layer in Agent Security

Comments
5 min read
Building Safe LangChain Agents with Scope Verification

Building Safe LangChain Agents with Scope Verification

Comments 2
5 min read
TryHackMe — Linux Privilege Escalation Writeup

TryHackMe — Linux Privilege Escalation Writeup

Comments
4 min read
Capture and Replay: Testing Security Policy Without Production Risk

Capture and Replay: Testing Security Policy Without Production Risk

Comments
8 min read
Patching the Dead: Why Glasswing Solves Yesterday's Problem with Tomorrow's Tools

Patching the Dead: Why Glasswing Solves Yesterday's Problem with Tomorrow's Tools

Comments
13 min read
Try Hack Me — File Inclusion

Try Hack Me — File Inclusion

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.