DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Adding passkey-backed human approval to high-risk MCP actions

Adding passkey-backed human approval to high-risk MCP actions

2
Comments 2
3 min read
Webhook vs polling for SMS verification codes: what actually breaks in production

Webhook vs polling for SMS verification codes: what actually breaks in production

Comments
5 min read
depwarden: npm Supply-Chain Scanning That Includes AI Agent Config

depwarden: npm Supply-Chain Scanning That Includes AI Agent Config

2
Comments
2 min read
Adding Optional Google Sign-In to a Browser-Based Image Converter

Adding Optional Google Sign-In to a Browser-Based Image Converter

Comments
3 min read
Proving Zero Trust Actually Works: Entra ID + Cloudflare Access over Both OIDC and SAML

Proving Zero Trust Actually Works: Entra ID + Cloudflare Access over Both OIDC and SAML

Comments
5 min read
Kestrel: the Active Directory audit that reads what the graph can’t see

Kestrel: the Active Directory audit that reads what the graph can’t see

Comments
1 min read
My AI agent tried to delete my secrets. It couldn't.

My AI agent tried to delete my secrets. It couldn't.

1
Comments
9 min read
Reducing Browser Fingerprint Detection Starts With Consistency

Reducing Browser Fingerprint Detection Starts With Consistency

Comments
5 min read
I'm 15 and I built "OAuth for AI subscriptions". Here's the full architecture

I'm 15 and I built "OAuth for AI subscriptions". Here's the full architecture

7
Comments 2
4 min read
Exploited at CVSS 10.0 - And the Vendor Never Checked Whether EOL Versions Are Affected

Exploited at CVSS 10.0 - And the Vendor Never Checked Whether EOL Versions Are Affected

1
Comments
4 min read
What 78K attack samples taught me about catching prompt injection

What 78K attack samples taught me about catching prompt injection

Comments
2 min read
What I learned wiring an AI agent fleet into self-hosted SigNoz

What I learned wiring an AI agent fleet into self-hosted SigNoz

Comments 1
5 min read
The Path Traversal Fix Cursor Writes Ignores Symlinks (CWE-22)

The Path Traversal Fix Cursor Writes Ignores Symlinks (CWE-22)

1
Comments
7 min read
100 Days of DevOps and Cloud (AWS), Day 18: MariaDB's Secure Install, and Why 'Read-Only' Needs More Than ec2:Describe

100 Days of DevOps and Cloud (AWS), Day 18: MariaDB's Secure Install, and Why 'Read-Only' Needs More Than ec2:Describe

6
Comments
3 min read
What a successful HMAC check tells you about webhook forwarding

What a successful HMAC check tells you about webhook forwarding

1
Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.