DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
JSON Web Tokens (JWT): Deep Dive into Design, Security Risks and Real-World Failures

JSON Web Tokens (JWT): Deep Dive into Design, Security Risks and Real-World Failures

Comments
4 min read
7 Open-Source Security Tools Every Developer Ignores (But Shouldn't)

7 Open-Source Security Tools Every Developer Ignores (But Shouldn't)

Comments
6 min read
The Dependency Avalanche: 644 Strangers in Your package.json

The Dependency Avalanche: 644 Strangers in Your package.json

Comments
6 min read
We built 24 apps with AI. Three platforms. 561 vulnerabilities.

We built 24 apps with AI. Three platforms. 561 vulnerabilities.

1
Comments 2
7 min read
Why output-stage PII masking is the wrong protective surface for data exfiltration in RAG

Why output-stage PII masking is the wrong protective surface for data exfiltration in RAG

Comments 2
8 min read
React2Shell (CVE-2025-55182): Exploitation Flow and Secure Coding Lessons

React2Shell (CVE-2025-55182): Exploitation Flow and Secure Coding Lessons

1
Comments
1 min read
PreviewDrop's Privacy Policy Is Live — What It Means for Teams Who Care About Data

PreviewDrop's Privacy Policy Is Live — What It Means for Teams Who Care About Data

Comments
2 min read
Building a DDoS Bouncer: Anomaly Detection with Python & Z-Score

Building a DDoS Bouncer: Anomaly Detection with Python & Z-Score

4
Comments 1
2 min read
I built an open-source dependency intelligence platform in TypeScript — here's how it works

I built an open-source dependency intelligence platform in TypeScript — here's how it works

Comments
3 min read
Stop Using Ad-Heavy Online Text Tools. Build or Use Client-Side Utilities Instead.

Stop Using Ad-Heavy Online Text Tools. Build or Use Client-Side Utilities Instead.

Comments
2 min read
572K Weekly Downloads, One Preinstall Script: The SAP CAP Supply Chain Attack Your AI Agent Would Have Missed

572K Weekly Downloads, One Preinstall Script: The SAP CAP Supply Chain Attack Your AI Agent Would Have Missed

1
Comments
3 min read
GHSA-H829-5CG7-6HFF: GHSA-H829-5CG7-6HFF: Improper Tag Signature Verification in Gitverify

GHSA-H829-5CG7-6HFF: GHSA-H829-5CG7-6HFF: Improper Tag Signature Verification in Gitverify

Comments
2 min read
What Is Agent Reliability Testing?

What Is Agent Reliability Testing?

Comments
9 min read
Two Retailers, One Attack: What Really Decides Who Survives a Breach

Two Retailers, One Attack: What Really Decides Who Survives a Breach

Comments
7 min read
Continuous monitoring caught a credential leak in a published MCP package. Six republishes later, it is still there.

Continuous monitoring caught a credential leak in a published MCP package. Six republishes later, it is still there.

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.