DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
🚨 ClawdBot (Moltbot): Powerful AI Agents, Real Automation… and Real Risks

🚨 ClawdBot (Moltbot): Powerful AI Agents, Real Automation… and Real Risks

Comments
3 min read
Clickjacking — when your users click things they never meant to

Clickjacking — when your users click things they never meant to

1
Comments
1 min read
Gerenciamento de Atualizações e Evolução Contínua de Software com IA

Gerenciamento de Atualizações e Evolução Contínua de Software com IA

Comments
15 min read
OWASP Top 10 – A04: Insecure Design (Remediation Perspective)

OWASP Top 10 – A04: Insecure Design (Remediation Perspective)

Comments
2 min read
Don’t Trust Your Agents. Trust Your Boundary: a runtime authorization layer for LLM tool calls.

Don’t Trust Your Agents. Trust Your Boundary: a runtime authorization layer for LLM tool calls.

Comments
6 min read
CVE-2024-4990: Magic Methods, Tragic Endings: RCE in Yii2 via Unsafe Reflection

CVE-2024-4990: Magic Methods, Tragic Endings: RCE in Yii2 via Unsafe Reflection

Comments
2 min read
CVE-2025-54997: The Janitor's Key: Turning OpenBao Audit Logs into RCE

CVE-2025-54997: The Janitor's Key: Turning OpenBao Audit Logs into RCE

Comments
2 min read
CVE-2026-22785: Orval Overload: From OpenAPI Spec to Remote Code Execution

CVE-2026-22785: Orval Overload: From OpenAPI Spec to Remote Code Execution

Comments
2 min read
CVE-2026-22817: Identity Theft on the Edge: Exploiting JWT Algorithm Confusion in Hono

CVE-2026-22817: Identity Theft on the Edge: Exploiting JWT Algorithm Confusion in Hono

Comments
2 min read
GHSA-VX9W-5CX4-9796: Crawl4AI: When Web Scrapers Become File Servers

GHSA-VX9W-5CX4-9796: Crawl4AI: When Web Scrapers Become File Servers

Comments
2 min read
CVE-2026-23996: The Tell-Tale Delay: Timing Side-Channels in fastapi-api-key

CVE-2026-23996: The Tell-Tale Delay: Timing Side-Channels in fastapi-api-key

Comments
2 min read
GHSA-F2MF-Q878-GH58: Parsl Tongue: SQL Injection in High-Performance Computing Visualization

GHSA-F2MF-Q878-GH58: Parsl Tongue: SQL Injection in High-Performance Computing Visualization

Comments
2 min read
CVE-2026-21441: The Invisible Avalanche: urllib3 Decompression Bomb

CVE-2026-21441: The Invisible Avalanche: urllib3 Decompression Bomb

Comments
2 min read
GHSA-RHFX-M35P-FF5J: Borrow Checker's Revenge: Stacked Borrows Violation in Rust's `lru` Crate

GHSA-RHFX-M35P-FF5J: Borrow Checker's Revenge: Stacked Borrows Violation in Rust's `lru` Crate

Comments
2 min read
CVE-2025-32444: Pickle Rick-Roll: Critical RCE in vLLM's Mooncake Integration

CVE-2025-32444: Pickle Rick-Roll: Critical RCE in vLLM's Mooncake Integration

Comments
2 min read
CVE-2026-22200: Paper Cuts to Pwnage: Turning osTicket PDF Exports into RCE

CVE-2026-22200: Paper Cuts to Pwnage: Turning osTicket PDF Exports into RCE

Comments
2 min read
CVE-2026-22708: Trust Issues: Bypassing Cursor AI's 'Safe Mode' via Shell Built-ins

CVE-2026-22708: Trust Issues: Bypassing Cursor AI's 'Safe Mode' via Shell Built-ins

Comments
2 min read
CVE-2025-61984: Bash a Newline: The SSH ProxyCommand RCE You Didn't Know You Had

CVE-2025-61984: Bash a Newline: The SSH ProxyCommand RCE You Didn't Know You Had

Comments
2 min read
CVE-2026-23498: Shopware 6: Mapping Your Way to RCE via Twig Type Juggling

CVE-2026-23498: Shopware 6: Mapping Your Way to RCE via Twig Type Juggling

Comments
2 min read
How AI Agents Get Hacked Through Their Own Memories

How AI Agents Get Hacked Through Their Own Memories

Comments
6 min read
Modeling identity and access hierarchy in Postgres with ltree

Modeling identity and access hierarchy in Postgres with ltree

Comments
7 min read
Building Cryptographically Secure Random Number Generators for High-Stakes Distributed Systems

Building Cryptographically Secure Random Number Generators for High-Stakes Distributed Systems

Comments
7 min read
Tu Nube como una Base de Datos: Guía Práctica de Steampipe para AWS

Tu Nube como una Base de Datos: Guía Práctica de Steampipe para AWS

Comments
4 min read
CVE-2025-66648: Vega's Visual Betrayal: Leaking the Window via Internal Functions

CVE-2025-66648: Vega's Visual Betrayal: Leaking the Window via Internal Functions

Comments
2 min read
CVE-2026-24785: The Sound of Silence: Breaking Clatter's Post-Quantum Promises (CVE-2026-24785)

CVE-2026-24785: The Sound of Silence: Breaking Clatter's Post-Quantum Promises (CVE-2026-24785)

Comments
2 min read
loading...