DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
How I Stopped wp-blog-header.php Regenerate Malware in WordPress After Wordfence Missed the Real Cause

How I Stopped wp-blog-header.php Regenerate Malware in WordPress After Wordfence Missed the Real Cause

Comments
7 min read
AI Writes Your Code. Who Is Accountable?

AI Writes Your Code. Who Is Accountable?

Comments
4 min read
Why AI Agents Need Their Own Authorization Protocol (and How We Built One)

Why AI Agents Need Their Own Authorization Protocol (and How We Built One)

Comments
3 min read
JWT Token Explained: How to Decode, Debug, and Secure Your Tokens

JWT Token Explained: How to Decode, Debug, and Secure Your Tokens

Comments 1
1 min read
I Spent a Week Securing Webhook Ingestion. The Real Attack Surface Was Delivery.

I Spent a Week Securing Webhook Ingestion. The Real Attack Surface Was Delivery.

1
Comments
6 min read
3 Auth Bugs Cursor Keeps Writing Into Your API Endpoints

3 Auth Bugs Cursor Keeps Writing Into Your API Endpoints

1
Comments
3 min read
I Thought the Hard Part Was the Code. Turns Out Production Is Where Security Assumptions Go to Die.

Rate limits, SMTP, and Docker build tips

I Thought the Hard Part Was the Code. Turns Out Production Is Where Security Assumptions Go to Die.

9
Comments 18
10 min read
Multi-Agent Systems Are Undeployable in Enterprise Without This Trust Layer

Multi-Agent Systems Are Undeployable in Enterprise Without This Trust Layer

Comments
5 min read
Five Things That Go Wrong When AI Agents Hold API Keys

Five Things That Go Wrong When AI Agents Hold API Keys

6
Comments 2
3 min read
Why your AI agent is vulnerable to prompt injection (and how to fix it in 3 lines)

Why your AI agent is vulnerable to prompt injection (and how to fix it in 3 lines)

Comments 1
2 min read
The hidden security cost of AI-generated code (and what to do about it)

The hidden security cost of AI-generated code (and what to do about it)

Comments
8 min read
Docker Security Best Practices for Self-Hosters in 2026

Docker Security Best Practices for Self-Hosters in 2026

2
Comments
12 min read
Why Developers Are Bad at Securing Their Own API Keys

Why Developers Are Bad at Securing Their Own API Keys

Comments
3 min read
Zero Token Architecture: Why Your AI Agent Should Never See Your Real API Key

Zero Token Architecture: Why Your AI Agent Should Never See Your Real API Key

Comments
4 min read
Web Crypto API — Hash Anything in the Browser Without npm Packages

Web Crypto API — Hash Anything in the Browser Without npm Packages

Comments
1 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.