DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Passkeys Explained Simply

Comments warn account recovery is the weak link

Passkeys Explained Simply

112
Comments 34
6 min read
Never Let the Model Pick the Tenant ID: Securing an LLM Agent in Go

Never Let the Model Pick the Tenant ID: Securing an LLM Agent in Go

1
Comments
10 min read
L1.9: I built a prompt injection firewall for AI agents (28 detection rules)

L1.9: I built a prompt injection firewall for AI agents (28 detection rules)

Comments 1
2 min read
Dagster AuthKit v0.4.0 - Security Hardening, Cross-Pod Sessions, and We Need Your Help

Dagster AuthKit v0.4.0 - Security Hardening, Cross-Pod Sessions, and We Need Your Help

Comments
4 min read
CISA rewrote how the US government handles dying software — twice this year

CISA rewrote how the US government handles dying software — twice this year

1
Comments
3 min read
Prompt Injection for API Teams: What It Is and How to Test for It

Prompt Injection for API Teams: What It Is and How to Test for It

1
Comments
12 min read
The CISO Doesn't Read Your CLI Output

The CISO Doesn't Read Your CLI Output

2
Comments
7 min read
SQLAlchemy ORM Security: The Raw Query Escape Hatch

SQLAlchemy ORM Security: The Raw Query Escape Hatch

Comments
5 min read
Agentic Code Security: What Autonomous AI Gets Wrong

Agentic Code Security: What Autonomous AI Gets Wrong

Comments
6 min read
I Built a Free Privacy-First Developer Toolkit - No Data Leaves Your Browser

I Built a Free Privacy-First Developer Toolkit - No Data Leaves Your Browser

Comments
2 min read
A letter that walks your network for you: reproducing a fresh Roundcube SSRF on a live lab

A letter that walks your network for you: reproducing a fresh Roundcube SSRF on a live lab

Comments
10 min read
API Key Hygiene: Scopes, Expiry, Rotation and 2FA

API Key Hygiene: Scopes, Expiry, Rotation and 2FA

5
Comments
6 min read
JWT Malformed, Invalid Signature, or Expired? A Practical Debugging Checklist

JWT Malformed, Invalid Signature, or Expired? A Practical Debugging Checklist

1
Comments
3 min read
Build-scanner — a zero-config static scanner for SQLi, NoSQLi, CORS, CSP & CSRF in React/Node apps (pre-release)

Build-scanner — a zero-config static scanner for SQLi, NoSQLi, CORS, CSP & CSRF in React/Node apps (pre-release)

1
Comments
1 min read
No Human at the Keyboard: OpenAI's Models Escaped Their Sandbox and Hacked Hugging Face to Cheat a Benchmark

No Human at the Keyboard: OpenAI's Models Escaped Their Sandbox and Hacked Hugging Face to Cheat a Benchmark

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.