DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Drift Protocol $285M Exploit - North Korean APT Attack on Solana

Drift Protocol $285M Exploit - North Korean APT Attack on Solana

Comments
4 min read
Securing PostgreSQL, in the order an attacker would try things

Securing PostgreSQL, in the order an attacker would try things

1
Comments
7 min read
Everything's Green Cap.

Everything's Green Cap.

Comments
2 min read
The Security Risk of 'npm install': Why We Built Our UI with Zero Component Libraries

The Security Risk of 'npm install': Why We Built Our UI with Zero Component Libraries

5
Comments
2 min read
Applying Checkov to Terraform as Code: A TFSEC Alternative

Applying Checkov to Terraform as Code: A TFSEC Alternative

Comments
3 min read
I benchmarked Python AI-app security scanners. Here's what each catches.

I benchmarked Python AI-app security scanners. Here's what each catches.

1
Comments
3 min read
OAuth2 + OpenID Connect in Spring Boot: A Practical Guide for Java Backend Engineers

OAuth2 + OpenID Connect in Spring Boot: A Practical Guide for Java Backend Engineers

Comments
5 min read
The Website Was Working Fine. The CMS Wasn't: Understanding Drupalgeddon2

The Website Was Working Fine. The CMS Wasn't: Understanding Drupalgeddon2

Comments
3 min read
HIPAA Risk Assessment in 2026: A Healthcare Engineer's Field Guide

HIPAA Risk Assessment in 2026: A Healthcare Engineer's Field Guide

Comments
4 min read
The Map Is Not the Territory — Dep-Aware Agent Between Explorer and Builder

The Map Is Not the Territory — Dep-Aware Agent Between Explorer and Builder

Comments
5 min read
401 Unauthorized Error: Causes and Solutions

401 Unauthorized Error: Causes and Solutions

Comments
4 min read
I claimed an auth bypass in a Next.js LLM proxy. The maintainer refuted in 3 hours with code. I conceded. He closed it cleanly.

I claimed an auth bypass in a Next.js LLM proxy. The maintainer refuted in 3 hours with code. I conceded. He closed it cleanly.

Comments
6 min read
My one-line installer would run anything it downloaded over 500 bytes

My one-line installer would run anything it downloaded over 500 bytes

Comments
4 min read
Securely Exposing Internal GCP VMs using Cloudflare Tunnels

Securely Exposing Internal GCP VMs using Cloudflare Tunnels

5
Comments
5 min read
One Vulnerable Parameter, Full Server Access: Understanding the Webmin Command Injection Vulnerability

One Vulnerable Parameter, Full Server Access: Understanding the Webmin Command Injection Vulnerability

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.