DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
How a Fake Job-Interview Repo Tried to Steal My Keys (and How I Caught It)

How a Fake Job-Interview Repo Tried to Steal My Keys (and How I Caught It)

Comments
7 min read
Ley 21.719: el problema no es solo legal, también es arquitectónico

Ley 21.719: el problema no es solo legal, también es arquitectónico

Comments
7 min read
Katana BadUSB Exploit, VSCode GitHub Token Stealing, and mimalloc Hardening

Katana BadUSB Exploit, VSCode GitHub Token Stealing, and mimalloc Hardening

Comments
3 min read
Rebuilding a HIPAA CI/CD pipeline: signed promotion, OPA admission, and audit-grade evidence

Rebuilding a HIPAA CI/CD pipeline: signed promotion, OPA admission, and audit-grade evidence

Comments
5 min read
SQL Injection Basics: My First Experience Testing SQLi in Real Applications

SQL Injection Basics: My First Experience Testing SQLi in Real Applications

Comments
3 min read
Startup Security Guide & LLM CISO

Startup Security Guide & LLM CISO

3
Comments 1
11 min read
A Deep Dive into Cleaning Persistent WordPress Malware and Hardening the REST API

A Deep Dive into Cleaning Persistent WordPress Malware and Hardening the REST API

Comments
5 min read
CSIRT: O Time Que Transforma Incidente Em Controle

CSIRT: O Time Que Transforma Incidente Em Controle

Comments
5 min read
path.join() Is Not Path Validation: A Next.js Traversal Walkthrough

path.join() Is Not Path Validation: A Next.js Traversal Walkthrough

Comments
4 min read
The difference between "this shouldn't happen" and "this cannot happen" in AI content pipelines

The difference between "this shouldn't happen" and "this cannot happen" in AI content pipelines

1
Comments
4 min read
21 SaaS tools that won't sign a HIPAA BAA — at any plan (2026)

21 SaaS tools that won't sign a HIPAA BAA — at any plan (2026)

Comments
3 min read
How I Detected Merlin QUIC C2 Traffic Using Entropy and Z-Scores (490K Packets, 0% False Positives)

How I Detected Merlin QUIC C2 Traffic Using Entropy and Z-Scores (490K Packets, 0% False Positives)

1
Comments
10 min read
A signed BAA doesn't make your AI feature HIPAA-compliant: the half developers keep skipping

A signed BAA doesn't make your AI feature HIPAA-compliant: the half developers keep skipping

Comments
5 min read
I extracted an audit log into my SaaS core, and the review caught it logging the wrong thing

I extracted an audit log into my SaaS core, and the review caught it logging the wrong thing

Comments
6 min read
The one HIPAA requirement you can't hand to a vendor: your risk analysis

The one HIPAA requirement you can't hand to a vendor: your risk analysis

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.