DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Why Cursor Keeps Writing MD5 Password Hashes (CWE-328)

Why Cursor Keeps Writing MD5 Password Hashes (CWE-328)

1
Comments
3 min read
ForgeRock AM Scripted Decision Node: Production Scripts & Debug Guide

ForgeRock AM Scripted Decision Node: Production Scripts & Debug Guide

Comments
4 min read
Google Cloud Next26:Securing AI

Google Cloud NEXT '26 Challenge Submission

Google Cloud Next26:Securing AI

1
Comments
3 min read
Securing AI Agent Workflows: Preventing Identity Collapse in Multi-Step Chains

Securing AI Agent Workflows: Preventing Identity Collapse in Multi-Step Chains

Comments
9 min read
The TLS Fingerprinting Hell: Why I Stopped Reverse-Engineering the Vinted App

The TLS Fingerprinting Hell: Why I Stopped Reverse-Engineering the Vinted App

Comments
5 min read
Your Agent's Reputation Doesn't Travel. Here's What Does.

Your Agent's Reputation Doesn't Travel. Here's What Does.

Comments
4 min read
Debugging theory solved our security triage problem

Debugging theory solved our security triage problem

Comments
6 min read
Everyone's Sharing Claude Code Skills. Nobody's Checking What's Inside.

Everyone's Sharing Claude Code Skills. Nobody's Checking What's Inside.

Comments
5 min read
How to Safely Allow Inline Scripts Without Breaking Security with CSP Nonce

How to Safely Allow Inline Scripts Without Breaking Security with CSP Nonce

1
Comments
4 min read
Your API Is Leaking Source Fingerprints. Here's How to Stop It.

Your API Is Leaking Source Fingerprints. Here's How to Stop It.

2
Comments
6 min read
nginx-ui's MCP endpoint shipped with 'empty allowlist equals allow-all' — and that's the story worth sitting with

nginx-ui's MCP endpoint shipped with 'empty allowlist equals allow-all' — and that's the story worth sitting with

Comments 3
7 min read
Two-Thirds of AI-Agent Security Incidents Share One Pattern

Two-Thirds of AI-Agent Security Incidents Share One Pattern

1
Comments
8 min read
Protecting Node.js APIs: Audiences, Scopes, and Bearer Tokens

Protecting Node.js APIs: Audiences, Scopes, and Bearer Tokens

Comments
5 min read
The Vercel Breach Began at a Compromised AI Tool. Here's the Lesson.

The Vercel Breach Began at a Compromised AI Tool. Here's the Lesson.

Comments
7 min read
From Promises to Proof: Designing a Defensive Escrow Protocol

From Promises to Proof: Designing a Defensive Escrow Protocol

5
Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.