DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CSIRT: O Time Que Transforma Incidente Em Controle

CSIRT: O Time Que Transforma Incidente Em Controle

Comments
5 min read
path.join() Is Not Path Validation: A Next.js Traversal Walkthrough

path.join() Is Not Path Validation: A Next.js Traversal Walkthrough

Comments
4 min read
21 SaaS tools that won't sign a HIPAA BAA — at any plan (2026)

21 SaaS tools that won't sign a HIPAA BAA — at any plan (2026)

Comments
3 min read
The difference between "this shouldn't happen" and "this cannot happen" in AI content pipelines

The difference between "this shouldn't happen" and "this cannot happen" in AI content pipelines

1
Comments
4 min read
How I Detected Merlin QUIC C2 Traffic Using Entropy and Z-Scores (490K Packets, 0% False Positives)

How I Detected Merlin QUIC C2 Traffic Using Entropy and Z-Scores (490K Packets, 0% False Positives)

1
Comments
10 min read
A signed BAA doesn't make your AI feature HIPAA-compliant: the half developers keep skipping

A signed BAA doesn't make your AI feature HIPAA-compliant: the half developers keep skipping

Comments
5 min read
I extracted an audit log into my SaaS core, and the review caught it logging the wrong thing

I extracted an audit log into my SaaS core, and the review caught it logging the wrong thing

Comments
6 min read
The one HIPAA requirement you can't hand to a vendor: your risk analysis

The one HIPAA requirement you can't hand to a vendor: your risk analysis

Comments
3 min read
Stablecoin Compliance at Scale: A Developer's Guide to Real-Time AML Screening for Crypto Payment Pipelines (2026)

Stablecoin Compliance at Scale: A Developer's Guide to Real-Time AML Screening for Crypto Payment Pipelines (2026)

Comments
3 min read
Stratoclave: a tenant-aware credit gateway for Amazon Bedrock — now with OpenAI codex support

Stratoclave: a tenant-aware credit gateway for Amazon Bedrock — now with OpenAI codex support

Comments
8 min read
Why Most Django Boilerplates Are Insecure by Default

Why Most Django Boilerplates Are Insecure by Default

3
Comments
5 min read
Cloudsec-Audit Python Package

Cloudsec-Audit Python Package

Comments
1 min read
SharePoint silently retired the EnableAzureADB2BIntegration setting in May — and your old guest links break in July

SharePoint silently retired the EnableAzureADB2BIntegration setting in May — and your old guest links break in July

6
Comments
8 min read
I Exposed My API Key Twice Before Building a Proxy — Here's What I Learned

I Exposed My API Key Twice Before Building a Proxy — Here's What I Learned

4
Comments
4 min read
Python obfuscation for AI assistants: runnable workspaces and off-disk secrets

Python obfuscation for AI assistants: runnable workspaces and off-disk secrets

2
Comments
13 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.