DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
How Attackers Exploit Trust Signals Like HTTPS and UI Design

How Attackers Exploit Trust Signals Like HTTPS and UI Design

Comments
10 min read
GHSA-XJVP-7243-RG9H: GHSA-xjvp-7243-rg9h: Critical Path Traversal in Wish SCP Middleware Allows Arbitrary File Read/Write

GHSA-XJVP-7243-RG9H: GHSA-xjvp-7243-rg9h: Critical Path Traversal in Wish SCP Middleware Allows Arbitrary File Read/Write

Comments
2 min read
53% of AI Agents Exceed Their Permissions. That's an Architecture Problem.

53% of AI Agents Exceed Their Permissions. That's an Architecture Problem.

Comments
8 min read
MCP security has 4 layers. Most teams have 2.

MCP security has 4 layers. Most teams have 2.

1
Comments
4 min read
Data Privacy in Regulated Applications: What Developers Need to Know

Data Privacy in Regulated Applications: What Developers Need to Know

Comments
7 min read
Your Emails Go to Spam Because of Three DNS Records You Never Set Up

Your Emails Go to Spam Because of Three DNS Records You Never Set Up

Comments
5 min read
CSP for Third Party Scripts: The Practical Cheat Sheet for GA, Stripe, Intercom, and More

CSP for Third Party Scripts: The Practical Cheat Sheet for GA, Stripe, Intercom, and More

1
Comments
6 min read
We Had Secrets in Kubernetes. Then We Got Audited.

We Had Secrets in Kubernetes. Then We Got Audited.

1
Comments
6 min read
IDOR in AI-Generated APIs: What Cursor Won't Check for You

IDOR in AI-Generated APIs: What Cursor Won't Check for You

3
Comments 2
3 min read
CNAPP pricing teardown: why Indian mid-market rejects Wiz, Orca, and Prisma Cloud (and what they buy instead)

CNAPP pricing teardown: why Indian mid-market rejects Wiz, Orca, and Prisma Cloud (and what they buy instead)

Comments
6 min read
IAM Access Analyzer nuked our prod hotfix because I fundamentally misunderstood how Zelkova evaluates wildcards

IAM Access Analyzer nuked our prod hotfix because I fundamentally misunderstood how Zelkova evaluates wildcards

Comments
2 min read
Letters of Marque for AI Agents: The 600-Year Authorization Architecture You're Reinventing

Letters of Marque for AI Agents: The 600-Year Authorization Architecture You're Reinventing

1
Comments
3 min read
How I Mastered Foundry and Earned My 101 Badge: A Journey into Web3 Security

How I Mastered Foundry and Earned My 101 Badge: A Journey into Web3 Security

Comments
2 min read
The Vercel April 2026 Security Incident: What Every Developer Actually Needs to Know

The Vercel April 2026 Security Incident: What Every Developer Actually Needs to Know

Comments
6 min read
The State of Package Health: Weekly Report #002

The State of Package Health: Weekly Report #002

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.