DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Why CVE-2026-67277 Reached the CISA KEV Catalog So Fast

Why CVE-2026-67277 Reached the CISA KEV Catalog So Fast

Comments
3 min read
CVE-2026-67277 and the MikroTrick Chain: When Two Flaws Become One Attack

CVE-2026-67277 and the MikroTrick Chain: When Two Flaws Become One Attack

Comments
3 min read
I've Been Using XopProtector for a While — Here's What I Found About Compatibility

I've Been Using XopProtector for a While — Here's What I Found About Compatibility

Comments
6 min read
MikroTik RouterOS CVE-2026-67277: A Defender's Detection and Response Playbook

MikroTik RouterOS CVE-2026-67277: A Defender's Detection and Response Playbook

Comments
4 min read
Building a 19D Kinematic Biometrics Engine for Bot Mitigation in FastAPI

Building a 19D Kinematic Biometrics Engine for Bot Mitigation in FastAPI

1
Comments
3 min read
Keep Free-Lane Diffs Off the Schema Lock

Keep Free-Lane Diffs Off the Schema Lock

Comments
8 min read
What Is a Confused Deputy? How Can a Trusted Program Be Tricked Into Using Its Own Permissions?

What Is a Confused Deputy? How Can a Trusted Program Be Tricked Into Using Its Own Permissions?

1
Comments
5 min read
239,093 NetScaler Deployments in View: Measuring the Citrix Edge After CVE-2026-19490

239,093 NetScaler Deployments in View: Measuring the Citrix Edge After CVE-2026-19490

Comments
4 min read
The Advisory That Was Not a Patch: Reading AA26-231A and the AI-Assisted Reconnaissance of Siemens S7 PLCs

The Advisory That Was Not a Patch: Reading AA26-231A and the AI-Assisted Reconnaissance of Siemens S7 PLCs

Comments
5 min read
When an Authentication Filter Reads the URL Instead of the Route: Lessons from CVE-2026-49869 in Kestra

When an Authentication Filter Reads the URL Instead of the Route: Lessons from CVE-2026-49869 in Kestra

Comments
4 min read
ProfessorOS

ProfessorOS

Comments
3 min read
When the Default Configuration Is the Vulnerability: JFrog Artifactory's Empty Join Key and the Supply-Chain Blast Radius

When the Default Configuration Is the Vulnerability: JFrog Artifactory's Empty Join Key and the Supply-Chain Blast Radius

Comments
4 min read
The credential your record names is not the one that made the call

The credential your record names is not the one that made the call

Comments 7
6 min read
BadHost in the AI Stack: What CVE-2026-48710 Means for FastAPI, vLLM and MCP Gateways

BadHost in the AI Stack: What CVE-2026-48710 Means for FastAPI, vLLM and MCP Gateways

1
Comments
4 min read
CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization

CVE-2026-48710 (BadHost): How a Malformed Host Header Bypasses Starlette Path Authorization

1
Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.