DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Stop Feeding Copilot Everything: Where ‘Bring Your Own Data’ Should Have Hard Limits

Stop Feeding Copilot Everything: Where ‘Bring Your Own Data’ Should Have Hard Limits

Comments
7 min read
🕵️‍♂️ Dependencies Should Not Be Silent: Inspect What Your npm Packages Actually Do

🕵️‍♂️ Dependencies Should Not Be Silent: Inspect What Your npm Packages Actually Do

1
Comments
3 min read
Your MCP Agents Are Over-Privileged. Here's How to Fix It.

Your MCP Agents Are Over-Privileged. Here's How to Fix It.

1
Comments
9 min read
AI agents can run shell commands — how do you prove what actually happened?

AI agents can run shell commands — how do you prove what actually happened?

Comments
3 min read
The Moonwell Oracle Exploit: How AI-Generated Code Created a $1.78M Pricing Bug That Bots Exploited in Minutes

The Moonwell Oracle Exploit: How AI-Generated Code Created a $1.78M Pricing Bug That Bots Exploited in Minutes

1
Comments
7 min read
How Android Actually Protects Data Stored on Your Device

How Android Actually Protects Data Stored on Your Device

2
Comments
3 min read
I Kept Auditing OpenClaw on AWS Lightsail: 53 Default Skills, No Channel Access Controls, Deletable Logs (Part 2)

I Kept Auditing OpenClaw on AWS Lightsail: 53 Default Skills, No Channel Access Controls, Deletable Logs (Part 2)

3
Comments
10 min read
🚨 The "Skynet" Social Network Was a Security Nightmare: Why Meta Really Bought Moltbook

🚨 The "Skynet" Social Network Was a Security Nightmare: Why Meta Really Bought Moltbook

Comments
4 min read
Files Are the New API — But Who's Checking the Files?

Files Are the New API — But Who's Checking the Files?

Comments
4 min read
I'm an AI Agent. Here's How I'm Hardcoded to NOT Destroy Your Production.

I'm an AI Agent. Here's How I'm Hardcoded to NOT Destroy Your Production.

Comments
5 min read
OpenClaw npm Malware: Fake Package Deploys GhostLoader RAT

OpenClaw npm Malware: Fake Package Deploys GhostLoader RAT

1
Comments
2 min read
How I Audit 200+ Dependencies in 5 Minutes (Free Tools Only)

How I Audit 200+ Dependencies in 5 Minutes (Free Tools Only)

Comments
4 min read
What Is a "Cyber Ninja"? — The World of Full-Stack Hacking

What Is a "Cyber Ninja"? — The World of Full-Stack Hacking

1
Comments
4 min read
Your AI Agent Has No Identity. Here's a One-Liner Fix.

Your AI Agent Has No Identity. Here's a One-Liner Fix.

Comments
3 min read
I Scanned 1,000 GitHub Actions Workflows — 40% Had Security Issues

I Scanned 1,000 GitHub Actions Workflows — 40% Had Security Issues

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.