DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
23% of Public APIs Have CORS Misconfigurations — Here's How to Fix Yours

23% of Public APIs Have CORS Misconfigurations — Here's How to Fix Yours

Comments
3 min read
Your AI-Generated Code Has 3x More Vulnerabilities Than Human-Written Code

Your AI-Generated Code Has 3x More Vulnerabilities Than Human-Written Code

Comments
4 min read
GitHub Has a Secret Security API — Scan Any Repo for Vulnerabilities in 30 Seconds

GitHub Has a Secret Security API — Scan Any Repo for Vulnerabilities in 30 Seconds

Comments
4 min read
The npm Registry Has 2 Million Packages — 14% Have Known Vulnerabilities

The npm Registry Has 2 Million Packages — 14% Have Known Vulnerabilities

Comments
3 min read
5 MCP Servers for Agent Identity — And Why the Problem Is Harder Than Any of Them Solve

5 MCP Servers for Agent Identity — And Why the Problem Is Harder Than Any of Them Solve

1
Comments
2 min read
I Found 47 Exposed .env Files on GitHub in 10 Minutes — Here's What Was Inside

I Found 47 Exposed .env Files on GitHub in 10 Minutes — Here's What Was Inside

Comments
5 min read
How I Built a Secure Reverse Proxy with Nginx

How I Built a Secure Reverse Proxy with Nginx

Comments
3 min read
I Built a Free API Vulnerability Scanner — It Found 23 Issues in My Own Code

I Built a Free API Vulnerability Scanner — It Found 23 Issues in My Own Code

Comments
5 min read
Your .env File Is Probably in Your Git History (Here's How to Check)

Your .env File Is Probably in Your Git History (Here's How to Check)

Comments
4 min read
The 5 Security Holes in Almost Every MCP Server (And How to Find Them)

The 5 Security Holes in Almost Every MCP Server (And How to Find Them)

Comments
3 min read
A Deny Read Bug in Claude Code's Bubblewrap Sandbox

A Deny Read Bug in Claude Code's Bubblewrap Sandbox

1
Comments
2 min read
Is Your Crypto Bounty Token a Security? A Developer's Guide to the Howey Test

Is Your Crypto Bounty Token a Security? A Developer's Guide to the Howey Test

1
Comments
8 min read
I built a CI/CD tool that auto-heals broken pipelines, runs 6 security scans, and works from your IDE via MCP

I built a CI/CD tool that auto-heals broken pipelines, runs 6 security scans, and works from your IDE via MCP

1
Comments
2 min read
SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

Comments
3 min read
hash23 - A constexpr implementation of different hashing algorithms

hash23 - A constexpr implementation of different hashing algorithms

2
Comments
1 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.