DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

Comments
3 min read
SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

Comments
3 min read
SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

Comments
3 min read
I Built a Supply Chain Scanner for Python — pip Has the Same Problem as npm

I Built a Supply Chain Scanner for Python — pip Has the Same Problem as npm

Comments
3 min read
I Scanned 500 npm Packages for Typosquatting — 23 Were Suspicious

I Scanned 500 npm Packages for Typosquatting — 23 Were Suspicious

Comments
3 min read
LiteLLM PyPI Compromise Is Just the Beginning — How to Audit Your Python Dependencies Right Now

LiteLLM PyPI Compromise Is Just the Beginning — How to Audit Your Python Dependencies Right Now

Comments
4 min read
MP1 Write‑Up – Stack Smashing

MP1 Write‑Up – Stack Smashing

1
Comments
6 min read
Prompt Injection Prevention: Building Secure AI Systems with Claude Code

Prompt Injection Prevention: Building Secure AI Systems with Claude Code

Comments
2 min read
Secure Shibboleth Integration in AKS Migration: Preserving Authentication Workflows and Network Security

Secure Shibboleth Integration in AKS Migration: Preserving Authentication Workflows and Network Security

Comments
15 min read
CVE-2026-28292: How a Simple Case-Sensitivity Bug Turns simple-git Into a Remote Code Execution Weapon (CVSS 9.8)

CVE-2026-28292: How a Simple Case-Sensitivity Bug Turns simple-git Into a Remote Code Execution Weapon (CVSS 9.8)

Comments
4 min read
Stop Claude Code from Hardcoding Secrets: Environment Variables Done Right

Stop Claude Code from Hardcoding Secrets: Environment Variables Done Right

Comments
3 min read
Building a Live Adversarial Arena for AI Safety Testing

Building a Live Adversarial Arena for AI Safety Testing

Comments
4 min read
Mengenal P2P Connector Berbasis Golang di Flowork OS (Bye-Bye Local API Server!)

Mengenal P2P Connector Berbasis Golang di Flowork OS (Bye-Bye Local API Server!)

Comments
4 min read
Claude CodeでAPIキー管理を設計する:スコープ・ローテーション・使用量追跡

Claude CodeでAPIキー管理を設計する:スコープ・ローテーション・使用量追跡

Comments
3 min read
20 Free Security APIs Every Developer Should Know About (2026)

20 Free Security APIs Every Developer Should Know About (2026)

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.