DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
The swarm that kept coming back

Reconstructing the AI swarm's wild cyber-attack

The swarm that kept coming back

18
Picked as gem Comments 5
22 min read
Docker Engine 29.8's --umask flag fixes permissions docker exec used to reset

Docker Engine 29.8's --umask flag fixes permissions docker exec used to reset

10
Comments 1
6 min read
Enforce Permissions Inside the pgvector Query, Not After It

Enforce Permissions Inside the pgvector Query, Not After It

Comments
5 min read
Zero Permissions: how an Android PDF editor ships with no INTERNET permission

Zero Permissions: how an Android PDF editor ships with no INTERNET permission

Comments
12 min read
Tenant membership is not resource permission

Tenant membership is not resource permission

Comments
1 min read
Digital Forensic Services: What They Are, What They Recover, and Why Most Organizations Call Too Late

Digital Forensic Services: What They Are, What They Recover, and Why Most Organizations Call Too Late

5
Comments
5 min read
One attacker rented 87,000 IPs with a modified AI CLI

One attacker rented 87,000 IPs with a modified AI CLI

Comments
4 min read
One wallet minted 3,339 tokens: spotting deployer factories and bundler clusters on-chain

One wallet minted 3,339 tokens: spotting deployer factories and bundler clusters on-chain

Comments
4 min read
What Is Web Cache Deception? How Can an Attacker Make a Cache Store Private Data?

What Is Web Cache Deception? How Can an Attacker Make a Cache Store Private Data?

1
Comments
7 min read
Breaking the AI Reverse-Engineering Barrier: A Deep Dive into XopProtector, an Open-Source Android Protection Solution

Breaking the AI Reverse-Engineering Barrier: A Deep Dive into XopProtector, an Open-Source Android Protection Solution

Comments
7 min read
AI Coding Assistants Invent Fake Packages 1 in 5 Times — Attackers Are Already Registering Them

AI Coding Assistants Invent Fake Packages 1 in 5 Times — Attackers Are Already Registering Them

Comments
2 min read
No CVE needed: how a GitHub issue hijacked an AI agent

No CVE needed: how a GitHub issue hijacked an AI agent

1
Comments 1
5 min read
Read permission is not export permission

Read permission is not export permission

Comments
1 min read
DevVault – Local secret manager and runtime env injector in Go

DevVault – Local secret manager and runtime env injector in Go

Comments
1 min read
Red Team Basics: Pass-the-Hash & Kerberoasting – So greifen Angreifer an

Red Team Basics: Pass-the-Hash & Kerberoasting – So greifen Angreifer an

Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.