DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
The No-Backend Backend: Neon Data API, RLS and 27 Attacks

The No-Backend Backend: Neon Data API, RLS and 27 Attacks

5
Comments
16 min read
Exposed GitLab Incoming Email Tokens Allow Unauthorized Code Modifications and CI Execution

Exposed GitLab Incoming Email Tokens Allow Unauthorized Code Modifications and CI Execution

1
Comments 1
6 min read
Thirty-Four Out of Thirty-Four. Then Zero Out of Ten.

Thirty-Four Out of Thirty-Four. Then Zero Out of Ten.

Comments
6 min read
OAuth client_credentials in Spring Boot for Prometheus Scrapes

OAuth client_credentials in Spring Boot for Prometheus Scrapes

Comments
10 min read
SolarWinds Observability Self-Hosted: Two Pre-Authentication RCE Vulnerabilities Fixed with Different Configuration Requirements

SolarWinds Observability Self-Hosted: Two Pre-Authentication RCE Vulnerabilities Fixed with Different Configuration Requirements

1
Comments
6 min read
I built a tiny library that makes your audit logs tamper-evident

I built a tiny library that makes your audit logs tamper-evident

Comments
3 min read
Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query

Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query

1
Comments
5 min read
CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

1
Comments
6 min read
security.txt in ten minutes: the cheapest Cyber Resilience Act task

security.txt in ten minutes: the cheapest Cyber Resilience Act task

Comments
2 min read
The fraud model that was right about everything except fraud

The fraud model that was right about everything except fraud

Comments
6 min read
Test the denied path before connecting an AI agent to SAP

Test the denied path before connecting an AI agent to SAP

Comments
3 min read
OpenAI's Agent Broke Into Medicare and Took 84 Days to Tell

OpenAI's Agent Broke Into Medicare and Took 84 Days to Tell

Comments
2 min read
HOLogram deep dive: the Input Vault — intercepting keystrokes before JavaScript reads them

HOLogram deep dive: the Input Vault — intercepting keystrokes before JavaScript reads them

Comments
4 min read
A Security Test Checklist for Tool-Calling AI Agents

A Security Test Checklist for Tool-Calling AI Agents

Comments
3 min read
Catch Broken Email DNS Before Your Client Hears “Your Messages Are Bouncing”

Catch Broken Email DNS Before Your Client Hears “Your Messages Are Bouncing”

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.