close

DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Stop Putting Secrets in Plaintext

Stop Putting Secrets in Plaintext

Comments
3 min read
Every dev tool you paste your data into is a potential breach you didn't sign up for

Every dev tool you paste your data into is a potential breach you didn't sign up for

6
Comments
2 min read
Hiding WooCommerce Prices Is a Data-Exposure Problem, Not a CSS Problem

Hiding WooCommerce Prices Is a Data-Exposure Problem, Not a CSS Problem

Comments
4 min read
Building a Read-Only Cloudflare Worker AI Security Console

Building a Read-Only Cloudflare Worker AI Security Console

1
Comments
8 min read
I built a vulnerability scanner that refuses to lie to me

I built a vulnerability scanner that refuses to lie to me

Comments
3 min read
A Security-Headers Grade Counts Headers. It Doesn’t Test Them.

A Security-Headers Grade Counts Headers. It Doesn’t Test Them.

Comments
5 min read
Two Vulnerabilities Bypassing Signature Verification in miniOrange SAML SSO

Two Vulnerabilities Bypassing Signature Verification in miniOrange SAML SSO

1
Comments
10 min read
CVE-2026-75501: Calix Router WAN-side UPnP Exposes Internal Devices

CVE-2026-75501: Calix Router WAN-side UPnP Exposes Internal Devices

1
Comments
10 min read
Treat Your Agent's Free Server Like a Compromised Machine

Treat Your Agent's Free Server Like a Compromised Machine

1
Comments
4 min read
SPF, DKIM, and DMARC: Why “Valid” Records Still Let Your Domain Be Spoofed

SPF, DKIM, and DMARC: Why “Valid” Records Still Let Your Domain Be Spoofed

Comments
6 min read
I Built an Open-Source Toolkit for AI Watermark & Provenance Forensics

I Built an Open-Source Toolkit for AI Watermark & Provenance Forensics

Comments
3 min read
Agent Memory Poisoning: Why Content Screening and Provenance Ranking Can't Stop Persistent False Information

Agent Memory Poisoning: Why Content Screening and Provenance Ranking Can't Stop Persistent False Information

Comments
4 min read
We benchmarked a security detector against 500k lines of Go. It found a real bug.

We benchmarked a security detector against 500k lines of Go. It found a real bug.

Comments
3 min read
Quipu: cifrado post-cuántico en Rust puro, con una rueda para Python

Quipu: cifrado post-cuántico en Rust puro, con una rueda para Python

Comments
2 min read
OWASP Top 10: A05 & A06 — Injection and Insecure Design

OWASP Top 10: A05 & A06 — Injection and Insecure Design

Comments
1 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.