Security - DEV Community
https://dev.to/t/security • 151 KB fetched Open original page
Security - DEV Community
Skip to content
Powered by Algolia
Log in
Create account
DEV Community
Security
Hopefully not just an afterthought!
Follow
Hide
Create Post
submission guidelines
Write as you are pleased, be mindful and keep it civil.
Older #security posts
1
2
3
4
5
6
7
8
9
… 75
… 2025
Posts
👋 Sign in for the ability to sort posts by relevant , latest , or top .
Someone Spammed My DEV Post. I Traced It to a Wombat.
Math shows three annual signups fund it
Don Johnson
Don Johnson
Don Johnson
Follow
Sep 10
Someone Spammed My DEV Post. I Traced It to a Wombat.
# discuss
# cybersecurity
# security
19 reactions
5 comments
14 min read
The Adventures of Blink S6e2: The Base Control [NIST 800-53 CM(3)]
Ben Link
Ben Link
Ben Link
Follow
Sep 10
The Adventures of Blink S6e2: The Base Control [NIST 800-53 CM(3)]
# security
# cicd
# devex
# management
9 reactions
1 comment
1 min read
When the code you're reviewing isn't what the model wrote
Cole Halton
Cole Halton
Cole Halton
Follow
Sep 11
When the code you're reviewing isn't what the model wrote
# aicodereview
# security
# evaldesign
Add Comment
2 min read
The Hack Nobody Ordered: When OpenAI's Own Model Broke Into Hugging Face
Arham Sayyed
Arham Sayyed
Arham Sayyed
Follow
Sep 10
The Hack Nobody Ordered: When OpenAI's Own Model Broke Into Hugging Face
# news
# ai
# security
# openai
1 reaction
Add Comment
10 min read
Stop Minting Static Credentials
Michael Ethridge
Michael Ethridge
Michael Ethridge
Follow
Sep 10
Stop Minting Static Credentials
# terraform
# vault
# security
# oidc
Add Comment
15 min read
I Asked a Frontier LLM to Recover Secrets from My Decompiled Build
Nikolai Sachok
Nikolai Sachok
Nikolai Sachok
Follow
Sep 10
I Asked a Frontier LLM to Recover Secrets from My Decompiled Build
# security
# llm
# testing
# reverseengineering
Add Comment
6 min read
Metrice: Zero-dependency post-quantum P2P mesh network
Ahmet Göktürk
Ahmet Göktürk
Ahmet Göktürk
Follow
Sep 10
Metrice: Zero-dependency post-quantum P2P mesh network
# javascript
# node
# security
# distributedsystems
Add Comment
3 min read
PicoCTF Mod 26 Writeup — Brute-Force a Caesar Cipher
CTFDojo
CTFDojo
CTFDojo
Follow
Sep 10
PicoCTF Mod 26 Writeup — Brute-Force a Caesar Cipher
# ctf
# security
# cryptography
Add Comment
3 min read
Taming SPAs with VORTEX: How a Crawler Actually Understands React, Vue, and Angular
Arturo Enrique Mata Garcia
Arturo Enrique Mata Garcia
Arturo Enrique Mata Garcia
Follow
Sep 10
Taming SPAs with VORTEX: How a Crawler Actually Understands React, Vue, and Angular
# architecture
# frontend
# javascript
# security
Add Comment
6 min read
Your Third-Party SDKs May Be Collecting More Data Than You Think
Peesh Chopra
Peesh Chopra
Peesh Chopra
Follow
Sep 10
Your Third-Party SDKs May Be Collecting More Data Than You Think
# privacy
# security
# webdev
# legal
Add Comment
6 min read
We open-sourced our vault's encryption code — and wrote honestly about what it doesn't guarantee
kh.vibecoding
kh.vibecoding
kh.vibecoding
Follow
Sep 10
We open-sourced our vault's encryption code — and wrote honestly about what it doesn't guarantee
# security
# encryption
# opensource
# api
Add Comment
4 min read
A Scoped Token Is Not a Code of Conduct
Christian Johannsen
Christian Johannsen
Christian Johannsen
Follow
Sep 10
A Scoped Token Is Not a Code of Conduct
# ai
# security
# mcp
# iam
Add Comment
6 min read
Your API Key Will Leak. Make That Not Matter
kh.vibecoding
kh.vibecoding
kh.vibecoding
Follow
Sep 10
Your API Key Will Leak. Make That Not Matter
# security
# api
# ai
# devops
Add Comment
5 min read
The Missing Layer Between AI and the Real World
Stephen Lincoln
Stephen Lincoln
Stephen Lincoln
Follow
Sep 10
The Missing Layer Between AI and the Real World
# agents
# ai
# architecture
# security
1 reaction
Add Comment
2 min read
When AI Gateways Lie: Debugging Upstream Channel Eviction and Routing Desync in Production
zimei07
zimei07
zimei07
Follow
Sep 10
When AI Gateways Lie: Debugging Upstream Channel Eviction and Routing Desync in Production
# security
# devops
# architecture
# opensource
Add Comment
4 min read
👋 Sign in for the ability to sort posts by relevant , latest , or top .
trending guides/resources
How Dopamine Works: The Architecture of a Modern iOS Jailbreak
Kimi K3's 2.8T Parameters Are Not a Self-Hosting Plan—Use This Readiness Gate
Patch Your Rails: Active Storage CVE-2026-66066
Codex Got Blocked by macOS. I Reinstalled Instead of Bypassing It.
Stealing Reasoning Traces from LLM APIs: How It Works and What to Audit
Passkeys Explained Simply
10 ChatGPT Prompts for Daily Use by L1 SOC Analysts
The $0.13 API Token: Inside the Underground Relay Market for AI Access
The Ultimate Bug Bounty Roadmap (2026): A Beginner-to-Pro Guide
Zimbra CVE-2026-73570: Unauthenticated Command Injection via SMTP
DeviceCheck and App Attest: Stopping Fraud in iOS Apps
Shai-Hulud Strikes Back: Keyv, Cacheable & 800+ npm Packages Hijacked in Massive Worm Attack
How to Block Dangerous Commands with Claude Code Hooks
Understanding OWASP Mobile Top 10 (2025): A Guide for Android & iOS Developers
I Tested 7 AI OSINT Agents on My Own Digital Footprint - Here's What They Found in 4 Minutes
How to Set Up Claude Code for a Project with Skills, Agents, Hooks, and a Secure GitHub Repository
A hacked WordPress, two attackers, and the hole no antivirus saw
GPT-5.6 Sol's file deletion isn't a bug you patch. It's proof that filtering an agent's actions d...
Bypassing Activation Lock via Device-to-Device Migration in iPhone: A Retrospective Analysis
เจาะลึกเหตุการณ์ AI หลุดแฮก Hugging Face, GPT-5.6 Sol หนีออกจากกรงได้อย่างไร ฉบับแปลและขยายความจา...
On-Premise AI Code Review: How We Deployed Claude Locally in an Air-Gapped Environment (Setup Guide)
Codex vs Claude Code no .NET: minha experiência usando os dois
Implementing TOTP Two-Factor Authentication from Scratch in Python
Open Banking APIs Explained: What PSD2 Compliance Actually Requires From Your Engineering Team
Anthropic just published a jailbreak severity scale. Here's what it means.
DEV Community — A space to discuss and keep up software development and manage your software career
*
Home
*
DEV Challenges
*
DEV++
*
Videos
*
DEV Education Tracks
*
DEV Help
*
Advertise on DEV
*
Organization Accounts
*
DEV Showcase
*
About
*
Contact
*
Free Postgres Database
*
DEV Shop
*
MLH
*
Code of Conduct
*
Privacy Policy
*
Terms of Use
Built on Forem — the open source software that powers DEV and other inclusive communities.
Made with love and Ruby on Rails . DEV Community (c) 2016 - 2026.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account
Links found on this page
- Skip to content [direct]
- Powered by Algolia [direct]
- Log in [direct]
- Create account [direct]
- Create Post [direct]
- 2 [direct]
- 3 [direct]
- 4 [direct]
- 5 [direct]
- 6 [direct]
- 7 [direct]
- 8 [direct]
- 9 [direct]
- 75 [direct]
- 2025 [direct]
- Someone Spammed My DEV Post. I Traced It to a Wombat. [direct]
- Don Johnson [direct]
- # discuss [direct]
- # cybersecurity [direct]
- The Adventures of Blink S6e2: The Base Control [NIST 800-53 CM(3)] [direct]
- Ben Link [direct]
- # cicd [direct]
- # devex [direct]
- # management [direct]
- When the code you're reviewing isn't what the model wrote [direct]
- Cole Halton [direct]
- # aicodereview [direct]
- # evaldesign [direct]
- The Hack Nobody Ordered: When OpenAI's Own Model Broke Into Hugging Face [direct]
- Arham Sayyed [direct]
- # news [direct]
- # ai [direct]
- # openai [direct]
- Stop Minting Static Credentials [direct]
- Michael Ethridge [direct]
- # terraform [direct]
- # vault [direct]
- # oidc [direct]
- I Asked a Frontier LLM to Recover Secrets from My Decompiled Build [direct]
- Nikolai Sachok [direct]
- # llm [direct]
- # testing [direct]
- # reverseengineering [direct]
- Metrice: Zero-dependency post-quantum P2P mesh network [direct]
- Ahmet Göktürk [direct]
- # javascript [direct]
- # node [direct]
- # distributedsystems [direct]
- PicoCTF Mod 26 Writeup — Brute-Force a Caesar Cipher [direct]
- CTFDojo [direct]
- # ctf [direct]
- # cryptography [direct]
- Taming SPAs with VORTEX: How a Crawler Actually Understands React, Vue, and Angular [direct]
- Arturo Enrique Mata Garcia [direct]
- # architecture [direct]
- # frontend [direct]
- Your Third-Party SDKs May Be Collecting More Data Than You Think [direct]
- Peesh Chopra [direct]
- # privacy [direct]
- # webdev [direct]
- # legal [direct]
- We open-sourced our vault's encryption code — and wrote honestly about what it doesn't guarantee [direct]
- kh.vibecoding [direct]
- # encryption [direct]
- # opensource [direct]
- # api [direct]
- A Scoped Token Is Not a Code of Conduct [direct]
- Christian Johannsen [direct]
- # mcp [direct]
- # iam [direct]
- Your API Key Will Leak. Make That Not Matter [direct]
- # devops [direct]
- The Missing Layer Between AI and the Real World [direct]
- Stephen Lincoln [direct]
- # agents [direct]
- When AI Gateways Lie: Debugging Upstream Channel Eviction and Routing Desync in Production [direct]
- zimei07 [direct]
- How Dopamine Works: The Architecture of a Modern iOS Jailbreak [direct]
- Kimi K3's 2.8T Parameters Are Not a Self-Hosting Plan—Use This Readiness Gate [direct]
- Patch Your Rails: Active Storage CVE-2026-66066 [direct]
|
|