[go: up one dir, main page]

DEV Community

#appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
GitHub finds your vulnerabilities. Something still has to manage them.

GitHub finds your vulnerabilities. Something still has to manage them.

1
Comments
6 min read
trust_remote_code Was Always a Dare, Not a Safeguard

trust_remote_code Was Always a Dare, Not a Safeguard

1
Comments
3 min read
Confronting Vault Sprawl And The Risks It Brings

Confronting Vault Sprawl And The Risks It Brings

Comments
8 min read
Running Snyk on Real Legacy Java Code — The Full Unfiltered Results

Running Snyk on Real Legacy Java Code — The Full Unfiltered Results

Comments
10 min read
HTB Orion — CraftCMS RCE, a Reverse Shell That Wouldn't Connect, and a Telnetd Auth Bypass

HTB Orion — CraftCMS RCE, a Reverse Shell That Wouldn't Connect, and a Telnetd Auth Bypass

Comments
4 min read
How to Prevent API Keys and Secrets from Leaking into LLMs

How to Prevent API Keys and Secrets from Leaking into LLMs

Comments
2 min read
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Comments
3 min read
An "Autonomous" AI Attack Got Caught Because It Left the Door Open

An "Autonomous" AI Attack Got Caught Because It Left the Door Open

2
Comments 1
3 min read
Hardening my own Nmap web UI: the security holes I shipped, and what actually saved me

Hardening my own Nmap web UI: the security holes I shipped, and what actually saved me

2
Comments
4 min read
Your Phishing Simulation Score Is 99%. Here's Why That Worries Me.

Your Phishing Simulation Score Is 99%. Here's Why That Worries Me.

Comments
4 min read
Agentic AI Security: Risks, OWASP Agentic Top 10, and Defensive Patterns (2026)

Agentic AI Security: Risks, OWASP Agentic Top 10, and Defensive Patterns (2026)

Comments
13 min read
DAST false negatives vs SAST false positives: a real case

DAST false negatives vs SAST false positives: a real case

1
Comments
10 min read
Cache Poisoning at the Edge: How Cloudflare Workers & Vercel Edge Functions Break Everything You Thought You Knew

Cache Poisoning at the Edge: How Cloudflare Workers & Vercel Edge Functions Break Everything You Thought You Knew

Comments
7 min read
AI Harnesses Are Just Middleware, and Middleware Trust Bugs Are Older Than Your Career

AI Harnesses Are Just Middleware, and Middleware Trust Bugs Are Older Than Your Career

1
Comments 2
3 min read
Copilot for Word Will Copy Its Own Poison Into Every Document It Touches

Copilot for Word Will Copy Its Own Poison Into Every Document It Touches

3
Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.