DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Your AI Agent Will Do Something Terrible. Here's How to Survive It.

Painful lessons from early deployers

Your AI Agent Will Do Something Terrible. Here's How to Survive It.

19
Comments 7
7 min read
The Witness Was the Suspect: Why AI Audit Logs Can't Be Trusted

Distinguishing tamper-proof from truth-proof

The Witness Was the Suspect: Why AI Audit Logs Can't Be Trusted

31
Comments 37
9 min read
Behind Cloudflare and nginx, All My Users Had the Same IP

Behind Cloudflare and nginx, All My Users Had the Same IP

10
Comments
4 min read
We scanned 470 open-source React Native apps. Here is what breaks them.

We scanned 470 open-source React Native apps. Here is what breaks them.

Comments
3 min read
A Mac App Is Not a Process

A Mac App Is Not a Process

Comments
8 min read
A software update should not be able to stop the fridge

A software update should not be able to stop the fridge

Comments
5 min read
How I Broke a "Letters Only" Filter Using Invisible Bytes (YesWeHack Dojo #54 Write-up)

How I Broke a "Letters Only" Filter Using Invisible Bytes (YesWeHack Dojo #54 Write-up)

Comments
5 min read
When the attacker is an agent: a defender's field guide to autonomous AI intrusions in 2026

When the attacker is an agent: a defender's field guide to autonomous AI intrusions in 2026

Comments
6 min read
I scanned 200 public vibe-coded apps. Half the Supabase ones expose their database.

I scanned 200 public vibe-coded apps. Half the Supabase ones expose their database.

Comments
3 min read
We caught our own AI security scanner making up vulnerabilities

We caught our own AI security scanner making up vulnerabilities

Comments
3 min read
The 0-Click AI Attack, Part 2: How to Break the Attack Chain Before It Becomes a Breach

The 0-Click AI Attack, Part 2: How to Break the Attack Chain Before It Becomes a Breach

Comments
10 min read
Indirect Prompt Injection Through Tool Descriptions and Tool Output: How Untrusted Metadata Hijacks Agents

Indirect Prompt Injection Through Tool Descriptions and Tool Output: How Untrusted Metadata Hijacks Agents

Comments
7 min read
She used Claude as a diary. The terms of service are now part of the charge.

She used Claude as a diary. The terms of service are now part of the charge.

5
Comments
5 min read
Sandboxes in Kubernetes without privileged: cgroup_writable and hostUsers: false

Sandboxes in Kubernetes without privileged: cgroup_writable and hostUsers: false

Comments
5 min read
ZTC (Zero-Token Confidence): juzgar una acción de IA leyendo el estado interno del modelo, con cero tokens extra

ZTC (Zero-Token Confidence): juzgar una acción de IA leyendo el estado interno del modelo, con cero tokens extra

Comments
6 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.