← All communities
Community 03

Cybersecurity

Offensive security, CTFs, defense.

Join this community

Projects from this community

01 total
Security

Kinga

Campus network intrusion dashboard.

News for Cybersecurity

DEV · Medium
DEV · Just In

Prompt Injection Is the New SQL Injection (and We're Not Ready)

In March 2026, a financial services company discovered that their customer-facing AI agent had been...

Read on DEV
DEV · Just In

The No-Backend Backend: Neon Data API, RLS and 27 Attacks

We built a multi-tenant team task board with no backend. The browser loads static files, signs in...

Read on DEV
DEV · Just In

Confused Deputy: The Old Bug That AI Agents Keep Reintroducing

Back in 1988, a compiler running on a commercial timesharing system had permission to write to a...

Read on DEV
DEV · Just In

The SOC Is Changing: From Alert Triage to AI-Native Security Operations

There's a particular kind of tired that only SOC analysts know. It's 2 a.m., the queue shows hundreds...

Read on DEV
DEV · Just In

Architecting a Resilient DevSecOps Pipeline for Enterprise AI Agents

A four-stage DevSecOps CI/CD architecture for securing enterprise AI agents with GitHub Actions, secret scanning, AI-assisted review, Veracode SCA, and Pipeline SAST.

Read on DEV
DEV · Just In

1,558 Tests Green and No Auth: The Tests That Never Actually Ran

A test named test_all_adapters_importable asserted nothing. It would pass forever, even if every...

Read on DEV
DEV

What Is a Parser Differential? How Can the Same Input Mean Different Things to Different Systems?

A request arrives at a web application. Before it reaches the application, it passes through a...

Aditya SharmaSep 19 · 6 min
DEV

Caddy 2.11's default post-quantum key exchange sends six times more handshake bytes

I measured Caddy's new default X25519MLKEM768 key exchange against classical X25519: ClientHello grows from 318 to 1494 bytes, ServerHello from 122 to 1210, but the raw crypto costs under 65 microseconds and old clients still connect fine.

Alex GeorgievSep 19 · 6 min
DEV

Your AI Coding Agent Can Be Attacked by the Repository It Opens

Most developers already know this rule: Don't run code from a repository you don't...

Robert AdamsonSep 19 · 5 min
DEV

Your AI Agent Has Too Many Permissions: A Practical Guide to Not Getting Burned

Somewhere right now, an AI agent has a standing API key with more access than the intern you'd never...

Mika FlowersSep 18 · 5 min
DEV

Bypassing a WAF and a CSP with Google Tag Manager: An Attacker’s Perspective and Remediation Advice

This blog was originally published by Ryan Chaplin on the Raxis blog February 10, 2026 During...

Bonnie SmyreSep 18 · 14 min
DEV

Two Strangers Built an Agent Mandate Protocol in My Comments. It Still Needs a Regulator.

I got something wrong in my own comments section nine days ago, and two strangers spent a week...

arun rajkumarSep 16 · 5 min