DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
How do you stop an LLM from leaking API keys in the code it writes? Default to secret

How do you stop an LLM from leaking API keys in the code it writes? Default to secret

6
Comments 4
8 min read
I Told a PR Nothing Would Break. Qodo Checked.

I Told a PR Nothing Would Break. Qodo Checked.

5
Comments
4 min read
Extending Zero Trust to Your Agents' Memory

Extending Zero Trust to Your Agents' Memory

Comments
10 min read
AI Coding Tip 037 - Stop Patching Blind

AI Coding Tip 037 - Stop Patching Blind

Comments
11 min read
If You Use Telegram in 2026: Read This Now

If You Use Telegram in 2026: Read This Now

Comments
10 min read
BigCommerce Third-Party App Compromise: Malicious Script Injected into Storefronts via Ribon Credentials

BigCommerce Third-Party App Compromise: Malicious Script Injected into Storefronts via Ribon Credentials

Comments
5 min read
Three Linux Kernel Vulnerabilities Added to CISA KEV: Active Exploitation Reported in AF_ALG, ebtables, and kTLS

Three Linux Kernel Vulnerabilities Added to CISA KEV: Active Exploitation Reported in AF_ALG, ebtables, and kTLS

Comments
6 min read
CrowdSec Source Code Leak: GitHub OAuth Token Abused in TanStack Supply Chain Attack

CrowdSec Source Code Leak: GitHub OAuth Token Abused in TanStack Supply Chain Attack

Comments
7 min read
Gemini Accessed Three Real Companies During a Security Evaluation via Password Guessing and Publicly Exposed Credentials

Gemini Accessed Three Real Companies During a Security Evaluation via Password Guessing and Publicly Exposed Credentials

Comments
6 min read
Click2Shell: One-Click Chain from Automatic WordPress Theme Installation to PHP Execution

Click2Shell: One-Click Chain from Automatic WordPress Theme Installation to PHP Execution

Comments
6 min read
Keeping credentials out of your coding agent’s model context

Keeping credentials out of your coding agent’s model context

Comments 1
3 min read
FileBrowser Permissions Explained: How Far Can One Compromised Account Actually Go?

FileBrowser Permissions Explained: How Far Can One Compromised Account Actually Go?

Comments
17 min read
Your AI Agent Needs a Chaos Monkey

Your AI Agent Needs a Chaos Monkey

1
Comments
8 min read
Fake LastPass Authenticator Installs a Microsoft-Signed Driver That Kills 145 Security Tools

Fake LastPass Authenticator Installs a Microsoft-Signed Driver That Kills 145 Security Tools

Comments
5 min read
Designing an eval harness for prompt-injection detection: what measuring my defenses actually taught me

Designing an eval harness for prompt-injection detection: what measuring my defenses actually taught me

Comments
6 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.