DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
I Got the proxy.ts Matcher Wrong for Three Projects Before I Understood Why

Security risks in the middleware to proxy shift

I Got the proxy.ts Matcher Wrong for Three Projects Before I Understood Why

11
Comments 4
9 min read
The whole payments industry now co-signs the agent payment rail. Who red-teams it?

The whole payments industry now co-signs the agent payment rail. Who red-teams it?

Comments
2 min read
MCP Security Crisis: Two Open-Source Frameworks Solving the Agent Security Problem

MCP Security Crisis: Two Open-Source Frameworks Solving the Agent Security Problem

1
Comments
3 min read
DBD Cornucopia is now available to play online!

DBD Cornucopia is now available to play online!

Comments
3 min read
Production RBAC patterns for Go and Node startups

Production RBAC patterns for Go and Node startups

Comments
10 min read
Your AI Gateway needs guardrails — here's how to add them with AWS Bedrock and Kong

Your AI Gateway needs guardrails — here's how to add them with AWS Bedrock and Kong

Comments
2 min read
CSRF: Why Double-Submit Cookie Falls Short for Financial-Grade Security

CSRF: Why Double-Submit Cookie Falls Short for Financial-Grade Security

Comments
4 min read
Your package-lock.json diff is unreadable. That's a supply-chain problem.

Your package-lock.json diff is unreadable. That's a supply-chain problem.

Comments
3 min read
When Claude Is Not Claude: How I Caught an AI Agent Lying About Its Own Identity

When Claude Is Not Claude: How I Caught an AI Agent Lying About Its Own Identity

Comments
7 min read
Blind Signatures Explained: Getting Something Signed Without Revealing It

Blind Signatures Explained: Getting Something Signed Without Revealing It

Comments
4 min read
How I Detected Merlin QUIC C2 Traffic Using Entropy and Z-Scores (490K Packets, 0% False Positives)

How I Detected Merlin QUIC C2 Traffic Using Entropy and Z-Scores (490K Packets, 0% False Positives)

Comments
10 min read
The difference between "this shouldn't happen" and "this cannot happen" in AI content pipelines

The difference between "this shouldn't happen" and "this cannot happen" in AI content pipelines

Comments
4 min read
Building a Multi-Tenant API Key Management Platform with Ory Talos: A Real-World Use Case

Building a Multi-Tenant API Key Management Platform with Ory Talos: A Real-World Use Case

Comments
10 min read
Headless Browser Detection in 2026: What Still Trips Up Playwright

Headless Browser Detection in 2026: What Still Trips Up Playwright

1
Comments
9 min read
A password and a PIN aren't multifactor: the Security+ authentication trap

A password and a PIN aren't multifactor: the Security+ authentication trap

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.