DEV Community

Cybersecurity

Articles related to cybersecurity and much more

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I Let Users Write HTML Templates - Here Are 6 Security Holes I Had to Patch

I Let Users Write HTML Templates - Here Are 6 Security Holes I Had to Patch

4
Comments
6 min read
Shadow API Risks: The Hidden Cybersecurity Threat Most U.S. Small Businesses Miss

Shadow API Risks: The Hidden Cybersecurity Threat Most U.S. Small Businesses Miss

3
Comments
2 min read
SeeTheSharpFlag — Hack The Box Mobile Challenge Write-up

SeeTheSharpFlag — Hack The Box Mobile Challenge Write-up

Comments
2 min read
GHSA-6QR9-G2XW-CW92: Dagu: The Friendly Ghost that Runs Your Malware (GHSA-6QR9-G2XW-CW92)

GHSA-6QR9-G2XW-CW92: Dagu: The Friendly Ghost that Runs Your Malware (GHSA-6QR9-G2XW-CW92)

Comments
2 min read
There's Always a Hardcoded Secret Somewhere — Meet Titus

There's Always a Hardcoded Secret Somewhere — Meet Titus

Comments
4 min read
GHSA-GV8R-9RW9-9697: The Ghost in the Handshake: Traefik & Go mTLS Bypass in HTTP/3

GHSA-GV8R-9RW9-9697: The Ghost in the Handshake: Traefik & Go mTLS Bypass in HTTP/3

Comments
2 min read
CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK

CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK

Comments
2 min read
The twist: AI is a tool, not the operator

The twist: AI is a tool, not the operator

2
Comments
5 min read
Day 7 — Cross-Site Request Forgery (CSRF) in Flask: Account Takeover via Session Riding & Proper Mitigation

Day 7 — Cross-Site Request Forgery (CSRF) in Flask: Account Takeover via Session Riding & Proper Mitigation

Comments
6 min read
CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the <

CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the <

Comments
2 min read
The $500 Million Security Gap: Bank of Ireland UK’s Critical Failure

The $500 Million Security Gap: Bank of Ireland UK’s Critical Failure

1
Comments
2 min read
Fortifying Web Applications: Understanding CSRF (Cross-Site Request Forgery)

Fortifying Web Applications: Understanding CSRF (Cross-Site Request Forgery)

1
Comments
2 min read
GHSA-33HQ-FVWR-56PM: The Billion-Comma Attack: Nuking Svelte SSR with Sparse Arrays

GHSA-33HQ-FVWR-56PM: The Billion-Comma Attack: Nuking Svelte SSR with Sparse Arrays

Comments
2 min read
Week 6 OAuth2 Conceptual Quiz

Week 6 OAuth2 Conceptual Quiz

1
Comments
10 min read
GHSA-6C9J-X93C-RW6J: OpenClaw Side-Channel: The `safeBins` File Existence Oracle

GHSA-6C9J-X93C-RW6J: OpenClaw Side-Channel: The `safeBins` File Existence Oracle

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.