DEV Community

#appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I Used AI to Help Remediate Vulnerabilities — Here's How Useful It Actually Was

I Used AI to Help Remediate Vulnerabilities — Here's How Useful It Actually Was

Comments
7 min read
Before and After: Measuring Security Posture Improvement With Real Metrics

Before and After: Measuring Security Posture Improvement With Real Metrics

Comments
6 min read
Zero-Day in 24 Hours: How AI-Assisted Exploit Velocity Is Redefining Enterprise Cyber Defense

Zero-Day in 24 Hours: How AI-Assisted Exploit Velocity Is Redefining Enterprise Cyber Defense

Comments
4 min read
Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines

Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines

Comments
12 min read
Your AI Coding Agent Trusts Git More Than It Trusts You

Your AI Coding Agent Trusts Git More Than It Trusts You

1
Comments
3 min read
Putting a Deterministic Cop Between Your LLM and Its Tools Is Not Optional Anymore

Putting a Deterministic Cop Between Your LLM and Its Tools Is Not Optional Anymore

4
Comments 2
3 min read
What Was on This Machine? Answering the Blast Radius Question After a Laptop Compromise

What Was on This Machine? Answering the Blast Radius Question After a Laptop Compromise

Comments
10 min read
Why an AppSec agent should try to disprove its own findings

Why an AppSec agent should try to disprove its own findings

Comments
6 min read
The POST was guarded, the GET on the same URL was not: cross-tenant PII disclosure in CoopCycle (GET /api/stores/{id}/addresses)

The POST was guarded, the GET on the same URL was not: cross-tenant PII disclosure in CoopCycle (GET /api/stores/{id}/addresses)

Comments
8 min read
The TODO shipped to npm: an unauthenticated route that could stop any city's AI workflow (Your Priorities, @yrpri/api < 9.0.244)

The TODO shipped to npm: an unauthenticated route that could stop any city's AI workflow (Your Priorities, @yrpri/api < 9.0.244)

Comments
7 min read
A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2

A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2

Comments
5 min read
How to Reduce Time to Revoke for Exposed Credentials

How to Reduce Time to Revoke for Exposed Credentials

5
Comments 1
8 min read
Why SAST and DAST Aren't Enough for Secrets Security

Why SAST and DAST Aren't Enough for Secrets Security

Comments
10 min read
We Built a Standardized File Format for Prompt Injection and Called It AGENTS.md

We Built a Standardized File Format for Prompt Injection and Called It AGENTS.md

1
Comments
3 min read
The LLM Isn't Your Attacker. Your eval() Statement Is.

The LLM Isn't Your Attacker. Your eval() Statement Is.

6
Comments 2
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.