DEV Community

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

Comments
8 min read
The Business Context Problem: Why Vulnerability Severity Scores Lie

The Business Context Problem: Why Vulnerability Severity Scores Lie

Comments
4 min read
RAMPART Tests Your AI Agents in Dev. What Catches Malicious Tool Calls in Production?

RAMPART Tests Your AI Agents in Dev. What Catches Malicious Tool Calls in Production?

2
Comments
5 min read
The Ghost Platforms That Broke Our Payment Rails and How We Unchained Ourselves

The Ghost Platforms That Broke Our Payment Rails and How We Unchained Ourselves

Comments
3 min read
Platform Lockdowns Will Doom Your Business

Platform Lockdowns Will Doom Your Business

1
Comments
2 min read
The Egregious Cost of Compliance: One Platform's Overly Broad Restrictions

The Egregious Cost of Compliance: One Platform's Overly Broad Restrictions

Comments
2 min read
Unchaining Freelance Commerce in Nigeria Was Not Just About Payments

Unchaining Freelance Commerce in Nigeria Was Not Just About Payments

Comments
3 min read
The Dark Side of Standardized E-commerce Solutions for Global Creators

The Dark Side of Standardized E-commerce Solutions for Global Creators

Comments
2 min read
The Shai-Hulud Worm Is Now Open Source — Here's How to Stop Self-Replicating Prompts Before They Reach Your LLM

The Shai-Hulud Worm Is Now Open Source — Here's How to Stop Self-Replicating Prompts Before They Reach Your LLM

1
Comments
5 min read
Hidden Audio Attacks on Voice AI: How Transcription Pipelines Get Hijacked

Hidden Audio Attacks on Voice AI: How Transcription Pipelines Get Hijacked

Comments
4 min read
Your Okta Is Only As Strong As Your SIM Card

Your Okta Is Only As Strong As Your SIM Card

Comments
3 min read
I Dusted Off a 6-Year-Old Java Project and Ran Snyk Against It — Here's What I Found

I Dusted Off a 6-Year-Old Java Project and Ran Snyk Against It — Here's What I Found

Comments
9 min read
Modernising a 6-Year-Old Spring Boot Project Without Breaking Everything

Modernising a 6-Year-Old Spring Boot Project Without Breaking Everything

Comments
8 min read
GraphQL Authorization Bypass: A Real CVE Code Review

GraphQL Authorization Bypass: A Real CVE Code Review

1
Comments 1
9 min read
Why the Variable Name Is the Most Important Feature in Secrets Detection

Why the Variable Name Is the Most Important Feature in Secrets Detection

Comments
8 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.