DEV Community

#appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
OAuth Tokens Were Always the Weak Link. AI Agents Just Made It Worse

OAuth Tokens Were Always the Weak Link. AI Agents Just Made It Worse

1
Comments
3 min read
FastAPI accepts a response_model on streaming routes and silently ignores it

FastAPI accepts a response_model on streaming routes and silently ignores it

Comments
5 min read
A Sandbox Got Popped at Black Hat. Nobody Should Be Shocked.

A Sandbox Got Popped at Black Hat. Nobody Should Be Shocked.

1
Comments
3 min read
The one they fixed

The one they fixed

Comments
4 min read
FastAPI prints the contents of Pydantic's Secret[T]

FastAPI prints the contents of Pydantic's Secret[T]

Comments
6 min read
Five findings in FastAPI, and what happened when I reported them

Five findings in FastAPI, and what happened when I reported them

Comments
4 min read
Top Enterprise SCA Tools in 2026: A Developer's Comparison

Top Enterprise SCA Tools in 2026: A Developer's Comparison

Comments
11 min read
A CVSS 10.0 in Your AI Coding Agent Is Just TOCTOU Wearing a Hoodie

A CVSS 10.0 in Your AI Coding Agent Is Just TOCTOU Wearing a Hoodie

1
Comments
3 min read
Why I Suppressed 30% of Snyk's Recommendations

Why I Suppressed 30% of Snyk's Recommendations

Comments
8 min read
Adding WebAuthn to a multi-tenant NestJS + Next.js app: what nobody tells you

Adding WebAuthn to a multi-tenant NestJS + Next.js app: what nobody tells you

Comments
11 min read
A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)

A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)

Comments 2
6 min read
They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network

They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network

Comments
6 min read
Secure Code Review Challenge #2: Professional — Solution (Clean Code Can Still Be Vulnerable)

Secure Code Review Challenge #2: Professional — Solution (Clean Code Can Still Be Vulnerable)

Comments 2
11 min read
The npm Worm That Learned to Trust Your AI Agent

The npm Worm That Learned to Trust Your AI Agent

Comments
3 min read
Your AI Scam Detector Trusts Fake Reviewers More Than You Think

Your AI Scam Detector Trusts Fake Reviewers More Than You Think

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.