DEV Community

Cybersecurity

Articles related to cybersecurity and much more

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
JSON, CSV, and YAML Are Not Safe Formats for AI Agents: They Are Attack Vectors

JSON, CSV, and YAML Are Not Safe Formats for AI Agents: They Are Attack Vectors

Comments
5 min read
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Comments
5 min read
PKCE Downgrade Attack: When the Authorization Server Accepts Both Flows

PKCE Downgrade Attack: When the Authorization Server Accepts Both Flows

Comments
5 min read
OAuth Flow CSRF: How a Missing State Parameter Enables Forced Authorization

OAuth Flow CSRF: How a Missing State Parameter Enables Forced Authorization

Comments
5 min read
Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Comments
5 min read
HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

Comments
6 min read
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

Comments
6 min read
REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

Comments
6 min read
gRPC Server Reflection: The Unauthenticated API Catalog in Your Production Service

gRPC Server Reflection: The Unauthenticated API Catalog in Your Production Service

Comments
5 min read
Agent Output Is an Injection Vector: SQL, Shell, and Template Engines

Agent Output Is an Injection Vector: SQL, Shell, and Template Engines

Comments
5 min read
BFLA Survives Pentests: Why Testers Never Try the Wrong HTTP Method

BFLA Survives Pentests: Why Testers Never Try the Wrong HTTP Method

Comments
5 min read
Exposed Spring Boot Actuator: /heapdump Delivers Credentials in Production

Exposed Spring Boot Actuator: /heapdump Delivers Credentials in Production

Comments
5 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

Comments
6 min read
gRPC Security: The Authorization Model REST Scanners Cannot See

gRPC Security: The Authorization Model REST Scanners Cannot See

Comments
5 min read
OAuth Token Leakage in Agentic AI: When the Context Window Becomes a Credential Store

OAuth Token Leakage in Agentic AI: When the Context Window Becomes a Credential Store

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.