Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
infosec
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint
Davi
Davi
Davi
Follow
Sep 6
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint
#
authentication
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel
Davi
Davi
Davi
Follow
Sep 6
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page
Davi
Davi
Davi
Follow
Sep 6
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page
#
authentication
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It
Davi
Davi
Davi
Follow
Sep 6
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It
#
authentication
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention
Davi
Davi
Davi
Follow
Sep 6
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention
#
backend
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
SAML XSW: Signatures That Validate the Wrong Element
Davi
Davi
Davi
Follow
Sep 6
SAML XSW: Signatures That Validate the Wrong Element
#
authentication
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials
Davi
Davi
Davi
Follow
Sep 6
Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked
Davi
Davi
Davi
Follow
Sep 6
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
Wayback Machine for OSINT: What Stayed Archived After Remediation
Davi
Davi
Davi
Follow
Sep 6
Wayback Machine for OSINT: What Stayed Archived After Remediation
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
JWT Algorithm Negotiation Is a Spec Design Flaw, Not a Library Bug
Davi
Davi
Davi
Follow
Sep 6
JWT Algorithm Negotiation Is a Spec Design Flaw, Not a Library Bug
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
Working: CORS misconfigurations escape automated detection
Davi
Davi
Davi
Follow
Sep 6
Working: CORS misconfigurations escape automated detection
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
XXE in Document-Processing APIs: The Attack Surface Nobody Hardens
Davi
Davi
Davi
Follow
Sep 6
XXE in Document-Processing APIs: The Attack Surface Nobody Hardens
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
API SSRF: Allowlists Fail Because They Validate the URL, Not the Resolved IP
Davi
Davi
Davi
Follow
Sep 6
API SSRF: Allowlists Fail Because They Validate the URL, Not the Resolved IP
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
CORS Misconfiguration in APIs: Why Reflected Origin Plus Credentials Is the Dangerous Pattern, Not Wildcard
Davi
Davi
Davi
Follow
Sep 6
CORS Misconfiguration in APIs: Why Reflected Origin Plus Credentials Is the Dangerous Pattern, Not Wildcard
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
Subdomain Takeover Severity Comes From Security Context, Not the Exploit Mechanism
Davi
Davi
Davi
Follow
Sep 6
Subdomain Takeover Severity Comes From Security Context, Not the Exploit Mechanism
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account