close

DEV Community

Security

Hopefully not just an afterthought!

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Your Agents Need a Security Boundary. Heres Why Its Become Non-Negotiable.

Your Agents Need a Security Boundary. Heres Why Its Become Non-Negotiable.

Comments
5 min read
Letting an AI agent run shell commands is RCE on your machine. I fixed it with the kernel, not Docker.

Letting an AI agent run shell commands is RCE on your machine. I fixed it with the kernel, not Docker.

Comments
4 min read
Defeating IDOR: A Developer's Guide to Securing Object-Level Access Control

Defeating IDOR: A Developer's Guide to Securing Object-Level Access Control

Comments
6 min read
AI agents need tiered approval escalation, not one big confirm button

AI agents need tiered approval escalation, not one big confirm button

Comments
4 min read
An AI agent acted across two companies. Whose audit log knows which human?

An AI agent acted across two companies. Whose audit log knows which human?

Image 1
Comments
6 min read
I gave my AI agent database access. Then I built a firewall so it couldn't wipe prod.

I gave my AI agent database access. Then I built a firewall so it couldn't wipe prod.

Comments 1
3 min read
I Hardened Pod securityContext and Broke 9 Containers in Production

I Hardened Pod securityContext and Broke 9 Containers in Production

Comments 1
6 min read
The ISO 27001 Statement of Applicability, explained for engineers

The ISO 27001 Statement of Applicability, explained for engineers

Comments 1
3 min read
I got nervous about installing MCP servers, so I built a scanner for them

I got nervous about installing MCP servers, so I built a scanner for them

Image 1
Comments
3 min read
Why Prompt Injection Won't Be "Fixed"

Why Prompt Injection Won't Be "Fixed"

Comments 1
9 min read
I added TOTP 2FA to my Django app in ~40 lines and no 2FA library — but one line decides whether it's real

I added TOTP 2FA to my Django app in ~40 lines and no 2FA library — but one line decides whether it's real

Comments
4 min read
Where the Hell Do I Put This Token? Syncing Claude Code Secrets to 3 Macs with the 1Password CLI

Where the Hell Do I Put This Token? Syncing Claude Code Secrets to 3 Macs with the 1Password CLI

Comments
9 min read
7 Days Until MiCA. Your Agents Cannot Prove Who They Are to Each Other.

7 Days Until MiCA. Your Agents Cannot Prove Who They Are to Each Other.

Comments
4 min read
The support loop is fine, right up until crypto goes mainstream.

The support loop is fine, right up until crypto goes mainstream.

Comments
2 min read
I Built an eBPF Security Agent That Catches GitHub PAT Exfiltration at the Kernel Level

I Built an eBPF Security Agent That Catches GitHub PAT Exfiltration at the Kernel Level

Comments
7 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.