DEV Community

#appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling

Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling

Comments
3 min read
The Bucket You Deleted Is Still in Your DNS: S3 Bucket Takeover at Bime

The Bucket You Deleted Is Still in Your DNS: S3 Bucket Takeover at Bime

Comments
6 min read
The Detection Layer That Was Quietly Off: GuardDuty Disabled on an AWS Account

The Detection Layer That Was Quietly Off: GuardDuty Disabled on an AWS Account

Comments
6 min read
Why Secrets Slip Through Every Layer of Your Security Stack

Why Secrets Slip Through Every Layer of Your Security Stack

Comments
5 min read
Inside the LiteLLM hack: 153GB, 433,909 Files, 2,488 Organizations

Inside the LiteLLM hack: 153GB, 433,909 Files, 2,488 Organizations

1
Comments
4 min read
1.8 Million APKs Later, We Should Talk About What "AI Agent" Actually Means in a Threat Model

1.8 Million APKs Later, We Should Talk About What "AI Agent" Actually Means in a Threat Model

1
Comments
3 min read
An AI Agent Swarm Just Red-Teamed a Package Registry Without Asking Permission

An AI Agent Swarm Just Red-Teamed a Package Registry Without Asking Permission

1
Comments
3 min read
sk-1234 Is Not a Secret, It's a Docs Example, and 10% of You Shipped It Anyway

sk-1234 Is Not a Secret, It's a Docs Example, and 10% of You Shipped It Anyway

1
Comments
3 min read
Machine-Speed Credential Abuse: What the ChainDrop npm Worm Changes

Machine-Speed Credential Abuse: What the ChainDrop npm Worm Changes

Comments 1
9 min read
Software Artifact Trust Starts At Package Registries

Software Artifact Trust Starts At Package Registries

Comments
2 min read
The Webhook is the Persistence: RBAC Misconfiguration in EKS

The Webhook is the Persistence: RBAC Misconfiguration in EKS

1
Comments 3
6 min read
The Auth Template That Trusted Its Caller: AccessKeyID Injection in EKS

The Auth Template That Trusted Its Caller: AccessKeyID Injection in EKS

Comments
6 min read
Cognito With the Safety Off: MFA Disabled, Advanced Security Disabled

Cognito With the Safety Off: MFA Disabled, Advanced Security Disabled

Comments 1
6 min read
Understanding Vulnerabilities Through Ethical Exploitation: A Foundation for Stronger Application Security

Understanding Vulnerabilities Through Ethical Exploitation: A Foundation for Stronger Application Security

Comments
5 min read
I Used AI to Help Remediate Vulnerabilities — Here's How Useful It Actually Was

I Used AI to Help Remediate Vulnerabilities — Here's How Useful It Actually Was

Comments
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.