DEV Community

#appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Running Snyk on Real Legacy Java Code — The Full Unfiltered Results

Running Snyk on Real Legacy Java Code — The Full Unfiltered Results

Comments
10 min read
HTB Orion — CraftCMS RCE, a Reverse Shell That Wouldn't Connect, and a Telnetd Auth Bypass

HTB Orion — CraftCMS RCE, a Reverse Shell That Wouldn't Connect, and a Telnetd Auth Bypass

Comments
4 min read
An AI "Escaped Its Sandbox" — Or We Just Built a Bad Sandbox

An AI "Escaped Its Sandbox" — Or We Just Built a Bad Sandbox

1
Comments 1
3 min read
How to Prevent API Keys and Secrets from Leaking into LLMs

How to Prevent API Keys and Secrets from Leaking into LLMs

Comments
2 min read
We Just Handed AI Agents the Keys to the Password Vault. What Could Go Wrong?

We Just Handed AI Agents the Keys to the Password Vault. What Could Go Wrong?

1
Comments
3 min read
Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Clinejection: How a GitHub Issue Title Compromised an AI Coding Assistant Used by 5M Developers

Comments
3 min read
Your AI Agent's Memory Is Now an Attack Surface, and Nobody Designed for That

Your AI Agent's Memory Is Now an Attack Surface, and Nobody Designed for That

1
Comments
3 min read
GitLost Is a Preview of Every Agentic Workflow Breach You'll See This Year

GitLost Is a Preview of Every Agentic Workflow Breach You'll See This Year

1
Comments
3 min read
AI-Run Ransomware: The Autopilot Was Impressive, the Pilot Still Booked the Flight

AI-Run Ransomware: The Autopilot Was Impressive, the Pilot Still Booked the Flight

1
Comments
3 min read
Hardening my own Nmap web UI: the security holes I shipped, and what actually saved me

Hardening my own Nmap web UI: the security holes I shipped, and what actually saved me

2
Comments
4 min read
Your Phishing Simulation Score Is 99%. Here's Why That Worries Me.

Your Phishing Simulation Score Is 99%. Here's Why That Worries Me.

Comments
4 min read
"183 Local Tools, Zero Guardrails: What Local MCP Gets Wrong About 'Privacy'"

"183 Local Tools, Zero Guardrails: What Local MCP Gets Wrong About 'Privacy'"

Comments
3 min read
HalluSquatting: How Attackers Turn AI Coding Agents Into a Botnet Without Touching a Single Victim

HalluSquatting: How Attackers Turn AI Coding Agents Into a Botnet Without Touching a Single Victim

1
Comments 1
5 min read
Agentic AI Security: Risks, OWASP Agentic Top 10, and Defensive Patterns (2026)

Agentic AI Security: Risks, OWASP Agentic Top 10, and Defensive Patterns (2026)

Comments
13 min read
Your Coding Agent Is a New Attack Surface and Most Devs Aren't Ready for It

Your Coding Agent Is a New Attack Surface and Most Devs Aren't Ready for It

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.