DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
LiteLLM Was Backdoored: What the TeamPCP Supply Chain Attack Means for Python AI Projects

LiteLLM Was Backdoored: What the TeamPCP Supply Chain Attack Means for Python AI Projects

Comments
3 min read
I analyzed 250,000 attacks on my Linux servers. Here's what I found.

I analyzed 250,000 attacks on my Linux servers. Here's what I found.

1
Comments
7 min read
How I Built Secure Firebase Cloud Functions with Admin Permissions and Rate Limiting

How I Built Secure Firebase Cloud Functions with Admin Permissions and Rate Limiting

Comments
4 min read
I checked my logs this morning… the traffic wasn’t what I expected

I checked my logs this morning… the traffic wasn’t what I expected

Comments
1 min read
Macaroon Tokens vs API Keys: Why Capability-Based Auth Beats Identity-Based Auth for AI Agents

Macaroon Tokens vs API Keys: Why Capability-Based Auth Beats Identity-Based Auth for AI Agents

Comments
2 min read
(CVE-2026-27489) - Two Incomplete Fixes for a Path Traversal Vulnerability in ONNX

(CVE-2026-27489) - Two Incomplete Fixes for a Path Traversal Vulnerability in ONNX

Comments
1 min read
Building a Domain-Bound Software Licensing System: Architecture Deep Dive

Building a Domain-Bound Software Licensing System: Architecture Deep Dive

Comments
3 min read
Axios Compromise: What Happened, Why It Matters, and What We Should Do Next

Axios Compromise: What Happened, Why It Matters, and What We Should Do Next

Comments
2 min read
I Tested 9 AI Agent Frameworks for Basic Security. None of Them Passed.

I Tested 9 AI Agent Frameworks for Basic Security. None of Them Passed.

Comments
4 min read
Axios Gets 100 Million Downloads a Week. Today, Two Came With a Trojan.

Axios Gets 100 Million Downloads a Week. Today, Two Came With a Trojan.

1
Comments
2 min read
The Axios Attack Proved Vibe Coding's Biggest Blind Spot

The Axios Attack Proved Vibe Coding's Biggest Blind Spot

Comments
6 min read
Indirect Prompt Injection Can Be Stopped by the AI Itself — Embed Directional Context Narrowing into Your Design

Indirect Prompt Injection Can Be Stopped by the AI Itself — Embed Directional Context Narrowing into Your Design

Comments
4 min read
Frontend Security: A Senior Engineer's Guide

Frontend Security: A Senior Engineer's Guide

Comments
6 min read
Someone Backdoored axios on npm. Here is How to Check if You Were Hit

Someone Backdoored axios on npm. Here is How to Check if You Were Hit

Comments
5 min read
Combining Hermes Agent with NVIDIA OpenShell so I can let an AI agent do whatever it wants... inside a cage it can't break out of.

Combining Hermes Agent with NVIDIA OpenShell so I can let an AI agent do whatever it wants... inside a cage it can't break out of.

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.