DEV Community

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
DAST false negatives vs SAST false positives: a real case

DAST false negatives vs SAST false positives: a real case

1
Comments
10 min read
Cache Poisoning at the Edge: How Cloudflare Workers & Vercel Edge Functions Break Everything You Thought You Knew

Cache Poisoning at the Edge: How Cloudflare Workers & Vercel Edge Functions Break Everything You Thought You Knew

Comments
7 min read
AI Coding Agents Are the New Attack Surface Nobody's Ready For

AI Coding Agents Are the New Attack Surface Nobody's Ready For

1
Comments
3 min read
Mobile App Authentication: Best Practices for iOS and Android Developers (2026)

Mobile App Authentication: Best Practices for iOS and Android Developers (2026)

Comments
17 min read
Palo Alto Unit 42 Caught Indirect Prompt Injection in the Wild — Here's What Your Agent Firewall Needs to Stop It

Palo Alto Unit 42 Caught Indirect Prompt Injection in the Wild — Here's What Your Agent Firewall Needs to Stop It

1
Comments
5 min read
How Malicious MCP Configs in Amazon Q Developer Could Execute Arbitrary Code — and How to Stop It

How Malicious MCP Configs in Amazon Q Developer Could Execute Arbitrary Code — and How to Stop It

Comments
5 min read
Protecting Developers Means Protecting Their Secrets

Protecting Developers Means Protecting Their Secrets

Comments
10 min read
The Tool Found Corridor Nodes — But the Bigger Finding Was Where It Found None

The Tool Found Corridor Nodes — But the Bigger Finding Was Where It Found None

Comments
5 min read
Claude Code Security: Why the Real Risk Lies Beyond Code

Claude Code Security: Why the Real Risk Lies Beyond Code

Comments 1
5 min read
Who Actually Owns This Service Account?

Who Actually Owns This Service Account?

Comments
5 min read
North Korean Hackers Poisoned 140+ npm Packages in an AI Dev Tooling Attack. Here's What Would Have Caught It.

North Korean Hackers Poisoned 140+ npm Packages in an AI Dev Tooling Attack. Here's What Would Have Caught It.

1
Comments
4 min read
The Service That Stored Nothing Sensitive But Still Became High Priority

The Service That Stored Nothing Sensitive But Still Became High Priority

Comments
7 min read
Security First, Transparency Always: Inside GitGuardian's Responsible Disclosure Process

Security First, Transparency Always: Inside GitGuardian's Responsible Disclosure Process

5
Comments
4 min read
Why Security Should Be Modeled as a Graph

Why Security Should Be Modeled as a Graph

Comments
7 min read
DBD Cornucopia is now available to play online!

DBD Cornucopia is now available to play online!

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.