DEV Community

#appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Ethical hacking is not a toolset, it is a mindset with a permission slip

Ethical hacking is not a toolset, it is a mindset with a permission slip

Comments
6 min read
6 Best AI Pentesting Tools in 2026

6 Best AI Pentesting Tools in 2026

Comments
12 min read
Six Hours, Thousands of Credentials, and Zero Surprise

Six Hours, Thousands of Credentials, and Zero Surprise

1
Comments
3 min read
Invisible Unicode Tag Characters Just Jumped From Prompt Injection to Phishing

Invisible Unicode Tag Characters Just Jumped From Prompt Injection to Phishing

1
Comments
6 min read
The Auth Template That Trusted Its Caller: AccessKeyID Injection in EKS

The Auth Template That Trusted Its Caller: AccessKeyID Injection in EKS

Comments
6 min read
The Webhook is the Persistence: RBAC Misconfiguration in EKS

The Webhook is the Persistence: RBAC Misconfiguration in EKS

1
Comments 3
6 min read
Understanding Vulnerabilities Through Ethical Exploitation: A Foundation for Stronger Application Security

Understanding Vulnerabilities Through Ethical Exploitation: A Foundation for Stronger Application Security

Comments
5 min read
I Used AI to Help Remediate Vulnerabilities — Here's How Useful It Actually Was

I Used AI to Help Remediate Vulnerabilities — Here's How Useful It Actually Was

Comments
7 min read
ASCII Smuggling Just Graduated From AI Attacks to Your Inbox

ASCII Smuggling Just Graduated From AI Attacks to Your Inbox

1
Comments
5 min read
Your AI Coding Agent Will Run Whatever a Stranger's Repo Tells It To

Your AI Coding Agent Will Run Whatever a Stranger's Repo Tells It To

1
Comments
3 min read
Before and After: Measuring Security Posture Improvement With Real Metrics

Before and After: Measuring Security Posture Improvement With Real Metrics

Comments
6 min read
I pointed my own security tool at my own GitHub Action. It found two bugs.

I pointed my own security tool at my own GitHub Action. It found two bugs.

Comments 1
5 min read
Zero-Day in 24 Hours: How AI-Assisted Exploit Velocity Is Redefining Enterprise Cyber Defense

Zero-Day in 24 Hours: How AI-Assisted Exploit Velocity Is Redefining Enterprise Cyber Defense

Comments
4 min read
Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines

Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines

Comments
12 min read
Your AI Coding Agent Trusts Git More Than It Trusts You

Your AI Coding Agent Trusts Git More Than It Trusts You

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.