DEV Community

#infosec

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
12 Questions That Actually Separate Threat Detection Vendors

12 Questions That Actually Separate Threat Detection Vendors

Comments
8 min read
THE DARK SIDE OF DNS: WEAPONIZING RECURSIVE RESOLVERS FOR STEALTH DATA EXFILTRATION

THE DARK SIDE OF DNS: WEAPONIZING RECURSIVE RESOLVERS FOR STEALTH DATA EXFILTRATION

1
Comments
8 min read
Patch Tuesday September 2026: 2 Zero-Days, 119 Critical Fixes Among 1186 CVEs

Patch Tuesday September 2026: 2 Zero-Days, 119 Critical Fixes Among 1186 CVEs

Comments
3 min read
HTB - Funnel

HTB - Funnel

Comments
3 min read
HTB - Preignition

HTB - Preignition

Comments
1 min read
StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell

StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell

Comments
5 min read
When Critical Infrastructure Gets Hacked: What the Rand Water Cyber Incident Teaches Us About IT, OT and Cyber Resilience

When Critical Infrastructure Gets Hacked: What the Rand Water Cyber Incident Teaches Us About IT, OT and Cyber Resilience

Comments
5 min read
A Clean Penetration Test Report Does Not Mean You Are Secure. I Write These Reports, and Here Is What They Actually Prove.

A Clean Penetration Test Report Does Not Mean You Are Secure. I Write These Reports, and Here Is What They Actually Prove.

Comments
7 min read
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

Comments
6 min read
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Comments
5 min read
Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Comments
6 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

Comments
5 min read
SAML XSW: Signatures That Validate the Wrong Element

SAML XSW: Signatures That Validate the Wrong Element

Comments
5 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

Comments
6 min read
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.