Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
HTTPS Isn’t Optional, It’s the Boundary of Your System
Cover image for HTTPS Isn’t Optional, It’s the Boundary of Your System

HTTPS Isn’t Optional, It’s the Boundary of Your System

Comments
2 min read
How to Secure Your CI/CD Pipeline End-to-End (With Real Tools)

How to Secure Your CI/CD Pipeline End-to-End (With Real Tools)

1
Comments 1
3 min read
The Agentic Software Factory: How AI Teams Debate, Code, and can Secure Enterprise Infrastructure

The Agentic Software Factory: How AI Teams Debate, Code, and can Secure Enterprise Infrastructure

3
Comments 1
13 min read
Field Guide v0.1 What is inside and where to start

Field Guide v0.1 What is inside and where to start

Comments
2 min read
⚙️ Persistent Threat Via Environment Vars
Cover image for ⚙️ Persistent Threat Via Environment Vars

⚙️ Persistent Threat Via Environment Vars

Comments
6 min read
Webhook Security Best Practices for Production 2025-2026
Cover image for Webhook Security Best Practices for Production 2025-2026

Webhook Security Best Practices for Production 2025-2026

1
Comments
7 min read
Week 7 Scripting Challenge: JWT Token Validation

Week 7 Scripting Challenge: JWT Token Validation

3
Comments
21 min read
Aider + OpenClaw: How Autonomous Exploit Generators Rewrite the Rules of Security Research
Cover image for Aider + OpenClaw: How Autonomous Exploit Generators Rewrite the Rules of Security Research

Aider + OpenClaw: How Autonomous Exploit Generators Rewrite the Rules of Security Research

3
Comments
4 min read
CVE-2025-22234: The 73rd Byte: How a Spring Security Fix Created a Timing Leak

CVE-2025-22234: The 73rd Byte: How a Spring Security Fix Created a Timing Leak

Comments
2 min read
JWT Algorithm Confusion Attack: Two Active CVEs in 2026

JWT Algorithm Confusion Attack: Two Active CVEs in 2026

1
Comments 1
4 min read
GHSA-JP3Q-WWP3-PWV9: Freeform, Free Execution: Stored XSS in Craft CMS's Favorite Form Builder

GHSA-JP3Q-WWP3-PWV9: Freeform, Free Execution: Stored XSS in Craft CMS's Favorite Form Builder

Comments
2 min read
Every protocol your agent speaks, scanned

Every protocol your agent speaks, scanned

Comments
4 min read
We Built an Open-Source Prompt Injection Attack Console. Here's Why.

We Built an Open-Source Prompt Injection Attack Console. Here's Why.

1
Comments 2
3 min read
Your AI Agent Just Ran rm -rf / — Here's How to Stop It

Your AI Agent Just Ran rm -rf / — Here's How to Stop It

Comments 2
3 min read
I Found an API Key I Deleted 18 Months Ago Still Living in My Git History

I Found an API Key I Deleted 18 Months Ago Still Living in My Git History

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.