Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I Built a Free API Vulnerability Scanner — It Found 23 Issues in My Own Code

I Built a Free API Vulnerability Scanner — It Found 23 Issues in My Own Code

Comments
5 min read
The 5 Security Holes in Almost Every MCP Server (And How to Find Them)

The 5 Security Holes in Almost Every MCP Server (And How to Find Them)

Comments
3 min read
A Deny Read Bug in Claude Code's Bubblewrap Sandbox

A Deny Read Bug in Claude Code's Bubblewrap Sandbox

1
Comments
2 min read
Is Your Crypto Bounty Token a Security? A Developer's Guide to the Howey Test
Cover image for Is Your Crypto Bounty Token a Security? A Developer's Guide to the Howey Test

Is Your Crypto Bounty Token a Security? A Developer's Guide to the Howey Test

1
Comments
8 min read
SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page
Cover image for SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

Comments
3 min read
I built a CI/CD tool that auto-heals broken pipelines, runs 6 security scans, and works from your IDE via MCP

I built a CI/CD tool that auto-heals broken pipelines, runs 6 security scans, and works from your IDE via MCP

1
Comments
2 min read
hash23 - A constexpr implementation of different hashing algorithms
Cover image for hash23 - A constexpr implementation of different hashing algorithms

hash23 - A constexpr implementation of different hashing algorithms

2
Comments
1 min read
SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate
Cover image for SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

Comments
3 min read
I Scanned 500 npm Packages for Typosquatting — 23 Were Suspicious

I Scanned 500 npm Packages for Typosquatting — 23 Were Suspicious

Comments
3 min read
I Built a Supply Chain Scanner for Python — pip Has the Same Problem as npm

I Built a Supply Chain Scanner for Python — pip Has the Same Problem as npm

Comments
3 min read
SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem
Cover image for SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

Comments
3 min read
SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

Comments
3 min read
LiteLLM PyPI Compromise Is Just the Beginning — How to Audit Your Python Dependencies Right Now

LiteLLM PyPI Compromise Is Just the Beginning — How to Audit Your Python Dependencies Right Now

Comments
4 min read
MP1 Write‑Up – Stack Smashing

MP1 Write‑Up – Stack Smashing

1
Comments
6 min read
Prompt Injection Prevention: Building Secure AI Systems with Claude Code

Prompt Injection Prevention: Building Secure AI Systems with Claude Code

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.