DEV Community

#infosec

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
HTB - Funnel

HTB - Funnel

Comments
3 min read
HTB - Responder

HTB - Responder

Comments
5 min read
HTB - Preignition

HTB - Preignition

Comments
1 min read
StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell

StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell

Comments
5 min read
When Critical Infrastructure Gets Hacked: What the Rand Water Cyber Incident Teaches Us About IT, OT and Cyber Resilience

When Critical Infrastructure Gets Hacked: What the Rand Water Cyber Incident Teaches Us About IT, OT and Cyber Resilience

Comments
5 min read
A Clean Penetration Test Report Does Not Mean You Are Secure. I Write These Reports, and Here Is What They Actually Prove.

A Clean Penetration Test Report Does Not Mean You Are Secure. I Write These Reports, and Here Is What They Actually Prove.

Comments
7 min read
Why CIDS Looks at Behavior, Not Just Individual Requests

Why CIDS Looks at Behavior, Not Just Individual Requests

Comments
3 min read
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

Comments
6 min read
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Comments
5 min read
SAML XSW: Signatures That Validate the Wrong Element

SAML XSW: Signatures That Validate the Wrong Element

Comments
5 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Comments
5 min read
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Comments
5 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

Comments
6 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

Comments
5 min read
Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.