DEV Community

#devsecops

Integrating security practices into the DevOps lifecycle.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
The Command Injection Fix Cursor Writes Still Runs Code (CWE-78)

The Command Injection Fix Cursor Writes Still Runs Code (CWE-78)

Comments
5 min read
🛡️ Vulnerability Math: CVE vs. CVSS vs. EPSS

🛡️ Vulnerability Math: CVE vs. CVSS vs. EPSS

1
Comments
1 min read
Proof-of-Fix in GSC: An Architecture for Provable Vulnerability Remediation Verification

Proof-of-Fix in GSC: An Architecture for Provable Vulnerability Remediation Verification

Comments
7 min read
Networking Foundations: From OSI Layers to TCP Handshakes

Networking Foundations: From OSI Layers to TCP Handshakes

Comments
6 min read
Agentjacking: Your Sentry DSN Lets Attackers Hijack Cursor

Agentjacking: Your Sentry DSN Lets Attackers Hijack Cursor

Comments
5 min read
Every CISO Needs an AIBOM in 2026 and Most Vendors Are Faking It

Every CISO Needs an AIBOM in 2026 and Most Vendors Are Faking It

Comments
9 min read
The IDOR Fix Cursor Writes Stops at the GET Route (CWE-639)

The IDOR Fix Cursor Writes Stops at the GET Route (CWE-639)

Comments 1
9 min read
Turn Trivy SBOM and SARIF output into versioned release evidence

Turn Trivy SBOM and SARIF output into versioned release evidence

Comments
2 min read
Why I Suppressed 30% of Snyk's Recommendations

Why I Suppressed 30% of Snyk's Recommendations

Comments
8 min read
The SSRF Fix Cursor Writes Is Still Vulnerable (CWE-918)

The SSRF Fix Cursor Writes Is Still Vulnerable (CWE-918)

1
Comments 1
6 min read
⚠️ Shai-Hulud opens your IDE: the npm worm that beats --ignore-scripts

⚠️ Shai-Hulud opens your IDE: the npm worm that beats --ignore-scripts

2
Comments
6 min read
Shift-Left Security Is Dead When Cursor Writes the Code

Shift-Left Security Is Dead When Cursor Writes the Code

Comments
5 min read
Why Cursor Installs npm Packages With Known CVEs

Why Cursor Installs npm Packages With Known CVEs

Comments
4 min read
Stop Slopsquatting With a CI Gate, Not a Better Prompt

Stop Slopsquatting With a CI Gate, Not a Better Prompt

Comments
4 min read
Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026

Supply Chain Attacks verstehen: Praktische Tipps zur Abwehr von 2026

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.