DEV Community

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Agentjacking: How AI Coding Agents Get Hijacked Through Their Own Tool Pipeline

Agentjacking: How AI Coding Agents Get Hijacked Through Their Own Tool Pipeline

1
Comments
5 min read
LangGraph RCE Chain: How Malicious Tool Calls Escalate to Full Host Compromise

LangGraph RCE Chain: How Malicious Tool Calls Escalate to Full Host Compromise

1
Comments 1
5 min read
The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub

The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub

Comments
6 min read
Claude Fable 5 Was Jailbroken in 48 Hours. Here's What Actually Stopped Nothing.

Claude Fable 5 Was Jailbroken in 48 Hours. Here's What Actually Stopped Nothing.

1
Comments
5 min read
AI Email Agents Are Phishable: How OpenClaw Spilled User Data to Social Engineering Attacks

AI Email Agents Are Phishable: How OpenClaw Spilled User Data to Social Engineering Attacks

2
Comments
4 min read
The Invisible Breach: Why Modern Web Frameworks Aren't Immune to LFI

The Invisible Breach: Why Modern Web Frameworks Aren't Immune to LFI

Comments
8 min read
OpenAI Built a Lockdown Mode Because Tool-Based Data Exfiltration Is Real — Here's What Catches It Earlier

OpenAI Built a Lockdown Mode Because Tool-Based Data Exfiltration Is Real — Here's What Catches It Earlier

1
Comments
5 min read
Python’s Private Variables Aren't Private: An AppSec Reality Check

Python’s Private Variables Aren't Private: An AppSec Reality Check

Comments
2 min read
Notification Hijacking: How WhatsApp and Slack Content Could Weaponize Google Gemini

Notification Hijacking: How WhatsApp and Slack Content Could Weaponize Google Gemini

1
Comments
5 min read
Hidden in Plain Sight: How Notification Prompt Injection Can Hijack Your AI Assistant

Hidden in Plain Sight: How Notification Prompt Injection Can Hijack Your AI Assistant

1
Comments
4 min read
How Meta's AI Support Bot Got Tricked Into Hijacking Instagram Accounts

How Meta's AI Support Bot Got Tricked Into Hijacking Instagram Accounts

1
Comments
5 min read
When Your Background AI Agent Becomes a C2 Server

When Your Background AI Agent Becomes a C2 Server

2
Comments
4 min read
Dangerous MCP OAuth Shortcuts are Ruining Security

Dangerous MCP OAuth Shortcuts are Ruining Security

1
Comments
1 min read
GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

Comments
8 min read
The Business Context Problem: Why Vulnerability Severity Scores Lie

The Business Context Problem: Why Vulnerability Severity Scores Lie

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.