Website profile

@Thepracticaldev

A constructive and inclusive social network for software developers. With you every step of your journey.

  • 10,482articles · 30d
  • 2+ hour agolatest article
  • Aug 14, 2026earliest in window
  • 97%with images
  • 293avg words
articles per day
Categories
  • Software Dev. 9,686
  • Science & Technology 9,559
  • Computers & Electronics 7,403
  • Business & Industrial 810
  • Internet & Telecom 769
  • Economy, Business & Finance 383
  • Finance 333
  • Arts, Culture, Entertainment & Media 245

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

DEV Community
dev.to > sudeephazra > ai-security-scanning-needs-evidence-not-just-more-agents-2mlb

AI Security Scanning Needs Evidence, Not Just More Agents

2+ hour, 59+ min ago   (994+ words) Google’s Mantis caught my attention because it points to a problem most AI security demos quietly walk around: finding a vulnerability is not the same as proving one exists. That distinction matters. Security teams already live with noisy scanners, half-useful…...

DEV Community
dev.to > artem_sulyma > security-by-design-1goc

Security by Design

3+ hour, 23+ min ago   (752+ words) Ask a manufacturer what "security by design" means and you get something abstract: we think about security early, we do not bolt it on at the end. It is one of those phrases that gets used everywhere and defined nowhere....

DEV Community
dev.to > balbaks > i-ran-my-scanner-against-5-real-cves-it-missed-4-then-i-reverted-my-own-fix-4dhk

I ran my scanner against 5 real CVEs. It missed 4. Then I reverted my own fix.

14+ hour ago   (657+ words) Why this post is different from the last one The last write-up in this series announced four tools. This one is about what happened when I stopped writing tests for my own tools and started checking one of them against…...

DEV Community
dev.to > pavan-kumar-appannagari > when-ai-finds-bugs-faster-than-teams-can-patch-them-2cbl

When AI Finds Bugs Faster Than Teams Can Patch Them

21+ hour, 26+ min ago   (727+ words) The most compelling AI story emerging in 2026 isn't about chatbots, image generation, or code autocompletion. It comes from the defensive security space. In April 2026, Anthropic launched Project Glasswing, granting technology leaders and critical infrastructure providers early access to Claude Mythos…...

DEV Community
dev.to > umair24171 > fixing-ai-agent-supply-chain-attack-nodejs-blueprint-2plc

Fixing AI Agent Supply Chain Attack: Node.js Blueprint

1+ day, 3+ hour ago   (549+ words) This article was originally published on BuildZn. Key vectors for an ai agent supply chain attack: This is why ai agent attack prevention needs to be baked in from day one. You can't just trust the agent's "reasoning." My approach…...

DEV Community
dev.to > uhltak > die-xz-backdoor-weckruf-fur-die-open-source-sicherheit-4ph9

Die XZ-Backdoor: Weckruf für die Open-Source-Sicherheit

3+ day, 5+ hour ago   (249+ words) Um das Ausmaß des Vorfalls zu verstehen, müssen wir die Ereignisse Schritt für Schritt nachvollziehen. Es ist eine Geschichte, die sich wie ein Cyber-Thriller liest, aber bittere Realität ist. Hätte Freund diese kleine Anomalie ignoriert, wäre die Backdoor unentdeckt in…...

DEV Community
dev.to > muskan_bandta > gpt-6-astra-shipped-with-its-zero-day-skill-behind-a-gate-heres-what-gated-capability-means-for-3151

GPT-6 Astra Shipped With Its Zero-Day Skill Behind a Gate. Here's What 'Gated Capability' Means for the Rest of Us.

3+ day, 6+ hour ago   (297+ words) Normally a model ships and everything it can do ships with it. Astra breaks that pattern: OpenAI decoupled the dangerous capability from the general release. You can use GPT-6 Astra; you cannot casually ask it to weaponize a zero-day, because…...

DEV Community
dev.to > arisyndata > why-rbac-alone-isnt-enough-for-enterprise-data-agents-3b4f

Why RBAC Alone Isn't Enough for Enterprise Data Agents

3+ day, 9+ hour ago   (525+ words) A user can be blocked from a sensitive column and still receive sensitive information derived from... Tagged with ai, agents, llm, sql....

DEV Community
dev.to > xulingfeng > stratagems-30-lena-signed-the-client-the-ai-didnt-know-it-was-being-audited-3985

Stratagems #30: Lena Signed the Client. The AI Didn't Know It Was Being Audited.

3+ day, 10+ hour ago   (1408+ words) Come to check the locks, and leave holding the keys. Slip in through the gap, take the host's seat,... Tagged with ai, discuss, career, programming....

DEV Community
dev.to > njenga_nganga_00063bc67 > the-dark-side-of-dns-weaponizing-recursive-resolvers-for-stealth-data-exfiltration-85g

THE DARK SIDE OF DNS: WEAPONIZING RECURSIVE RESOLVERS FOR STEALTH DATA EXFILTRATION

3+ day, 20+ hour ago   (1612+ words) Recursive DNS resolvers can turn a routine name-lookup service into a quiet exfiltration relay, carrying encoded data through infrastructure most organizations allow by default. DNS is trusted because it is necessary. Workstations need it. Servers need it. Cloud workloads need…...