✕ Clear all filters
16 articles
▶ Videos →

📰 Dev.to · Patience Mpofu

16 articles · Updated every 3 hours · View all reads

All Articles 131,075Blog Posts 136,076Tech Tutorials 33,950Research Papers 25,448News 18,608 ⚡ AI Lessons
Training on Synthetic Data: How to Build an ML Security Tool Without Touching Real Leaked Secrets
Dev.to · Patience Mpofu 📐 ML Fundamentals ⚡ AI Lesson 2mo ago
Training on Synthetic Data: How to Build an ML Security Tool Without Touching Real Leaked Secrets
Before I wrote a single line of model training code, I made a decision that constrained everything...
Why I Chose Random Forest Over Deep Learning for Secrets Detection
Dev.to · Patience Mpofu 📐 ML Fundamentals ⚡ AI Lesson 2mo ago
Why I Chose Random Forest Over Deep Learning for Secrets Detection
Every time I mention that my secrets detector uses a Random Forest classifier, someone asks the same...
Why the Variable Name Is the Most Important Feature in Secrets Detection
Dev.to · Patience Mpofu 2mo ago
Why the Variable Name Is the Most Important Feature in Secrets Detection
ere's a question that sounds trivial until you think about it carefully. Are these two lines of code...
The 26-Dimensional Feature Vector: How a Machine Learns to Recognise a Secret
Dev.to · Patience Mpofu 2mo ago
The 26-Dimensional Feature Vector: How a Machine Learns to Recognise a Secret
hen my secrets detector evaluates a candidate string, it doesn't see code. It sees a vector of 26...
Why I Built an ML-Powered Secrets Detector Instead of Just Using Regex
Dev.to · Patience Mpofu 📐 ML Fundamentals ⚡ AI Lesson 2mo ago
Why I Built an ML-Powered Secrets Detector Instead of Just Using Regex
ost secrets scanners work the same way. They maintain a list of regex patterns — one for AWS access...
What Building a SAST Tool Taught Me About AppSec That 13 Years of Software Engineering Didn't
Dev.to · Patience Mpofu 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
What Building a SAST Tool Taught Me About AppSec That 13 Years of Software Engineering Didn't
I've been writing software professionally since 2011. Java, C#, Kotlin, Node.js. Enterprise...
False Positives in SAST — How I Built Suppression Into My Scanner and Why It Matters
Dev.to · Patience Mpofu 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
False Positives in SAST — How I Built Suppression Into My Scanner and Why It Matters
There's a failure mode that kills security tooling programmes quietly, without drama, and it's not a...
The Adoption Trap to Avoid
Dev.to · Patience Mpofu ⚡ AI Lesson 2mo ago
The Adoption Trap to Avoid
The single biggest mistake teams make with CI/CD-integrated security tooling is treating it as a...
Writing Custom SAST Rules for Vulnerabilities Your Scanner Doesn't Cover
Dev.to · Patience Mpofu 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
Writing Custom SAST Rules for Vulnerabilities Your Scanner Doesn't Cover
Every SAST tool ships with a default ruleset. And every default ruleset has gaps. Sometimes the gap...
How I Modelled the OWASP Top 10 Into a YAML Rule Engine
Dev.to · Patience Mpofu 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
How I Modelled the OWASP Top 10 Into a YAML Rule Engine
When I set out to write detection rules for my SAST tool, I didn't start with a list of regex...
I Built a SAST Scanner From Scratch — Here's Every Design Decision I Made
Dev.to · Patience Mpofu 🔐 Cybersecurity ⚡ AI Lesson 2mo ago
I Built a SAST Scanner From Scratch — Here's Every Design Decision I Made
When most developers want to scan their code for security vulnerabilities, they install Semgrep or...
I Built a SAST Scanner from Scratch and Ran It Against 4 Famous Vulnerable Apps — Here's What It Found
Dev.to · Patience Mpofu 🔐 Cybersecurity ⚡ AI Lesson 4mo ago
I Built a SAST Scanner from Scratch and Ran It Against 4 Famous Vulnerable Apps — Here's What It Found
Static Application Security Testing (SAST) tools are a staple of any mature AppSec programme. Tools...