Tech Skills
Cybersecurity
Ethical hacking, penetration testing, network security, CTFs and defensive security
Skills in this topic
9 skills — Sign in to track your progress
Security Basics
beginner
Fix OWASP top 10 vulnerabilities
Cryptography Fundamentals
intermediate
Explain how digital signatures prevent tampering
AI Security
intermediate
Identify and patch prompt injection vulnerabilities
Network Security
intermediate
Configure a firewall with proper inbound/outbound rules
Ethical Hacking & Pen Testing
intermediate
Conduct a full pen test with Kali Linux
Cloud Security
intermediate
Implement IAM least-privilege policies on AWS/GCP
Incident Response
intermediate
Build an incident response playbook
Security Compliance
intermediate
Map controls for SOC 2 Type II compliance
Defensive AI
advanced
Build an AI-powered log anomaly detector
Simon Willison's Blog
🔐 Cybersecurity
⚡ AI Lesson
4d ago
Quoting Calif Research
Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...] The victim does not need to answ
Simon Willison's Blog
🔐 Cybersecurity
⚡ AI Lesson
6d ago
Creepy crawlies
Creepy crawlies Konstantin Ryabitsev discusses how bad the "background radiation" of abusive crawlers has become from the perspective of git.kernel.org , the of
Simon Willison's Blog
🔐 Cybersecurity
⚡ AI Lesson
1w ago
The purpose of DNS is to spread scams
The purpose of DNS is to spread scams Terence Eden shares some daunting statistics in support of his take that "the Domain Name System's purpose seems to be a v

Dev.to · Mino Randriamanivo
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Maintenance & security Journey in 2026 - Post-mortem measures in GHOST compromised websites
Hi, An attack was ran on multiple Ghost websites (https://kahiether.com/, etc..) this summer, 3rd...

Dev.to · Finley Zhou
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Give Every Agent Patch a Regression Budget, Not Just a Green Check
A green CI run is not a verdict. It is a photograph taken at one moment, under one seed, with one set...

Dev.to · BeckettHayes6821
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Bot-Resistant Account Deletion Workflow for Consent Cleanup and Session Revocation
Short answer: make deletion a two-phase, abuse-resistant workflow that proves user intent, revokes...

Dev.to · Dmytro Polianskyi
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Your camera roll is part of your developer threat model
Developers spend a lot of time protecting source repositories, CI secrets, cloud consoles, and...

Dev.to · tony chen
🔐 Cybersecurity
⚡ AI Lesson
1w ago
5 Recovery Rules for Signup Bot Defense — CAPTCHA Before Account Creation
Signup bot defense is an account-lifecycle decision, not a widget decision. For a property-management...

Dev.to · Dmytro Polianskyi
🔐 Cybersecurity
⚡ AI Lesson
1w ago
How On-Device Sensitive Photo Scanning Works
“Local” should describe a data path, not a marketing mood. Here is what to verify before allowing a...

Dev.to · LunarBreeze4173085
🔐 Cybersecurity
⚡ AI Lesson
1w ago
5 Guardrails for E-commerce Login Callbacks: Choosing Providers and Local Sessions
An e-commerce login callback is an abuse-control boundary, not a redirect handler. Short answer:...

Dev.to · 仪袁韶
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Multi-model routing with one key: BYOK failover explained (2026)
← All guides One key, four models: BYOK failover explained A bring-your-own-key gateway lets you...

Dev.to · MiloHastings5316
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Analytics Identity Gates — Provisioning, Session Lifetimes, and Consent Evidence
Short answer: treat workspace access as an auditable state machine, keep phone OTP as one...

Dev.to · pm25coder
🔐 Cybersecurity
⚡ AI Lesson
1w ago
A credential fetch is a read: the containment guard your write-target sandbox was missing
A credential fetch is a read: the containment guard your write-target sandbox was...

Dev.to · Trkfpn392751
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Server-Side CAPTCHA Verification Before Account Creation Explained (Signup Bot Defense)
Short answer: verify the CAPTCHA at the account-creation service boundary, record that decision as an...

Dev.to · NevilleChristensen2637
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Gateway Token Validation Options — A 4-Step JWKS Choice for Game Signup
Short answer: for a game signup gateway, validate JWTs with a cached public-key set, refresh on...

Dev.to · Tiago Vilas Boas (Montanha)
🔐 Cybersecurity
⚡ AI Lesson
1w ago
O prompt de AppSec que eu criei achou 1 gap em 174 rotas.
Pessoal, eu quase abri uma issue com uma lista. O modelo tinha devolvido XSS, CORS, CSP, um SVG...

Dev.to · Abd El-latif
🔐 Cybersecurity
⚡ AI Lesson
1w ago
The Security Fix That Would Have Silently Broken My Feature
I recently shipped Mermaid diagram support to Forem, the open source platform that powers DEV. Fenced...

Dev.to · Jason Miller
🔐 Cybersecurity
⚡ AI Lesson
1w ago
CVE-2026-32193 Is a Copilot Hijack Disguised as a Boring Path Traversal
The official record is one sentence: an "authorized attacker," a local path traversal in Azure...

Dev.to · Etairos.ai
🔐 Cybersecurity
⚡ AI Lesson
1w ago
BGP Hijack Delivered a Backdoored Virtualizor Update to VPS Hosts
TL;DR what: An attacker falsely announced a block of Hetzner-hosted IP addresses...

Dev.to · Kaustav Sarkar
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Patterns, Anti-Patterns, and Operational Reality
This blog is a part of the Zero-Trust Security on Istio Series, if you haven't read the previous...

Dev.to · Deep Fix
🔐 Cybersecurity
⚡ AI Lesson
1w ago
How to Resolve SSL/TLS Certificate Handshake Failures – Step-by-Step Guide for Developers
Introduction SSL/TLS handshake failures cripple web services, CI pipelines, and...

Dev.to · Seceon_inc
🔐 Cybersecurity
⚡ AI Lesson
1w ago
AI SOC vs Traditional SOC: What’s the Difference?
The debate over AI SOC vs traditional SOC has moved from theoretical to urgent. Security teams face...

Dev.to · Cub4nH1
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Sicurezza API REST: best practices
Meta description: Scopri le best practice per la sicurezza delle API REST. Guida completa con esempi...

Dev.to · BeyondMachines
🔐 Cybersecurity
⚡ AI Lesson
1w ago
Orient Blackswan Hit by Ransomware Attack in Hyderabad
Orient Blackswan, a publishing house in Hyderabad, suffered a ransomware attack that encrypted business data and disrupted their IT infrastructure. The company

Dev.to · BramwellVance7953
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Two-Factor Authentication Explained — Go SMS, Email Fallback, Delivery Polling
Short answer: use SMS as the first delivery channel, poll its delivery state against a bounded...

Dev.to · TokenPAPA
🔐 Cybersecurity
⚡ AI Lesson
2w ago
TokenPAPA Security & Privacy: How We Handle Your Data
How TokenPAPA protects your data: TLS 1.3 encryption in transit, AES-256 at rest, hashed API keys, Stripe payment security, no training on your prompt

Dev.to · Shaan Satsangi
🔐 Cybersecurity
⚡ AI Lesson
2w ago
The approval signature that could be spent twice
I built this project and wrote this article for the purposes of entering the Google Cloud "All Things...

Dev.to · Michael "Mike" K. Saleme
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Can your security test suite fail? Mine passed against nothing.
Most security test suites answer one question: did the attack succeed? The verdict then falls out of...

Dev.to · Svyatoslav Pavlov
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Host key verification failed: what it means and the right way to fix it
Near the top of every search result for this error sits the same one-liner: -o...

Dev.to · ilya mozerov
🔐 Cybersecurity
⚡ AI Lesson
2w ago
My scanner reported honest coverage every day, and it was the same coverage every day
I have a tool whose whole job is catching tools that lie. The idea is small. A lot of my scripts...
Simon Willison's Blog
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Just a rumour of a bug is enough to find a security exploit these days
Just a rumour of a bug is enough to find a security exploit these days Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer o

Dev.to · Todd Linnertz
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Governance You Can't Grep Isn't Governance
Earlier this month I clicked a button labeled Freeze, and a validator told me my artifact was...

Dev.to · Bonnie Smyre
🔐 Cybersecurity
⚡ AI Lesson
2w ago
The Growing Threat: Attackers Using GitHub Repositories as Malware Staging Mechanisms
This blog was originally published by Brian Tant on the Raxis blog January 21, 2026 GitHub has...

Dev.to · Lily
🔐 Cybersecurity
⚡ AI Lesson
2w ago
3 Wrong Guesses About a Chrome Slot Limit: 3 6 Reserved Lanes
Automation doesn't break when you write it. It breaks in production, weeks later, quietly — and my...

Dev.to · Rocky
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Your First Cloud Pentest Isn't Going to Play Out Like Your Last AD Engagement
First cloud-focused engagement, and the plan going in looked like every internal AD assessment before...

Dev.to · Sangyeon Park
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Your Security Scanner Has a Blind Spot: Streaming
I spent an afternoon convinced my detector was broken. I was building Cencurity, a local gateway...

Dev.to · Vipul Singh
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Your JWT Decoder Should Never Ask for Your Signing Secret
A JWT looks like gibberish until you decode it — three Base64URL segments separated by dots: header,...

Dev.to · Olga Larionova
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Google Staff Security Engineer Interview Prep: Cloud CISO, Product Security, Coding, and Domain-Specific Questions
Introduction to the Google Staff Security Engineer Interview Securing a Staff Security...

Dev.to · Peter Jackman
🔐 Cybersecurity
⚡ AI Lesson
2w ago
The Voice-AI Vendor Security Questionnaire: 12 Questions About Recordings, PII and Model Training
Short answer: Before signing an AI voice or AI sales-agent vendor, get written answers to twelve questions: recording storage and location, retention and deleti

Dev.to · Rasika Dangamuwa
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Why TOTP 2FA Verification Fails in Production: 5 Cryptographic Edge Cases
Implementing Time-Based One-Time Passwords (TOTP, RFC 6238) seems straightforward: generate a 160-bit...

Dev.to · Android 小行家
🔐 Cybersecurity
⚡ AI Lesson
2w ago
XopProtector: An Open Source Android APK Protection Framework Ready for Real-World Production
XopProtector: An Open Source Android APK Protection Framework Ready for Real-World...

Dev.to · wartzar-bee
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Your agent's 'secure' network policy was off unless you did four steps — so it was off
enclave 0.8.0 makes the safe autonomous-agent config the default instead of a ritual. The lesson: an opt-in control with a four-step activation cost is a contro

Dev.to · bozoinc
🔐 Cybersecurity
⚡ AI Lesson
2w ago
SBOM-for-Agents: The Missing Trust Layer for Agent Supply Chains
Introduction Software Bill of Materials (SBOMs) are now a standard requirement for enterprise...

Dev.to · Fewparts
🔐 Cybersecurity
⚡ AI Lesson
2w ago
A symlink walks straight out of an agent's write allow-list
path.resolve never opens anything. A link inside your allow-list reads as in scope, and the write lands outside it — here's the escape, the fix, and the bug the

Dev.to · Rasika Dangamuwa
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Why Webhook HMAC Verification Fails in Production: 5 Cryptographic Traps Every Developer Misses
You’ve set up your webhook endpoint to receive payment notifications from Stripe, pull request alerts...

Dev.to · CVE Reports
🔐 Cybersecurity
⚡ AI Lesson
2w ago
CVE-2026-45019: CVE-2026-45019: Server-Side Request Forgery (SSRF) in Chainlit MCP Endpoint
CVE-2026-45019: Server-Side Request Forgery (SSRF) in Chainlit MCP Endpoint Vulnerability...

Dev.to · Humza Tareen
🔐 Cybersecurity
⚡ AI Lesson
2w ago
GCS Race Conditions & Generation-Fenced Leases
Two race conditions in distributed step leasing where stale workers deleted fresh locks — fixed with GCS generation-based optimistic concurrency.

Dev.to · Olivier Bourgeois
🔐 Cybersecurity
⚡ AI Lesson
2w ago
Taking control of cluster security: A deep dive into GKE ClusterNetworkPolicy
Discover how GKE ClusterNetworkPolicy enables platform teams to establish global security guardrails without hindering developer agility
DeepCamp AI