Tech Skills

Cybersecurity

Ethical hacking, penetration testing, network security, CTFs and defensive security

32,547
lessons
Skills in this topic
View full skill map →
Security Basics
beginner
Fix OWASP top 10 vulnerabilities
Cryptography Fundamentals
intermediate
Explain how digital signatures prevent tampering
AI Security
intermediate
Identify and patch prompt injection vulnerabilities
Network Security
intermediate
Configure a firewall with proper inbound/outbound rules
Ethical Hacking & Pen Testing
intermediate
Conduct a full pen test with Kali Linux
Cloud Security
intermediate
Implement IAM least-privilege policies on AWS/GCP
Incident Response
intermediate
Build an incident response playbook
Security Compliance
intermediate
Map controls for SOC 2 Type II compliance
Defensive AI
advanced
Build an AI-powered log anomaly detector
All Reads (24,263) Articles (13188)Blog Posts (8694)Tutorials (871)Research Papers (70)News (1440)
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 4d ago
Quoting Calif Research
Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...] The victim does not need to answ
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 6d ago
Creepy crawlies
Creepy crawlies Konstantin Ryabitsev discusses how bad the "background radiation" of abusive crawlers has become from the perspective of git.kernel.org , the of
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 1w ago
The purpose of DNS is to spread scams
The purpose of DNS is to spread scams Terence Eden shares some daunting statistics in support of his take that "the Domain Name System's purpose seems to be a v
Maintenance & security Journey in 2026 - Post-mortem measures in GHOST compromised websites
Dev.to · Mino Randriamanivo 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Maintenance & security Journey in 2026 - Post-mortem measures in GHOST compromised websites
Hi, An attack was ran on multiple Ghost websites (https://kahiether.com/, etc..) this summer, 3rd...
Give Every Agent Patch a Regression Budget, Not Just a Green Check
Dev.to · Finley Zhou 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Give Every Agent Patch a Regression Budget, Not Just a Green Check
A green CI run is not a verdict. It is a photograph taken at one moment, under one seed, with one set...
Bot-Resistant Account Deletion Workflow for Consent Cleanup and Session Revocation
Dev.to · BeckettHayes6821 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Bot-Resistant Account Deletion Workflow for Consent Cleanup and Session Revocation
Short answer: make deletion a two-phase, abuse-resistant workflow that proves user intent, revokes...
Your camera roll is part of your developer threat model
Dev.to · Dmytro Polianskyi 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Your camera roll is part of your developer threat model
Developers spend a lot of time protecting source repositories, CI secrets, cloud consoles, and...
5 Recovery Rules for Signup Bot Defense — CAPTCHA Before Account Creation
Dev.to · tony chen 🔐 Cybersecurity ⚡ AI Lesson 1w ago
5 Recovery Rules for Signup Bot Defense — CAPTCHA Before Account Creation
Signup bot defense is an account-lifecycle decision, not a widget decision. For a property-management...
How On-Device Sensitive Photo Scanning Works
Dev.to · Dmytro Polianskyi 🔐 Cybersecurity ⚡ AI Lesson 1w ago
How On-Device Sensitive Photo Scanning Works
“Local” should describe a data path, not a marketing mood. Here is what to verify before allowing a...
5 Guardrails for E-commerce Login Callbacks: Choosing Providers and Local Sessions
Dev.to · LunarBreeze4173085 🔐 Cybersecurity ⚡ AI Lesson 1w ago
5 Guardrails for E-commerce Login Callbacks: Choosing Providers and Local Sessions
An e-commerce login callback is an abuse-control boundary, not a redirect handler. Short answer:...
Multi-model routing with one key: BYOK failover explained (2026)
Dev.to · 仪袁韶 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Multi-model routing with one key: BYOK failover explained (2026)
← All guides One key, four models: BYOK failover explained A bring-your-own-key gateway lets you...
Analytics Identity Gates — Provisioning, Session Lifetimes, and Consent Evidence
Dev.to · MiloHastings5316 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Analytics Identity Gates — Provisioning, Session Lifetimes, and Consent Evidence
Short answer: treat workspace access as an auditable state machine, keep phone OTP as one...
A credential fetch is a read: the containment guard your write-target sandbox was missing
Dev.to · pm25coder 🔐 Cybersecurity ⚡ AI Lesson 1w ago
A credential fetch is a read: the containment guard your write-target sandbox was missing
A credential fetch is a read: the containment guard your write-target sandbox was...
Server-Side CAPTCHA Verification Before Account Creation Explained (Signup Bot Defense)
Dev.to · Trkfpn392751 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Server-Side CAPTCHA Verification Before Account Creation Explained (Signup Bot Defense)
Short answer: verify the CAPTCHA at the account-creation service boundary, record that decision as an...
Gateway Token Validation Options — A 4-Step JWKS Choice for Game Signup
Dev.to · NevilleChristensen2637 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Gateway Token Validation Options — A 4-Step JWKS Choice for Game Signup
Short answer: for a game signup gateway, validate JWTs with a cached public-key set, refresh on...
O prompt de AppSec que eu criei achou 1 gap em 174 rotas.
Dev.to · Tiago Vilas Boas (Montanha) 🔐 Cybersecurity ⚡ AI Lesson 1w ago
O prompt de AppSec que eu criei achou 1 gap em 174 rotas.
Pessoal, eu quase abri uma issue com uma lista. O modelo tinha devolvido XSS, CORS, CSP, um SVG...
The Security Fix That Would Have Silently Broken My Feature
Dev.to · Abd El-latif 🔐 Cybersecurity ⚡ AI Lesson 1w ago
The Security Fix That Would Have Silently Broken My Feature
I recently shipped Mermaid diagram support to Forem, the open source platform that powers DEV. Fenced...
CVE-2026-32193 Is a Copilot Hijack Disguised as a Boring Path Traversal
Dev.to · Jason Miller 🔐 Cybersecurity ⚡ AI Lesson 1w ago
CVE-2026-32193 Is a Copilot Hijack Disguised as a Boring Path Traversal
The official record is one sentence: an "authorized attacker," a local path traversal in Azure...
BGP Hijack Delivered a Backdoored Virtualizor Update to VPS Hosts
Dev.to · Etairos.ai 🔐 Cybersecurity ⚡ AI Lesson 1w ago
BGP Hijack Delivered a Backdoored Virtualizor Update to VPS Hosts
TL;DR what: An attacker falsely announced a block of Hetzner-hosted IP addresses...
Patterns, Anti-Patterns, and Operational Reality
Dev.to · Kaustav Sarkar 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Patterns, Anti-Patterns, and Operational Reality
This blog is a part of the Zero-Trust Security on Istio Series, if you haven't read the previous...
How to Resolve SSL/TLS Certificate Handshake Failures – Step-by-Step Guide for Developers
Dev.to · Deep Fix 🔐 Cybersecurity ⚡ AI Lesson 1w ago
How to Resolve SSL/TLS Certificate Handshake Failures – Step-by-Step Guide for Developers
Introduction SSL/TLS handshake failures cripple web services, CI pipelines, and...
AI SOC vs Traditional SOC: What’s the Difference?
Dev.to · Seceon_inc 🔐 Cybersecurity ⚡ AI Lesson 1w ago
AI SOC vs Traditional SOC: What’s the Difference?
The debate over AI SOC vs traditional SOC has moved from theoretical to urgent. Security teams face...
Sicurezza API REST: best practices
Dev.to · Cub4nH1 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Sicurezza API REST: best practices
Meta description: Scopri le best practice per la sicurezza delle API REST. Guida completa con esempi...
Orient Blackswan Hit by Ransomware Attack in Hyderabad
Dev.to · BeyondMachines 🔐 Cybersecurity ⚡ AI Lesson 1w ago
Orient Blackswan Hit by Ransomware Attack in Hyderabad
Orient Blackswan, a publishing house in Hyderabad, suffered a ransomware attack that encrypted business data and disrupted their IT infrastructure. The company
Two-Factor Authentication Explained — Go SMS, Email Fallback, Delivery Polling
Dev.to · BramwellVance7953 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Two-Factor Authentication Explained — Go SMS, Email Fallback, Delivery Polling
Short answer: use SMS as the first delivery channel, poll its delivery state against a bounded...
TokenPAPA Security & Privacy: How We Handle Your Data
Dev.to · TokenPAPA 🔐 Cybersecurity ⚡ AI Lesson 2w ago
TokenPAPA Security & Privacy: How We Handle Your Data
How TokenPAPA protects your data: TLS 1.3 encryption in transit, AES-256 at rest, hashed API keys, Stripe payment security, no training on your prompt
The approval signature that could be spent twice
Dev.to · Shaan Satsangi 🔐 Cybersecurity ⚡ AI Lesson 2w ago
The approval signature that could be spent twice
I built this project and wrote this article for the purposes of entering the Google Cloud "All Things...
Can your security test suite fail? Mine passed against nothing.
Dev.to · Michael "Mike" K. Saleme 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Can your security test suite fail? Mine passed against nothing.
Most security test suites answer one question: did the attack succeed? The verdict then falls out of...
Host key verification failed: what it means and the right way to fix it
Dev.to · Svyatoslav Pavlov 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Host key verification failed: what it means and the right way to fix it
Near the top of every search result for this error sits the same one-liner: -o...
My scanner reported honest coverage every day, and it was the same coverage every day
Dev.to · ilya mozerov 🔐 Cybersecurity ⚡ AI Lesson 2w ago
My scanner reported honest coverage every day, and it was the same coverage every day
I have a tool whose whole job is catching tools that lie. The idea is small. A lot of my scripts...
Simon Willison's Blog 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Just a rumour of a bug is enough to find a security exploit these days
Just a rumour of a bug is enough to find a security exploit these days Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer o
Governance You Can't Grep Isn't Governance
Dev.to · Todd Linnertz 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Governance You Can't Grep Isn't Governance
Earlier this month I clicked a button labeled Freeze, and a validator told me my artifact was...
The Growing Threat: Attackers Using GitHub Repositories as Malware Staging Mechanisms
Dev.to · Bonnie Smyre 🔐 Cybersecurity ⚡ AI Lesson 2w ago
The Growing Threat: Attackers Using GitHub Repositories as Malware Staging Mechanisms
This blog was originally published by Brian Tant on the Raxis blog January 21, 2026 GitHub has...
3 Wrong Guesses About a Chrome Slot Limit: 3 6 Reserved Lanes
Dev.to · Lily 🔐 Cybersecurity ⚡ AI Lesson 2w ago
3 Wrong Guesses About a Chrome Slot Limit: 3 6 Reserved Lanes
Automation doesn't break when you write it. It breaks in production, weeks later, quietly — and my...
Your First Cloud Pentest Isn't Going to Play Out Like Your Last AD Engagement
Dev.to · Rocky 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Your First Cloud Pentest Isn't Going to Play Out Like Your Last AD Engagement
First cloud-focused engagement, and the plan going in looked like every internal AD assessment before...
Your Security Scanner Has a Blind Spot: Streaming
Dev.to · Sangyeon Park 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Your Security Scanner Has a Blind Spot: Streaming
I spent an afternoon convinced my detector was broken. I was building Cencurity, a local gateway...
Your JWT Decoder Should Never Ask for Your Signing Secret
Dev.to · Vipul Singh 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Your JWT Decoder Should Never Ask for Your Signing Secret
A JWT looks like gibberish until you decode it — three Base64URL segments separated by dots: header,...
Google Staff Security Engineer Interview Prep: Cloud CISO, Product Security, Coding, and Domain-Specific Questions
Dev.to · Olga Larionova 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Google Staff Security Engineer Interview Prep: Cloud CISO, Product Security, Coding, and Domain-Specific Questions
Introduction to the Google Staff Security Engineer Interview Securing a Staff Security...
The Voice-AI Vendor Security Questionnaire: 12 Questions About Recordings, PII and Model Training
Dev.to · Peter Jackman 🔐 Cybersecurity ⚡ AI Lesson 2w ago
The Voice-AI Vendor Security Questionnaire: 12 Questions About Recordings, PII and Model Training
Short answer: Before signing an AI voice or AI sales-agent vendor, get written answers to twelve questions: recording storage and location, retention and deleti
Why TOTP 2FA Verification Fails in Production: 5 Cryptographic Edge Cases
Dev.to · Rasika Dangamuwa 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Why TOTP 2FA Verification Fails in Production: 5 Cryptographic Edge Cases
Implementing Time-Based One-Time Passwords (TOTP, RFC 6238) seems straightforward: generate a 160-bit...
XopProtector: An Open Source Android APK Protection Framework Ready for Real-World Production
Dev.to · Android 小行家 🔐 Cybersecurity ⚡ AI Lesson 2w ago
XopProtector: An Open Source Android APK Protection Framework Ready for Real-World Production
XopProtector: An Open Source Android APK Protection Framework Ready for Real-World...
Your agent's 'secure' network policy was off unless you did four steps — so it was off
Dev.to · wartzar-bee 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Your agent's 'secure' network policy was off unless you did four steps — so it was off
enclave 0.8.0 makes the safe autonomous-agent config the default instead of a ritual. The lesson: an opt-in control with a four-step activation cost is a contro
SBOM-for-Agents: The Missing Trust Layer for Agent Supply Chains
Dev.to · bozoinc 🔐 Cybersecurity ⚡ AI Lesson 2w ago
SBOM-for-Agents: The Missing Trust Layer for Agent Supply Chains
Introduction Software Bill of Materials (SBOMs) are now a standard requirement for enterprise...
A symlink walks straight out of an agent's write allow-list
Dev.to · Fewparts 🔐 Cybersecurity ⚡ AI Lesson 2w ago
A symlink walks straight out of an agent's write allow-list
path.resolve never opens anything. A link inside your allow-list reads as in scope, and the write lands outside it — here's the escape, the fix, and the bug the
Why Webhook HMAC Verification Fails in Production: 5 Cryptographic Traps Every Developer Misses
Dev.to · Rasika Dangamuwa 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Why Webhook HMAC Verification Fails in Production: 5 Cryptographic Traps Every Developer Misses
You’ve set up your webhook endpoint to receive payment notifications from Stripe, pull request alerts...
CVE-2026-45019: CVE-2026-45019: Server-Side Request Forgery (SSRF) in Chainlit MCP Endpoint
Dev.to · CVE Reports 🔐 Cybersecurity ⚡ AI Lesson 2w ago
CVE-2026-45019: CVE-2026-45019: Server-Side Request Forgery (SSRF) in Chainlit MCP Endpoint
CVE-2026-45019: Server-Side Request Forgery (SSRF) in Chainlit MCP Endpoint Vulnerability...
GCS Race Conditions & Generation-Fenced Leases
Dev.to · Humza Tareen 🔐 Cybersecurity ⚡ AI Lesson 2w ago
GCS Race Conditions & Generation-Fenced Leases
Two race conditions in distributed step leasing where stale workers deleted fresh locks — fixed with GCS generation-based optimistic concurrency.
Taking control of cluster security: A deep dive into GKE ClusterNetworkPolicy
Dev.to · Olivier Bourgeois 🔐 Cybersecurity ⚡ AI Lesson 2w ago
Taking control of cluster security: A deep dive into GKE ClusterNetworkPolicy
Discover how GKE ClusterNetworkPolicy enables platform teams to establish global security guardrails without hindering developer agility