Tech is political: The people under attack in Palestine 🇵🇸, Iran 🇮🇷, and Lebanon 🇱🇧 are people like us. They’re our brothers and sisters, too. Read up on their history, scrutinize what you’re told, and demand that they be respected. Hide

Frontend Dogma

“security” News Archive

Definition, related topics, and tag feed

Definition · Supertopics: user-experience · Subtopics: authentication, authorization, bot-detection, certificates, cors, cryptography, csp, csrf, hashing, malware, privacy, provenance, randomness, rate-limiting, sanitization, ssh, ssl, tls, validation, vulnerabilities, xss (non-exhaustive) · “security” × ? · “security” RSS feed (per email)

Entry (Sources) and Additional TopicsDate#
Web Security Is Too Hard (eri)588
cloudflare, case-studies
Major Shai Hulud Campaign Strikes npm Again, Affecting keyv and 400+ Packages587
npm, dependencies
Stronger With Every Update: How We’re Making Chrome and the Web Safer in the AI Era586
chrome, browsers, ai
Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks585
foss, amazon
Maciek Palmowski on Testing Secure WordPress Hosting: Does the Marketing Match Reality? (pal+)584
podcasts, interviews, wordpress, hosting
Local-First AI Coding Workflow for Security-Conscious Teams (age)583
ai, processes
Disrupting Supply Chain Attacks on npm and GitHub Actions (gre+)582
npm, github-actions, link-lists
The Secure Way to Release an npm Package in 2026 (sit+/evi)581
dependencies, npm, configuration
npm Publish-Time Malware Scanning and Dual-Use Metadata580
npm, dependencies
Weaponizing and Defending the React Flight Protocol: Deserialization Sinks in RSCs (sma)579
react, components
Monday, July 27, 2026 Security Releases (nod)578
release-notes, nodejs
Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk (lor)577
wordpress, bugs
[Hugging Face] Security Incident Disclosure—July 2026576
hugging-face, ai
Milan Petrović on the Risks of Legacy PHP in WordPress and Why Upgrading Matters for Security (nat)575
podcasts, interviews, php, wordpress, maintenance
Now, Defenders Are Embracing the Prompt Injection, Too (ars)574
ai, prompting
npm Install-Time Security and GAT bypass2fa Deprecation573
npm, deprecation
You Shouldn’t Trust Trusted Publishing (yos)572
authentication
6 Security Settings Every GitHub Maintainer Should Enable This Week571
github, configuration, documentation
Shipping Post-Quantum Cryptography to Python (tra)570
python, cryptography, foss
npm Adds Preventive Account Protection for High-Impact Accounts569
npm
Ignore DNSSEC if You Like MITM Attacks568
dns
Anthropic’s Fable and the State of AI (sch)567
ai, anthropic, foss
Blocking Install Scripts Is Not a Silver Bullet (uli/nod)566
npm
Reuse Less Software565
dependencies, processes
Wednesday, June 17, 2026 Security Releases (nod)564
release-notes, nodejs
Upcoming Breaking Changes for npm v12563
npm
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders (sar/soc)562
npm, bugs
The Website Specification (joo)561
websites, documentation, fundamentals, seo, accessibility, ai-agents, performance, privacy, resilience, internationalization
The VibeSec Reckoning (mfo)560
ai, vibe-coding
Megalodon: Mass GitHub Repo Backdooring via CI Workflows559
github, ci-cd
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension (the)558
github, vs-code
GitHub Hacked—Internal Source Code Repositories Compromised via Employee Device557
github
Mini Shai Hulud: Compromised @antv npm Packages Enable CI/CD Credential Theft556
npm, dependencies, ci-cd
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised555
npm, dependencies
“The Worst Leak That I’ve Witnessed”: US Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub (giz)554
passwords, github
A Worm Just Ate Its Way Through the npm Registry… (fir)553
videos, npm, dependencies, tanstack
Hardening TanStack After the npm Compromise (cru+/tan)552
tanstack
Hackers Abuse Google Ads and Claude.ai Shared Chats to Distribute macOS Malware551
apple, unix-like, google, claude, ai
Weekend at Bernie’s (and)550
dependencies, foss, metrics
Behind the Scenes Hardening Firefox With Claude Mythos Preview (fre+/moz)549
firefox, browsers, claude, ai
Trustworthy JavaScript for the Open Web (moz)548
javascript, open-web, firefox, browsers
The Zero-Days Are Numbered (moz)547
firefox, browsers, ai, anthropic
Vercel April 2026 Security Incident546
vercel
AI Will Never Be Ethical or Safe (j9t)545
ai, ethics
No One Owes You Supply-Chain Security (pur)544
dependencies, rust
Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them543
wordpress, plugins
Adversarial AI: Understanding the Threats to Modern AI Systems (jet)542
ai, concepts
Anthropic Debuts Preview of Powerful New AI Model Mythos in New Cybersecurity Initiative541
anthropic, ai
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign (sar/soc)540
nodejs, foss
Post Mortem: Axios npm Supply Chain Compromise539
axios, npm
The Hidden Blast Radius of the Axios Compromise (ahm/soc)538
dependencies, npm, axios
Minimum Release Age Is an Underrated Supply Chain Defense (dan)537
dependencies, npm, bun, pnpm, yarn, deno, renovate, dependabot, axios
Axios Compromised on npm—Malicious Versions Drop Remote Access Trojan536
npm, dependencies, axios
Prevent Claude Code From Accessing .env (jad)535
claude, ai, environments
Node.js Brotli UAF (mai)534
nodejs, permissions, brotli, compression, claude, ai
Malicious PyPI Package—LiteLLM Supply Chain Compromise533
dependencies, vulnerabilities
Developing a Minimally HashDoS Resistant, Yet Quickly Reversible Integer Hash for V8 (joy/nod)532
nodejs, hashing
Tuesday, March 24, 2026 Security Releases (nod)531
release-notes, nodejs
Supply-Chain Attack Using Invisible Code Hits GitHub and Other Repositories (dan/ars)530
github, dependencies
OWASP’s Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed529
videos, vulnerabilities, ai, owasp
A GitHub Issue Title Compromised 4,000 Developer Machines528
github, ai
How to Steal npm Publish Tokens by Opening GitHub Issues (nec)527
npm, github, ai
MCP Servers and the Return of the Service Account Problem (aem)526
servers, mcp, ai
Security Advisory: Addressing Recent Vulnerabilities in Angular (ang)525
angular
An Exploit… in CSS?! (css)524
css
Goodbye “innerHTML”, Hello “setHTML”: Stronger XSS Protection in Firefox 148 (moz)523
javascript, methods, xss, firefox, browsers
Europe Is Ready to Ditch US Tech for Private Alternatives (pro)522
tooling, privacy, metrics
WebSocket Penetration Testing: A Complete Guide to CSWSH521
guides, websockets, testing
Node.js Path Traversal: Prevention and Security Guide (loi)520
guides, nodejs
Cryptography Usage in Web Standards (w3c)519
standards, cryptography
OpenJS Foundation Security Program: Annual Report 2025 (ope)518
openjs
A Security Checklist for Your React and Next.js Apps517
react, nextjs
How to Implement Rate Limiting in nginx (naw/one)516
how-tos, servers, nginx, rate-limiting
Securing npm Is Table Stakes (nza+/cha)515
podcasts, interviews, npm, ai
Security (vik+/htt)514
web-almanac, studies, research, metrics, tls, certificates, cookies, csp, http-headers, apis, sanitization, configuration
Node.js January 2026 Security Release: What Changed and Why It Matters (nod)513
nodejs
Tuesday, January 13, 2026 Security Releases (nod)512
release-notes, nodejs
Mitigating Denial-of-Service Vulnerability From Unrecoverable Stack Space Exhaustion for React, Next.js, and APM Users (mco+/nod)511
nodejs, vulnerabilities, react, nextjs, tooling, monitoring, performance
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens (sar/soc)510
npm, dependencies
Security Basics for Vibe-Coders (owe/pro)509
fundamentals, vibe-coding, ai
Testing Methods: Accessible Authentication (Enhanced) (dec)508
accessibility, testing, wcag, authentication
Testing Methods: Accessible Authentication (Minimum) (dec)507
accessibility, testing, wcag, authentication
Denial of Service and Source Code Exposure in React Server Components (rea)506
react, components
Thursday, December 18, 2025 Security Releases (nod)505
release-notes, nodejs
How We’re Protecting Our Newsroom From npm Supply Chain Attacks (rya/pnp)504
npm, dependencies, case-studies
No More Tokens—Locking Down npm Publish Workflows (zac)503
npm, dependencies, processes
[Next.js] Security Advisory: CVE-2025-66478 (seb)502
nextjs
Critical Security Vulnerability in React Server Components (rea)501
react, components
Decreasing [Let’s Encrypt] Certificate Lifetimes to 45 Days (mat/let)500
http, certificates, lets-encrypt
Taking Down Next.js Servers for 0.0001 Cents a Pop499
servers, nextjs, vulnerabilities
The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know498
npm, dependencies
GitLab Discovers Widespread npm Supply Chain Attack497
npm, dependencies, gitlab, aws, gcp, azure
Automated npm Secret Rotation in GitHub Actions (mhe)496
npm, automation, github-actions
What Developers Really Mean by “Bad Code” (jet)495
maintainability, scalability, consistency, quality
Introducing the OWASP Top 10:2025 (she+/owa)494
introductions, owasp, vulnerabilities
Removing XSLT for a More Secure Browser (dro)493
chromium, chrome, browsers, xsl, web-platform
Agentic AI and Security (ksi/mfo)492
ai, architecture
Octoverse: A New Developer Joins GitHub Every Second as AI Leads TypeScript to #1491
github, metrics, productivity, ai, foss, programming
HTTPS by Default (jde+)490
http, chrome, browsers
Will npm’s New Security Steps Stop Attacks? (rev)489
npm, maintenance, foss
Glassworm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace488
code-editors, vs-code
Improving the Trustworthiness of JavaScript on the Web487
javascript, web-apps
Past Time for Passkeys (nor)486
videos, passkeys, passwords, authentication
Secure Coding in JavaScript485
javascript, frameworks
My Conclusions After Using Signed Exchanges on My Website for 2 Years (paw)484
signed-exchanges, performance
Lazy-Loading as a Security Measure483
lazy-loading, angular, react
Backend Concepts Every Experienced Developers Must Know482
concepts, network, concurrency, apis, databases, caching, scalability, observability, architecture
Fixing Safari Mixed Content Issues With Vite and mkcert481
safari, browsers, vite, tooling
How Deno Protects Against npm Exploits (den)480
deno, npm
Strengthening npm Security: Important Changes to Authentication and Token Management479
npm
How Hackers Use AI to Find Vulnerabilities Faster478
ai
CAPTCHA, When Security Takes Precedence Over Accessibility477
captcha, accessibility
Our Plan for a More Secure npm Supply Chain (xco)476
npm, dependencies, foss
npm Security Best Practices475
npm, provenance, best-practices
This May Be the Worst One (the)474
videos, npm, dependencies
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages (pvd+/soc)473
npm, dependencies
ctrl/tinycolor and 40+ npm Packages Compromised472
npm, dependencies
How Maintainer Burnout Is Causing a Kubernetes Security Disaster471
kubernetes, maintenance, foss, economics
Oh No, Not Again… a Meditation on npm Supply Chain Attacks (tan)470
npm, dependencies, microsoft
Anatomy of a Billion-Download npm Supply-Chain Attack469
npm, dependencies
npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack (bur+/soc)468
npm, dependencies
CORS Explained: Stop Struggling With Cross-Origin Errors467
cors, http-headers, http
How OpenJS-Hosted Projects Benefit From Security Support (ope)466
openjs, hosting, foss
Why You Absolutely Need to Have Automated Dependency Management in Place (j9t)465
dependencies, maintainability, maintenance, automation, tooling
What Your Website’s Style Says About You—and How Hackers Can Use It Against You (err)464
css, javascript
Hardening Node.js Apps in Production: 8 Layers of Practical Security463
nodejs, best-practices
eslint-config-prettier Compromised: How npm Package With 30 Million Downloads Spread Malware462
prettier, eslint, npm, malware
npm Phishing Email Targets Developers With Typosquatted Domain (sar/soc)461
npm
AI Agents Are Creating a New Security Nightmare for Enterprises and Startups460
ai, apis
Tuesday, July 15, 2025 Security Releases (nod)459
release-notes, nodejs
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc)458
npm, dependencies
Dependabot Supports Configuration of a Minimum Package Age457
dependabot, configuration
MCP Security Vulnerabilities and Attack Vectors456
mcp, ai
A New Era of Code Quality455
quality
JWTs Are Not Session Tokens, Stop Using Them Like One454
json-web-tokens, authentication
Design Patterns for Securing LLM Agents Against Prompt Injections (sim)453
studies, research, ai, prompting, software-design-patterns
The Growing Risk of Malicious Browser Extensions (soc)452
browser-extensions
HTML Spec Change: Escaping “<” and “>” in Attributes (sec)451
html, attributes, escaping, xss
Escaping “<” and “>” in Attributes—How It Helps Protect Against Mutation XSS (sec)450
html, attributes, xss, escaping, chrome, browsers
Beware of End-of-Life Node.js Versions—Upgrade or Seek Post-EOL Support (mco/nod)449
nodejs, maintenance
How to Access Local MCP Servers Through a Secure Tunnel448
how-tos, mcp, ai, servers, network
Docker Launches Hardened Images, Intensifying Secure Container Market447
docker
Modernizing Security446
modernization, processes
Securing Your Node.js App From Command Injection445
nodejs
Passkeys for Normal People (tro)444
authentication, passkeys, examples, concepts
npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc)443
npm, malware, dependencies, link-lists
What Is an Encryption Backdoor? (int)442
encryption, vulnerabilities, concepts
Cybersecurity Leaders Are Staying in the Shadows (ste)441
community, culture
Principles for Coding Securely With LLMs (sea)440
ai, principles
Threat Actors Misuse Node.js to Deliver Malware and Other Malicious Payloads439
nodejs, malware
TLS Certificate Lifetimes Will Officially Reduce to 47 Days438
tls, certificates
LLMs Can’t Stop Making Up Software Dependencies and Sabotaging Everything (tho/the)437
ai, dependencies, slop
Secure a Vue App With OpenID Connect and the BFF Pattern (due)436
vuejs, authentication, backend-for-frontend
Teaching Code in the AI Era: Why Fundamentals Still Matter (ali)435
training, ai, programming, vibe-coding, scalability, performance, quality, testing, documentation
Stop Using Jenkins in 2025 (oso)434
jenkins, github-actions, ci-cd
Node.js Test CI Security Incident (nod)433
nodejs, retrospectives
Website Hijack Campaign Now Impacting 150,000 Sites (gad)432
Malware Found on npm Infecting Local Package With Reverse Shell (rev)431
npm, dependencies
Five Things Vibe Coders Should Know (From a Software Engineer)430
vibe-coding, sanitization, rate-limiting
GitHub Suffers a Cascading Supply Chain Attack Compromising CI/CD Secrets (inf)429
github, ci-cd
How to Prevent WordPress SQL Injection Attacks (sma)428
how-tos, wordpress, sql, databases
Lazarus Strikes npm Again With New Wave of Malicious Packages (soc)427
npm, dependencies
Updates on CVE for End-of-Life Versions (raf/nod)426
nodejs
What Is the OWASP Top 10 and How Can Your Team Benchmark Security? (jet)425
owasp, vulnerabilities, qodana
How to Protect Your Web Applications From XSS (tor/w3c)424
how-tos, web-apps, xss
In Tech, What Matters and What Is Dangerous (ham)423
community, foss, open-web
Secure UX: Building Cybersecurity and Privacy Into the UX Lifecycle (uxm)422
user-experience, processes
The Fallacy of Balance: Challenging the Notion of Security and Accessibility as Opposing Objectives (deq)421
videos, accessibility
It Is No Longer Safe to Move Our Governments and Societies to US Clouds (ber)420
cloud-computing, privacy, legal
How OWASP Helps You Secure Your Full-Stack Web Applications (eri/sma)419
owasp, monitoring, authentication, vulnerabilities, configuration, csrf, cryptography, authorization
10 Common Web Development Mistakes to Avoid Right Now418
mistakes, mobile, performance, accessibility, seo, navigation, analytics, testing
Tightening Every Bolt (bag)417
videos, processes, code-reviews, testing
On Generative AI Security (sch)416
ai, lessons, microsoft
Understanding CORS Errors in Signed Exchanges (paw)415
cors, errors, signed-exchanges
Keep Your Node.js Apps Secure With “npx is-my-node-vulnerable” (tre)414
packages, npm, nodejs
How I Open-Sourced My Secret Access Tokens From GitHub, Slack, and npm—and Who Actually Cares413
github, slack, npm
Node.js EOL Versions CVE Dubbed the “Worst CVE of the Year” by Security Experts (sar/soc)412
nodejs, documentation
Tuesday, January 21, 2025 Security Releases (raf/nod)411
release-notes, nodejs
APIs Are Quickly Becoming the Latest Security Battleground (and Nightmare)410
apis
CDN-First Is No Longer a Performance Feature (osv)409
content-delivery, performance, caching, embed-code, privacy
The Cyber-Cleanse: Take Back Your Digital Footprint (cyb)408
privacy
15 Principles for Secure Programming (rak)407
principles, validation, testing
Important Topics for Frontend Developers to Master in 2025406
learning, javascript, typescript, css, frameworks, git, apis, testing, performance, ci-cd, websockets
How to Automate OWASP Security Reviews in Your Pull Requests? (cod)405
how-tos, owasp, automation, code-reviews, coderabbit
Developer Guide: How to Implement Passkeys404
guides, how-tos, authentication, passkeys
5 Technical Trends to Help Web Developers Stand Out in 2025403
trends, career, javascript, ai, low-and-no-code
Avoid Hotlinking Images With “Cross-Origin-Resource-Policy”402
images
Content Security Policy Level 3 (mik/w3c)401
standards, csp
Security (vik/htt)400
web-almanac, studies, research, metrics
JavaScript Import Attributes (ES2025) (tre)399
javascript
Exploring Internet Traffic Shifts and Cyber Attacks During the 2024 US Election398
traffic
Cross-Site WebSocket Hijacking: Understanding and Exploiting CSWSH (pen)397
websockets
Securing Your Express REST API With Passport.js396
nodejs, express, json-web-tokens, apis, rest, tooling
SecretLint—a Linter for Preventing Committing Credentials (tre)395
tooling, linting
The Importance of UX in Cybersecurity (uxm)394
user-experience, usability
Understanding “npm audit” and Fixing Vulnerabilities393
npm, vulnerabilities, nodejs
Top 4 Web Vulnerabilities With Example and Mitigation392
vulnerabilities, sql, databases, xss, csrf
How to Implement Content Security Policy (CSP) Headers for Astro (tre)391
how-tos, http, http-headers, csp, astro, vercel, cloudflare
Why Code Security Matters—Even in Hardened Environments390
vulnerabilities, file-handling, nodejs
Database 101: SSL/TLS for Beginners389
introductions, databases, ssl, tls, authentication
Cloudflare Study: 39% of Companies Losing Control of Their IT and Security Environment (tre)388
studies, research, engineering-management
NIST Recommends Some Common-Sense Password Rules (sch)387
passwords, guidelines
I Finally Understand OAuth386
authorization, oauth, processes
Fake GitHub Site Targeting Developers (jul/san)385
github
Hacking Cars in JavaScript (Running Replay Attacks in the Browser With the HackRF) (dev)384
javascript
Gaining Access to Anyone’s Browser Without Them Even Visiting a Website383
arc, browsers, vulnerabilities
10 AI Dangers and Risks and How to Manage Them (rin)382
ai, privacy, sustainability, legal
Web Security: Shaping the Secure Web (set/w3c)381
web, w3c
5 Wasm Use Cases for Frontend Development (ele/des)380
guest-posts, webassembly, performance
What Is Incident Response?379
incident-response, overviews
The Great npm Garbage Patch378
dependencies, npm, spam
Migrating From Netlify to Cloudflare for AI Bot Protection (sia)377
migrating, netlify, cloudflare, bots, ai
Frontend Security Checklist (tre)376
checklists, react
Automated Ways to Security Audit Your Website375
auditing, automation, tooling
Secure Node.js Applications From Supply Chain Attacks374
nodejs, best-practices, dependencies
The Pitfalls of In-App Browsers (fro)373
browsers, mobile, privacy, user-experience
The Cloud Run Security Gap You Didn’t Know You Had (and How to Fix It)372
gcp
Supply Chain Security in npm—We Can Be Optimistic About the Future371
npm, dependencies, provenance
Script Integrity (chr/fro)370
embed-code, javascript
Tuesday, July 2, 2024 Security Releases (nod)369
release-notes, nodejs
Introducing the MDN HTTP Observatory (mdn)368
introductions, mdn, http
WebAuthn: Enhancing Security With Minimal Effort (tbe)367
authentication, webauthn
RegreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server366
ssh, vulnerabilities
Polyfill Supply Chain Attack Embeds Malware in JavaScript CDN Assets365
malware, vulnerabilities
Catching Compromised Cookies (sla)364
cookies, testing
Backdoor Slipped Into Multiple WordPress Plugins in Ongoing Supply-Chain Attack (dan/ars)363
wordpress, plugins
The Hacking of Culture and the Creation of Socio-Technical Debt (sch)362
culture
Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar/soc)361
npm, dependencies, vulnerabilities, caching
What Is Mixed Content? (fre)360
http
OAuth Authentication (rya)359
authentication, authorization, oauth
The Ultimate Guide to Iframes (log)358
guides, iframes, html, javascript
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem357
javascript, npm, dependencies, caching, vulnerabilities
JavaScript Security: Simple Practices to Secure Your Frontend356
javascript, dependencies, csp
Manifesto for a Humane Web (mic)355
websites, manifestos, web, principles, accessibility, dei, sustainability, user-experience
Securing Client-Side JavaScript (ada)354
javascript, graceful-degradation
Poor Express Authentication Patterns in Node.js and How to Avoid Them353
express, nodejs, authentication
Passkeys: A Shattered Dream (fir)352
authentication, passkeys
Using Legitimate GitHub URLs for Malware (sch)351
malware, github
When Security and Accessibility Clash: Why Are Banking Applications So Inaccessible? (nic)350
accessibility
Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects (rgi/ope)349
foss, openjs
Wednesday, April 10, 2024 Security Releases (raf/nod)348
release-notes, nodejs
Node.js Secure Coding: Mitigate and Weaponize Code Injection Vulnerabilities347
books, nodejs, vulnerabilities
The Free Software Commons (jen)346
foss, community
The V8 Sandbox345
v8
Wednesday, April 3, 2024 Security Releases (nod)344
release-notes, nodejs
Using JSON Web Tokens With Node.js343
json-web-tokens, nodejs, authentication
Building a Digital Fortress: How to Strengthen DNS Against DDoS Attacks?342
dns
In-App Browsers Are Still a Privacy, Security, and Choice Problem (tho/the)341
browsers, mobile, privacy
How Does Single Sign-On (SSO) Work? (mil)340
authentication
CORS Finally Explained—Simply339
csrf, cors, concepts
How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth)338
npm, dependencies, examples
Preventing SQL Injection Attacks in Node.js337
nodejs, databases, sql
Frontend Application Security: Tips and Tricks336
web-apps, xss, csrf, authentication, dependencies, csp, validation, tips-and-tricks
Wednesday, February 14, 2024 Security Releases (raf+/nod)335
release-notes, nodejs
How to Boost WordPress Security and Protect Your SEO Ranking334
how-tos, wordpress, seo
Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar/soc)333
npm, dependencies
Practice Safe DSD With “setHTMLUnsafe” (It’s Complicated) (jar/van)332
html, dom, shadow-dom, apis
Tuesday, February 6, 2024 Security Releases (raf/nod)331
release-notes, nodejs
JWT vs. Session Authentication330
authentication, json-web-tokens, comparisons
GitHub, npm Registry Abused to Host SSH Key-Stealing Malware329
github, npm, malware, foss
Navigating JavaScript Security: Recompiling Firefox to Bypass Anti-Debugger Techniques (gli)328
javascript, debugging, firefox, browsers
Deceptive Deprecation: The Truth About npm Deprecated Packages327
deprecation, npm, dependencies, research
Safely Accessing the DOM With Angular SSR326
dom, javascript, angular, server-side-rendering
Node.js Security Progress Report—Progress on Permission Model, Fuzzer, and Connections With Community (ope)325
nodejs
Secure Your Code: Auto-Fix Vulnerabilities With Dependabot (GitHub Tutorial)324
videos, dependencies, dependabot
I Hate CORS323
videos, cors
Building Multiple Progressive Web Apps on the Same Domain322
videos, web-apps, progressive-web-apps, architecture
Session-Based vs. Token-Based Authentication: Which Is Better?321
authentication, json-web-tokens, comparisons
10 Best Practices for Secure Code Review of Node.js Code320
best-practices, code-reviews, nodejs
Security Headers Using “<meta>” (sap/mat)319
csp, html
Blind CSS Exfiltration: Exfiltrate Unknown Web Pages318
css
Mastering Cryptography Fundamentals With Node’s “crypto” Module317
cryptography, nodejs
Secure Code Review Tips to Defend Against Vulnerable Node.js Code316
nodejs, code-reviews
Understanding CORS315
cors
What the !#@% Is a Passkey? (eff)314
passkeys
Secret Scanning Scans Public npm Packages313
npm, dependencies
Local HTTPS for Next.js 13.5 (ami)312
testing, http, nextjs
Understanding XSS Attacks311
xss
A Comprehensive Guide to the Dangers of Regular Expressions in JavaScript (phi)310
guides, javascript, regex
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble)309
ssh, dependencies, npm
Best Practices for Securing Node.js Applications in Production308
best-practices, nodejs
npm Provenance General Availability307
npm, provenance
The WebP 0-Day306
webp, google, apple
Open Source Trends to Look for in 2024305
foss, trends, outlooks, ai
Securing Your Node.js Apps by Analyzing Real-World Command Injection Examples304
nodejs, history, examples
How to Implement SSL/TLS Pinning in Node.js303
how-tos, ssl, tls, nodejs
A More Intelligent and Secure Web (ple/w3c)302
videos, w3c, standards, web, web-platform
Demystifying CORS: Understanding How Cross-Origin Resource Sharing Works301
cors, javascript
Towards HTTPS by Default (jde)300
browsers, chrome, http, tls
Sophisticated, Highly-Targeted Attacks Continue to Plague npm299
npm
An Update on Chrome Security Updates—Shipping Security Fixes to You Faster298
browsers, chrome
Tuesday, August 8, 2023 Security Releases (raf/nod)297
release-notes, nodejs
SECURITY.md: Should I Have It? (mry/ecl)296
documentation
Publishing With npm Provenance From Private Source Repositories Is No Longer Supported295
npm, provenance, foss
Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware (soc)294
malware, npm
Securing the Web Forward: Addressing Developer Concerns in Web Security (tor/w3c)293
web, surveys
User Input Sanitization and Validation: Securing Your App292
sanitization, validation, conformance
Encoding: A Brief History and Its Role in Cybersecurity291
encoding, unicode, history
Node.js Security Progress Report—17 Reports Closed (ope)290
nodejs
The Importance of Verifying Webhook Signatures289
webhooks
The Massive Bug at the Heart of the npm Ecosystem (dar/vlt)288
npm, dependencies, bugs
An Introduction to Command Injection Vulnerabilities in Node.js and JavaScript287
introductions, vulnerabilities, nodejs, javascript
All You Need to Know About CORS and CORS Errors286
cors, errors
Understanding Authorization Before Authentication: Enhancing Web API Security285
authorization, authentication, apis, comparisons
Django: A Security Improvement Coming to “format_html()” (ada)284
django, html
Tuesday, June 20, 2023 Security Releases (raf/nod)283
release-notes, nodejs
security.txt Now Mandatory for Dutch Government Websites282
legal
File Upload Security and Malware Protection (aus)281
malware, file-handling, edge-computing
Security Implications of HTTP Response Headers280
http, http-headers
The Case Against Automatic Dependency Updates (ben)279
dependencies, automation, ci-cd, maintenance
Automating Dependency Updates: The Big Debate278
dependencies, automation, ci-cd
Generating Provenance Statements277
npm, provenance
Introducing npm Package Provenance276
introductions, npm, provenance, foss
8 Best Tools for Cryptography and Encryption (sta)275
link-lists, tooling, comparisons, cryptography, encryption, privacy
Dissecting npm Malware: Five Packages and Their Evil Install Scripts274
npm, malware
Passkeys: What the Heck and Why? (css)273
passkeys
Senior Engineering Strategies for Advanced React and TypeScript (tec)272
strategies, react, typescript, architecture, testing, performance, accessibility, maintenance
Cryptographically Protecting Your SPA271
single-page-apps, cryptography
Tips for Handling Dependabot, CodeQL, and Secret Scanning Alerts270
alerting, dependabot, tips-and-tricks
Without Accessibility, There Is No Privacy or Security (lev)269
accessibility, privacy
How to Password-Protect a Static HTML Page With No JS (ede)268
how-tos, css, fonts
SSL Certificates Explained267
videos, certificates, ssl, protocols
Quick Tip: How to Hash a Password in PHP266
how-tos, php, passwords, tips-and-tricks
Sandboxing JavaScript Code265
javascript
Avoiding the Success Trap: Toward Policy for Open-Source Software as Infrastructure (atl)264
foss, infrastructure, policies, concepts
Unlocking Security Updates for Transitive Dependencies With npm263
npm, dependencies, maintenance
7 Required Steps to Secure Your Iframes Security262
iframes, xss, html, http-headers, csp
Conditional API Responses for JavaScript vs. HTML Forms (aus)261
javascript, html, forms, comparisons
Why Do We Need Authorization and Authentication?260
authorization, authentication
The Top 10 Security Vulnerabilities for Web Applications259
vulnerabilities, web-apps
Leaked a Secret? Check Your GitHub Alerts… for Free258
github
DOM Clobbering (fre/mat)257
dom
New npm Features for Secure Publishing and Safe Consumption256
npm, dependencies
Using SRI to Protect From Malicious JavaScript (mat)255
javascript
WordPress Versions 3.7–4.0 No Longer Get Security Updates (sar)254
wordpress
“Not Secure” Warning for IE Mode253
browsers, edge, internet-explorer
Node.js Security Best Practices (nod)252
nodejs, best-practices
npm Security: Preventing Supply Chain Attacks251
npm, dependencies
Secure JavaScript URL Validation250
javascript, validation, urls
Create a Passkey for Passwordless Logins (age)249
authentication, passkeys
Designing a Secure API248
software-design, apis
Phylum Detects Active Typosquatting Campaign Targeting npm Developers247
npm, dependencies
Security (htt)246
web-almanac, studies, research, metrics
Continue Using .env Files as Usual245
environments
Quick Reminder: HTML5 “required” and “pattern” Are Not a Security Feature (cod)244
html, forms
Stop Using .env Files Now243
environments
Debunking Myths About HTTPS242
http, myths
Secure Your Node.js App With JSON Web Tokens (app)241
nodejs, json-web-tokens
Dependabot Unlocks Transitive Dependencies for npm Projects240
dependencies, npm, dependabot
JavaScript Bugs Aplenty in Node.js Ecosystem—Found Automatically239
studies, research, nodejs, javascript, dependencies, quality, bugs
Introducing Even More Security Enhancements to npm238
introductions, npm
Top 5 npm Vulnerability Scanners237
npm, vulnerabilities, tooling
What Is Passwordless Authentication and How to Implement It236
authentication, passwords
GA4 Is Being Blocked by Content Security Policy235
csp, metrics, google
Please Remove That .git Folder234
git
Should I Have Separate GitHub Accounts for Personal and Professional Projects?233
discussions, github, career
Understanding CSRF Attacks (zel)232
csrf
npm Security Update: Attack Campaign Using Stolen OAuth Tokens231
oauth, version-control, npm
Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks230
javascript, npm, dependencies
Unexpectedly HTTPS?229
http
How to Respond to Growing Supply Chain Security Risks?228
how-tos, dependencies, nodejs, npm
The Web Is for Everyone: Our Vision for the Evolution of the Web (moz)227
web, outlooks, privacy, accessibility, performance, user-experience
Using HTTPS in Your Development Environment226
http, environments
How to Prevent SQL Injection Attacks in Node.js225
how-tos, nodejs, databases, sql
How to Fix Your Security Vulnerabilities With npm Override224
how-tos, vulnerabilities, npm, dependencies
Can You Get Pwned With CSS?223
css
Never, Ever, Ever Use Pixelation for Redacting Text222
content, images, obfuscation
Accessibly Insecure221
accessibility
Lessons Learned From Publishing a Content Security Policy220
lessons, csp
Ain’t No Party Like a Third Party (ada/css)219
dependencies, embed-code
Security (htt)218
web-almanac, studies, research, metrics
GitHub’s Commitment to npm Ecosystem Security217
github, npm
Understanding and Implementing OAuth2 in Node.js (hon)216
nodejs, authorization, oauth
How to Win at CORS (jaf)215
how-tos, cors, html, http
The Options for Password-Revealing Inputs (chr/css)214
html, css, passwords, usability
npm Security Best Practices (owa)213
npm, best-practices
Encoding Data for POST Requests (jaf)212
javascript, encoding
NPM Global Audit211
packages, npm, quality, auditing
Understanding and Preventing Common Security Vulnerabilities210
vulnerabilities
Open Source Insights209
websites, foss, dependencies, licensing
I Learned to Love the Same-Origin Policy (eee/css)208
cors
TLS and mTLS Demystified207
tls, protocols
Is Edge Computing Secure? Here Are 4 Security Risks to Be Aware Of206
edge-computing
Best Practices for Inclusive Textual Websites205
performance, accessibility, best-practices
Clickjacking Attacks and How to Prevent Them204
how-tos
How to Safely Use GitHub Actions in Organizations (nza)203
how-tos, github-actions
What Is mTLS and How Does It Work?202
Mutual TLS: Stuff You Should Know201
tls, protocols
Don’t Try to Sanitize Input—Escape Output200
sanitization, escaping
Encrypting DNS Query Bad for Performance? (erw)199
performance, dns, http, encryption
Apple Joins FIDO Alliance, Commits to Getting Rid of Passwords (sjv/zdn)198
apple, fido, passwords, authentication
How to Automatically Update Your JavaScript Dependencies (spa/clo)197
how-tos, javascript, dependencies, automation, processes
What SSL Is, and Which Certificate Type Is Right for You196
ssl, certificates, privacy, concepts
Usability and Security; Better Together (24w)195
usability, user-experience
Server-Side Includes (SSI) Injection (owa)194
ssi
How Internet Security Works: TLS, SSL, and CA (osd)193
tls, ssl, protocols, certificates
Security and Privacy for Our Times (luk/w3c)192
privacy, web-platform
Web Feature Developers Told to Dial Up Attention on Privacy and Security (rip)191
w3c, privacy, web-platform
CSS Security Vulnerabilities (chr/css)190
css, privacy, vulnerabilities
Understanding Subresource Integrity (dre/sma)189
hashing, embed-code
W3C Strategic Highlights: Web for All (Security, Privacy, Identity) (w3c)188
w3c, privacy, authentication
Guide to Web Authentication187
websites, authentication, webauthn, javascript
It’s Beginning to Look a Lot Like XSSmas (24w)186
vulnerabilities, csrf, xss
Protecting Your Site With Feature Policy (rac/sma)185
http-headers, http
AWS Security Guide: 7 Best Practices to Avoid Security Risks (wom)184
guides, aws, best-practices
WebAuthn, FIDO2 Infuse Browsers, Platforms With Strong Authentication (dar)183
w3c, fido, authentication, webauthn, browsers
In Your Face, Passwords: Big Three Browsers All Adopt Authentication API182
authentication, webauthn, apis, edge, chrome, firefox, browsers
HTTPS Is Easy (tro)181
websites, http
WordPress Security as a Process (sma)180
wordpress, processes
Making Your Website Faster and Safer With Cloudflare179
performance, caching, cloudflare
Validating Dependencies in the Project With npm-check and depcheck178
dependencies, maintenance, auditing, tooling, npm
Third Party CSS Is Not Safe (jaf)177
html, css, embed-code
Attackers Can Steal Sensitive Data by Abusing CSS—CSS Exfil Vulnerability176
css, csp
Building Secure JavaScript Applications175
javascript, xss, csrf, json-web-tokens, passwords
Creating Secure Password Resets With JSON Web Tokens (sma)174
passwords, json-web-tokens, nodejs
The Complete Guide to Switching From HTTP to HTTPS (sma)173
guides, http
Rate Limiting With nginx172
servers, nginx, rate-limiting
How (Not) to Control Your CDN (mno)171
content-delivery, caching, http
How to Secure WordPress With SSL170
how-tos, wordpress, ssl
Encrypting IP Addresses (ber)169
ip, network, privacy, encryption
How to Secure Your Web App With HTTP Headers (sma)168
how-tos, web-apps, http, http-headers, csp
Just Another HTTPS Nudge (chr/css)167
http
On EME in HTML5 (tim/w3c)166
eme, drm, html, legal, standards, w3c
What Is HTTPS and SSL, and Why Your Ecommerce Website Badly Needs Them Both165
http, ssl, ecommerce
Using SSH Securely (ann)164
ssh
More Than 300 Federal Gov Websites Fail to Meet Domain Encryption Deadline163
http, tls, protocols, encryption
Content Security Policy Level 2 (mik+/w3c)162
standards, csp
A Checklist for Website Reviews (hcr)161
checklists, performance, browsers, seo, accessibility
Content Security Policy, Your Future Best Friend (sma)160
csp, link-lists
A Refined Content Security Policy (web)159
html, csp, webkit, safari, browsers
The Performance Benefits of “rel=noopener” (jaf)158
html, links, performance
Web Platform Security Boundaries (ann)157
web-platform
Subresource Integrity (dev+/w3c)156
hashing, html, standards
npm Fails to Restrict the Actions of Malicious npm Packages155
npm, vulnerabilities
W3C Looks to Secure the Web (sdt)154
w3c, authentication
Distribution Packages Considered Insecure153
dependencies, unix-like
The Current State of Web Security (An Interview With Anselm Hannemann) (hel+/css)152
interviews, http, ssl, tls, encryption, cloudflare, lets-encrypt
Eliminating Known Vulnerabilities With Snyk (sma)151
vulnerabilities, tooling
10 Web Predictions for 2016 (cra)150
web, outlooks, site-generators, browsers, css, mobile, performance, webassembly, seo
HSTS and “Let’s Encrypt” (tka)149
http, http-headers, ssl, lets-encrypt
Indexing HTTPS Pages by Default148
google, search, http
An in-Depth Look at CORS147
cors, javascript, php
Why Passwordless Authentication Works (cra)146
authentication, passwords
Introduction to TLS and SSL (ope)145
introductions, tls, ssl, protocols, certificates
A Simple Developer Error Is Exposing Private Information on Thousands of Websites (owe)144
version-control, git, mistakes, vulnerabilities
More Tips to Further Secure WordPress (eli)143
wordpress, tips-and-tricks, plugins
Improving Web Security With the Content Security Policy142
csp, http
Deprecating HTTP141
http, protocols, deprecation
Mozilla Wants to Deprecate Non-Secure HTTP, Will Make Proposals to W3C “Soon” (epr/ven)140
mozilla, http, deprecation
Want Fancy Firefox Features? Secure Your Website (sts/cne)139
firefox, browsers, http
WordPress Front End Security: CSRF and Nonces (css)138
wordpress, csrf
Introduction to WordPress Front End Security: Escaping the Things (css)137
introductions, wordpress, escaping
What Are the Security Risks of HTML5 Apps?136
web-apps, sanitization
Moving to HTTPS on WordPress (chr/css)135
wordpress, http
Same-Origin Policy (ann)134
cors, web-platform
Securing the Web (w3c)133
web-platform
What I’d Tell My Younger Self About Learning Development as a Web Designer132
learning, programming, javascript, databases, servers, preprocessors, version-control, performance, career
HTTPS as a Ranking Signal (met)131
google, search, http, seo
mXSS (gaz)130
xss, html
It’s Time to Encrypt the Entire Internet (kli/wir)129
web, http, ssl, encryption
3 Tips to Find Hacking on Your Site, and Ways to Prevent and Fix It128
search, google, tips-and-tricks
Cross-Origin Resource Sharing (ann/w3c)127
cors, standards
Despite Automatic Updates, Old Browsers Are Still a Problem (edb/zdn)126
browsers, web-platform, chrome, firefox, internet-explorer, safari
Cross-Origin Resource Sharing on Track to Become a W3C Recommendation (sdt)125
w3c, cors, standards
Bid to Kill CAPTCHA Security Test Gains Momentum124
captcha, accessibility
We Should All Have Something to Hide123
privacy
Mobile Website Security122
mobile, hosting, policies
WordPress Security Tips121
wordpress, tips-and-tricks
Brad Hill: “HTML5 Security Realities” (chr/css)120
slides, xss, html
Bulletproof Your Drupal Website119
drupal
Top 10 PHP Security Vulnerabilities118
php, vulnerabilities
A Front End Engineer’s Manifesto (zac)117
websites, manifestos, user-experience, progressive-enhancement, simplicity, foss, accessibility, community, learning
A JavaScript Security Flaw116
javascript
The Secure Programmer’s Pledge115
manifestos
An Introduction to Content Security Policy (mik)114
introductions, csp
Rate Limiting With Apache and mod_security (joh)113
servers, apache, rate-limiting
Cross-Site Scripting Attacks (XSS)112
xss, examples
How to Secure Your WordPress Website (sma)111
how-tos, wordpress, link-lists
Using CORS110
cors
Some Notes on the Recent XML Encryption Attack (w3c)109
xml, encryption
XML Encryption Flaw Leaves Web Services Vulnerable (eur)108
web-services, xml, encryption
Notes From Writing HTML5 Media (bur)107
html, multimedia
HTTPS Is More Secure, So Why Isn’t the Web Using It? (ars)106
http, protocols, web
Web Cryptography: Salted Hash and Other Tasty Dishes (ali)105
cryptography
What Are the JSON Security Concerns in Web Development? (sim)104
json
What Is Cross Site Scripting or XSS? (chr/css)103
xss, javascript, concepts
Web Developers Accountable for HTML 5 Security (zdn)102
html
HTML5 Raises New Security Issues101
html, browsers
10 Useful WordPress Security Tweaks (sma)100
wordpress
Web Security: Are You Part of the Problem? (cod/sma)99
vulnerabilities, php, javascript
Full Frontal ’09: Chris Heilmann on JavaScript Security (mic/aja)98
javascript
Cookies and Security (nza)97
cookies, xss, csrf
A Critical Vulnerability in IE8 (jed)96
internet-explorer, browsers, vulnerabilities
Finally Something to Get a Few More Users Off of IE 6? (dal/aja)95
internet-explorer, browsers
The Internet Is Closing to Innovation (zit/new)94
web
You Could Be Getting Clickjacked (tec)93
vulnerabilities, frames, w3c
Video and Audio Tags and Cross Origin Access (dal/aja)92
html, multimedia
Dumb Security Tips: Think Before You Follow Online Guides (tan)91
tips-and-tricks
Alerting Webmasters to Webserver Vulnerabilities90
google
Simon Willison, @Media Ajax (mic/aja)89
ajax, xss, csrf, javascript, json