Tech is political: The people under attack in Palestine 🇵🇸, Iran 🇮🇷, and Lebanon 🇱🇧 are people like us. They’re our brothers and sisters, too. Read up on their history, scrutinize what you’re told, and demand respect and accountability. Hide

Frontend Dogma

“security” News Archive

Definition, related topics, and tag feed

Definition · Supertopics: user-experience · Subtopics: authentication, authorization, bot-detection, certificates, cors, cryptography, csp, csrf, hashing, malware, privacy, provenance, randomness, rate-limiting, sanitization, ssh, ssl, tls, validation, vulnerabilities, xss (non-exhaustive) · “security” × ? · “security” RSS feed (per email)

Entry (Sources) and Additional TopicsDate#
There’s a New Way to Break RSA That’s Faster Than Anything We’ve Seen Before (dan/ars)616
cryptography
Stage-Only npm Tokens for Safer Automation615
npm, automation
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang (agr/wir)614
google
The AI Threat Is Real, It Just Isn’t the One in the Headlines (rob)613
ai, outlooks, anthropic, openai
Introducing secure-eval-worker (mco/pla)612
introductions, nodejs, libraries, javascript, permissions
Anthropic’s Misuse Report, Condensed to 117 Findings (dan)611
anthropic, claude, ai, ai-agents
The V8 JavaScript Runtime Undermined My Constant-Time JavaScript Library (soa)610
v8, javascript, time
Cloud Takeover: Mass Scanning for Exposed Vite Endpoints (CVE-2026-39364) (f5l)609
vite
npm Extends Recovery-Code Security Holds to All Accounts608
npm
A Developer’s Practical Guide to Integrating AI Tools in Modern Web Development607
guides, ai, tooling
OpenAI Agents Hijacked German Website Before Hugging Face Hack, Report Claims (zsk)606
openai, ai
Your Next OpenAI API Timeout Might Not Be a Timeout at All605
openai, ai
Aaron D. Campbell on Navigating WordPress Security in the AI Era (aar+)604
podcasts, interviews, wordpress, ai
Vibe-Coded Apps Are the New Shadow IT603
vibe-coding, ai, tooling
Ensuring Code Compliance in Public Sector Software Projects (jet)602
compliance, privacy, auditing, qodana
OpenAI Agents Hacked Hugging Face in 700-Strong Swarm, Tried to Cover Tracks: Investigations (str)601
openai, hugging-face, ai
Good Riddance, TeamPCP. Now for the Hard Part.600
AI Checks AI: OpenAI Promises More Control After Attack on Hugging Face (mho/hei)599
ai, openai, hugging-face
The Pulse: Grok’s CLI Caught Uploading All Your Local Files to the Cloud (ger)598
ai
Triaging the AI Horde (mco)597
ai, processes
CSS: The Bomb Inside Your Inbox (gaz/por)596
css, html, csp, email
Web Security Is Too Hard (eri)595
cloudflare, case-studies
Major Shai Hulud Campaign Strikes npm Again, Affecting keyv and 400+ Packages594
npm, dependencies
Stronger With Every Update: How We’re Making Chrome and the Web Safer in the AI Era593
chrome, browsers, ai
Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks592
foss, amazon
Maciek Palmowski on Testing Secure WordPress Hosting: Does the Marketing Match Reality? (pal+)591
podcasts, interviews, wordpress, hosting
Local-First AI Coding Workflow for Security-Conscious Teams (age)590
ai, processes
Disrupting Supply Chain Attacks on npm and GitHub Actions (gre+)589
npm, github-actions, link-lists
The Secure Way to Release an npm Package in 2026 (sit+/evi)588
dependencies, npm, configuration
npm Publish-Time Malware Scanning and Dual-Use Metadata587
npm, dependencies
Weaponizing and Defending the React Flight Protocol: Deserialization Sinks in RSCs (sma)586
react, components
Monday, July 27, 2026 Security Releases (nod)585
release-notes, nodejs
Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk (lor)584
wordpress, bugs
[Hugging Face] Security Incident Disclosure—July 2026583
hugging-face, ai
Milan Petrović on the Risks of Legacy PHP in WordPress and Why Upgrading Matters for Security (nat)582
podcasts, interviews, php, wordpress, maintenance
Now, Defenders Are Embracing the Prompt Injection, Too (ars)581
ai, prompting
npm Install-Time Security and GAT bypass2fa Deprecation580
npm, deprecation
You Shouldn’t Trust Trusted Publishing (yos)579
authentication
6 Security Settings Every GitHub Maintainer Should Enable This Week578
github, configuration, documentation
Shipping Post-Quantum Cryptography to Python (tra)577
python, cryptography, foss
npm Adds Preventive Account Protection for High-Impact Accounts576
npm
Ignore DNSSEC if You Like MITM Attacks575
dns
Anthropic’s Fable and the State of AI (sch)574
ai, anthropic, foss
Blocking Install Scripts Is Not a Silver Bullet (uli/nod)573
npm
Reuse Less Software572
dependencies, processes
Upcoming Breaking Changes for npm v12571
npm
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders (sar/soc)570
npm, bugs
Wednesday, June 17, 2026 Security Releases (nod)569
release-notes, nodejs
The Website Specification (joo)568
websites, documentation, fundamentals, seo, accessibility, ai-agents, performance, privacy, resilience, internationalization
The VibeSec Reckoning (mfo)567
ai, vibe-coding
Megalodon: Mass GitHub Repo Backdooring via CI Workflows566
github, ci-cd
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension (the)565
github, vs-code
GitHub Hacked—Internal Source Code Repositories Compromised via Employee Device564
github
Mini Shai Hulud: Compromised @antv npm Packages Enable CI/CD Credential Theft563
npm, dependencies, ci-cd
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised562
npm, dependencies
“The Worst Leak That I’ve Witnessed”: US Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub (giz)561
passwords, github
A Worm Just Ate Its Way Through the npm Registry… (fir)560
videos, npm, dependencies, tanstack
Hardening TanStack After the npm Compromise (cru+/tan)559
tanstack
Hackers Abuse Google Ads and Claude.ai Shared Chats to Distribute macOS Malware558
apple, unix-like, google, claude, ai
Weekend at Bernie’s (and)557
dependencies, foss, metrics
Behind the Scenes Hardening Firefox With Claude Mythos Preview (fre+/moz)556
firefox, browsers, claude, ai
Trustworthy JavaScript for the Open Web (moz)555
javascript, open-web, firefox, browsers
The Zero-Days Are Numbered (moz)554
firefox, browsers, ai, anthropic
Vercel April 2026 Security Incident553
vercel
AI Will Never Be Ethical or Safe (j9t)552
ai, ethics
No One Owes You Supply-Chain Security (pur)551
dependencies, rust
Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them550
wordpress, plugins
Adversarial AI: Understanding the Threats to Modern AI Systems (jet)549
ai, concepts
Anthropic Debuts Preview of Powerful New AI Model Mythos in New Cybersecurity Initiative548
anthropic, ai
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign (sar/soc)547
nodejs, foss
Post Mortem: Axios npm Supply Chain Compromise546
axios, npm
The Hidden Blast Radius of the Axios Compromise (ahm/soc)545
dependencies, npm, axios
Minimum Release Age Is an Underrated Supply Chain Defense (dan)544
dependencies, npm, bun, pnpm, yarn, deno, renovate, dependabot, axios
Axios Compromised on npm—Malicious Versions Drop Remote Access Trojan543
npm, dependencies, axios
Prevent Claude Code From Accessing .env (jad)542
claude, ai, environments
Node.js Brotli UAF (mai)541
nodejs, permissions, brotli, compression, claude, ai
Malicious PyPI Package—LiteLLM Supply Chain Compromise540
dependencies, vulnerabilities
Developing a Minimally HashDoS Resistant, Yet Quickly Reversible Integer Hash for V8 (joy/nod)539
nodejs, hashing
Tuesday, March 24, 2026 Security Releases (nod)538
release-notes, nodejs
Supply-Chain Attack Using Invisible Code Hits GitHub and Other Repositories (dan/ars)537
github, dependencies
OWASP’s Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed536
videos, vulnerabilities, ai, owasp
A GitHub Issue Title Compromised 4,000 Developer Machines535
github, ai
How to Steal npm Publish Tokens by Opening GitHub Issues (nec)534
npm, github, ai
MCP Servers and the Return of the Service Account Problem (aem)533
servers, mcp, ai
Security Advisory: Addressing Recent Vulnerabilities in Angular (ang)532
angular
An Exploit… in CSS?! (css)531
css
Goodbye “innerHTML”, Hello “setHTML”: Stronger XSS Protection in Firefox 148 (moz)530
javascript, methods, xss, firefox, browsers
How Fake CAPTCHA Scams Trick You Into Installing Malware (mal)529
captcha, malware
Europe Is Ready to Ditch US Tech for Private Alternatives (pro)528
tooling, privacy, metrics
WebSocket Penetration Testing: A Complete Guide to CSWSH527
guides, websockets, testing
Node.js Path Traversal: Prevention and Security Guide (loi)526
guides, nodejs
Cryptography Usage in Web Standards (w3c)525
standards, cryptography
OpenJS Foundation Security Program: Annual Report 2025 (ope)524
openjs
A Security Checklist for Your React and Next.js Apps523
react, nextjs
How to Implement Rate Limiting in nginx (naw/one)522
how-tos, servers, nginx, rate-limiting
Securing npm Is Table Stakes (nza+/cha)521
podcasts, interviews, npm, ai
Security (vik+/htt)520
web-almanac, studies, research, metrics, tls, certificates, cookies, csp, http-headers, apis, sanitization, configuration
Node.js January 2026 Security Release: What Changed and Why It Matters (nod)519
nodejs
Mitigating Denial-of-Service Vulnerability From Unrecoverable Stack Space Exhaustion for React, Next.js, and APM Users (mco+/nod)518
nodejs, vulnerabilities, react, nextjs, tooling, monitoring, performance
Tuesday, January 13, 2026 Security Releases (nod)517
release-notes, nodejs
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens (sar/soc)516
npm, dependencies
Security Basics for Vibe-Coders (owe/pro)515
fundamentals, vibe-coding, ai
Testing Methods: Accessible Authentication (Enhanced) (dec)514
accessibility, testing, wcag, authentication
Testing Methods: Accessible Authentication (Minimum) (dec)513
accessibility, testing, wcag, authentication
Denial of Service and Source Code Exposure in React Server Components (rea)512
react, components
Thursday, December 18, 2025 Security Releases (nod)511
release-notes, nodejs
How We’re Protecting Our Newsroom From npm Supply Chain Attacks (rya/pnp)510
npm, dependencies, case-studies
No More Tokens—Locking Down npm Publish Workflows (zac)509
npm, dependencies, processes
[Next.js] Security Advisory: CVE-2025-66478 (seb)508
nextjs
Critical Security Vulnerability in React Server Components (rea)507
react, components
Decreasing [Let’s Encrypt] Certificate Lifetimes to 45 Days (mat/let)506
http, certificates, lets-encrypt
Taking Down Next.js Servers for 0.0001 Cents a Pop505
servers, nextjs, vulnerabilities
The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know504
npm, dependencies
GitLab Discovers Widespread npm Supply Chain Attack503
npm, dependencies, gitlab, aws, gcp, azure
Automated npm Secret Rotation in GitHub Actions (mhe)502
npm, automation, github-actions
What Developers Really Mean by “Bad Code” (jet)501
maintainability, scalability, consistency, quality
Introducing the OWASP Top 10:2025 (she+/owa)500
introductions, owasp, vulnerabilities
Removing XSLT for a More Secure Browser (dro)499
chromium, chrome, browsers, xsl, web-platform
Agentic AI and Security (ksi/mfo)498
ai, architecture
Octoverse: A New Developer Joins GitHub Every Second as AI Leads TypeScript to #1497
github, metrics, productivity, ai, foss, programming
HTTPS by Default (jde+)496
http, chrome, browsers
Will npm’s New Security Steps Stop Attacks? (rev)495
npm, maintenance, foss
Glassworm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace494
code-editors, vs-code
Improving the Trustworthiness of JavaScript on the Web493
javascript, web-apps
Past Time for Passkeys (nor)492
videos, passkeys, passwords, authentication
Secure Coding in JavaScript491
javascript, frameworks
My Conclusions After Using Signed Exchanges on My Website for 2 Years (paw)490
signed-exchanges, performance
Lazy-Loading as a Security Measure489
lazy-loading, angular, react
Backend Concepts Every Experienced Developers Must Know488
concepts, network, concurrency, apis, databases, caching, scalability, observability, architecture
Fixing Safari Mixed Content Issues With Vite and mkcert487
safari, browsers, vite, tooling
How Deno Protects Against npm Exploits (den)486
deno, npm
Strengthening npm Security: Important Changes to Authentication and Token Management485
npm
How Hackers Use AI to Find Vulnerabilities Faster484
ai
CAPTCHA, When Security Takes Precedence Over Accessibility483
captcha, accessibility
Our Plan for a More Secure npm Supply Chain (xco)482
npm, dependencies, foss
npm Security Best Practices481
npm, provenance, best-practices
This May Be the Worst One (the)480
videos, npm, dependencies
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages (pvd+/soc)479
npm, dependencies
ctrl/tinycolor and 40+ npm Packages Compromised478
npm, dependencies
How Maintainer Burnout Is Causing a Kubernetes Security Disaster477
kubernetes, maintenance, foss, economics
Oh No, Not Again… a Meditation on npm Supply Chain Attacks (tan)476
npm, dependencies, microsoft
Anatomy of a Billion-Download npm Supply-Chain Attack475
npm, dependencies
npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack (bur+/soc)474
npm, dependencies
CORS Explained: Stop Struggling With Cross-Origin Errors473
cors, http-headers, http
How OpenJS-Hosted Projects Benefit From Security Support (ope)472
openjs, hosting, foss
Why You Absolutely Need to Have Automated Dependency Management in Place (j9t)471
dependencies, maintainability, maintenance, automation, tooling
What Your Website’s Style Says About You—and How Hackers Can Use It Against You (err)470
css, javascript
Hardening Node.js Apps in Production: 8 Layers of Practical Security469
nodejs, best-practices
eslint-config-prettier Compromised: How npm Package With 30 Million Downloads Spread Malware468
prettier, eslint, npm, malware
npm Phishing Email Targets Developers With Typosquatted Domain (sar/soc)467
npm
AI Agents Are Creating a New Security Nightmare for Enterprises and Startups466
ai, apis
Tuesday, July 15, 2025 Security Releases (nod)465
release-notes, nodejs
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc)464
npm, dependencies
Dependabot Supports Configuration of a Minimum Package Age463
dependabot, configuration
MCP Security Vulnerabilities and Attack Vectors462
mcp, ai
A New Era of Code Quality461
quality
JWTs Are Not Session Tokens, Stop Using Them Like One460
json-web-tokens, authentication
Design Patterns for Securing LLM Agents Against Prompt Injections (sim)459
studies, research, ai, prompting, software-design-patterns
The Growing Risk of Malicious Browser Extensions (soc)458
browser-extensions
HTML Spec Change: Escaping “<” and “>” in Attributes (sec)457
html, attributes, escaping, xss
Escaping “<” and “>” in Attributes—How It Helps Protect Against Mutation XSS (sec)456
html, attributes, xss, escaping, chrome, browsers
Beware of End-of-Life Node.js Versions—Upgrade or Seek Post-EOL Support (mco/nod)455
nodejs, maintenance
How to Access Local MCP Servers Through a Secure Tunnel454
how-tos, mcp, ai, servers, network
Docker Launches Hardened Images, Intensifying Secure Container Market453
docker
Modernizing Security452
modernization, processes
Securing Your Node.js App From Command Injection451
nodejs
Passkeys for Normal People (tro)450
authentication, passkeys, examples, concepts
npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc)449
npm, malware, dependencies, link-lists
What Is an Encryption Backdoor? (int)448
encryption, vulnerabilities, concepts
Cybersecurity Leaders Are Staying in the Shadows (ste)447
community, culture
Principles for Coding Securely With LLMs (sea)446
ai, principles
Threat Actors Misuse Node.js to Deliver Malware and Other Malicious Payloads445
nodejs, malware
TLS Certificate Lifetimes Will Officially Reduce to 47 Days444
tls, certificates
LLMs Can’t Stop Making Up Software Dependencies and Sabotaging Everything (tho/the)443
ai, dependencies, slop
Secure a Vue App With OpenID Connect and the BFF Pattern (due)442
vuejs, authentication, backend-for-frontend
Teaching Code in the AI Era: Why Fundamentals Still Matter (ali)441
training, ai, programming, vibe-coding, scalability, performance, quality, testing, documentation
Stop Using Jenkins in 2025 (oso)440
jenkins, github-actions, ci-cd
Node.js Test CI Security Incident (nod)439
nodejs, retrospectives
Website Hijack Campaign Now Impacting 150,000 Sites (gad)438
Malware Found on npm Infecting Local Package With Reverse Shell (rev)437
npm, dependencies
Five Things Vibe Coders Should Know (From a Software Engineer)436
vibe-coding, sanitization, rate-limiting
GitHub Suffers a Cascading Supply Chain Attack Compromising CI/CD Secrets (inf)435
github, ci-cd
How to Prevent WordPress SQL Injection Attacks (sma)434
how-tos, wordpress, sql, databases
Lazarus Strikes npm Again With New Wave of Malicious Packages (soc)433
npm, dependencies
What Is the OWASP Top 10 and How Can Your Team Benchmark Security? (jet)432
owasp, vulnerabilities, qodana
Updates on CVE for End-of-Life Versions (raf/nod)431
nodejs
How to Protect Your Web Applications From XSS (tor/w3c)430
how-tos, web-apps, xss
In Tech, What Matters and What Is Dangerous (ham)429
community, foss, open-web
Secure UX: Building Cybersecurity and Privacy Into the UX Lifecycle (uxm)428
user-experience, processes
The Fallacy of Balance: Challenging the Notion of Security and Accessibility as Opposing Objectives (deq)427
videos, accessibility
It Is No Longer Safe to Move Our Governments and Societies to US Clouds (ber)426
cloud-computing, privacy, legal
How OWASP Helps You Secure Your Full-Stack Web Applications (eri/sma)425
owasp, monitoring, authentication, vulnerabilities, configuration, csrf, cryptography, authorization
10 Common Web Development Mistakes to Avoid Right Now424
mistakes, mobile, performance, accessibility, seo, navigation, analytics, testing
Tightening Every Bolt (bag)423
videos, processes, code-reviews, testing
On Generative AI Security (sch)422
ai, lessons, microsoft
Understanding CORS Errors in Signed Exchanges (paw)421
cors, errors, signed-exchanges
Keep Your Node.js Apps Secure With “npx is-my-node-vulnerable” (tre)420
packages, npm, nodejs
Node.js EOL Versions CVE Dubbed the “Worst CVE of the Year” by Security Experts (sar/soc)419
nodejs, documentation
How I Open-Sourced My Secret Access Tokens From GitHub, Slack, and npm—and Who Actually Cares418
github, slack, npm
Tuesday, January 21, 2025 Security Releases (raf/nod)417
release-notes, nodejs
APIs Are Quickly Becoming the Latest Security Battleground (and Nightmare)416
apis
CDN-First Is No Longer a Performance Feature (osv)415
content-delivery, performance, caching, embed-code, privacy
The Cyber-Cleanse: Take Back Your Digital Footprint (cyb)414
privacy
15 Principles for Secure Programming (rak)413
principles, validation, testing
Important Topics for Frontend Developers to Master in 2025412
learning, javascript, typescript, css, frameworks, git, apis, testing, performance, ci-cd, websockets
How to Automate OWASP Security Reviews in Your Pull Requests? (cod)411
how-tos, owasp, automation, code-reviews, coderabbit
Developer Guide: How to Implement Passkeys410
guides, how-tos, authentication, passkeys
5 Technical Trends to Help Web Developers Stand Out in 2025409
trends, career, javascript, ai, low-and-no-code
Avoid Hotlinking Images With “Cross-Origin-Resource-Policy”408
images
Content Security Policy Level 3 (mik/w3c)407
standards, csp
Security (vik/htt)406
web-almanac, studies, research, metrics
JavaScript Import Attributes (ES2025) (tre)405
javascript
Exploring Internet Traffic Shifts and Cyber Attacks During the 2024 US Election404
traffic
Cross-Site WebSocket Hijacking: Understanding and Exploiting CSWSH (pen)403
websockets
Securing Your Express REST API With Passport.js402
nodejs, express, json-web-tokens, apis, rest, tooling
SecretLint—a Linter for Preventing Committing Credentials (tre)401
tooling, linting
Top 4 Web Vulnerabilities With Example and Mitigation400
vulnerabilities, sql, databases, xss, csrf
The Importance of UX in Cybersecurity (uxm)399
user-experience, usability
Understanding “npm audit” and Fixing Vulnerabilities398
npm, vulnerabilities, nodejs
How to Implement Content Security Policy (CSP) Headers for Astro (tre)397
how-tos, http, http-headers, csp, astro, vercel, cloudflare
Why Code Security Matters—Even in Hardened Environments396
vulnerabilities, file-handling, nodejs
Database 101: SSL/TLS for Beginners395
introductions, databases, ssl, tls, authentication
Cloudflare Study: 39% of Companies Losing Control of Their IT and Security Environment (tre)394
studies, research, engineering-management
NIST Recommends Some Common-Sense Password Rules (sch)393
passwords, guidelines
I Finally Understand OAuth392
authorization, oauth, processes
Fake GitHub Site Targeting Developers (jul/san)391
github
Hacking Cars in JavaScript (Running Replay Attacks in the Browser With the HackRF) (dev)390
javascript
Gaining Access to Anyone’s Browser Without Them Even Visiting a Website389
arc, browsers, vulnerabilities
10 AI Dangers and Risks and How to Manage Them (rin)388
ai, privacy, sustainability, legal
Web Security: Shaping the Secure Web (set/w3c)387
web, w3c
5 Wasm Use Cases for Frontend Development (ele/des)386
guest-posts, webassembly, performance
What Is Incident Response?385
incident-response, overviews
The Great npm Garbage Patch384
dependencies, npm, spam
Migrating From Netlify to Cloudflare for AI Bot Protection (sia)383
migrating, netlify, cloudflare, bots, ai
Frontend Security Checklist (tre)382
checklists, react
Automated Ways to Security Audit Your Website381
auditing, automation, tooling
Secure Node.js Applications From Supply Chain Attacks380
nodejs, best-practices, dependencies
The Pitfalls of In-App Browsers (fro)379
browsers, mobile, privacy, user-experience
The Cloud Run Security Gap You Didn’t Know You Had (and How to Fix It)378
gcp
Supply Chain Security in npm—We Can Be Optimistic About the Future377
npm, dependencies, provenance
Script Integrity (chr/fro)376
embed-code, javascript
WebAuthn: Enhancing Security With Minimal Effort (tbe)375
authentication, webauthn
Tuesday, July 2, 2024 Security Releases (nod)374
release-notes, nodejs
Introducing the MDN HTTP Observatory (mdn)373
introductions, mdn, http
RegreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server372
ssh, vulnerabilities
Polyfill Supply Chain Attack Embeds Malware in JavaScript CDN Assets371
malware, vulnerabilities
Catching Compromised Cookies (sla)370
cookies, testing
Backdoor Slipped Into Multiple WordPress Plugins in Ongoing Supply-Chain Attack (dan/ars)369
wordpress, plugins
The Hacking of Culture and the Creation of Socio-Technical Debt (sch)368
culture
Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar/soc)367
npm, dependencies, vulnerabilities, caching
What Is Mixed Content? (fre)366
http
OAuth Authentication (rya)365
authentication, authorization, oauth
The Ultimate Guide to Iframes (log)364
guides, iframes, html, javascript
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem363
javascript, npm, dependencies, caching, vulnerabilities
JavaScript Security: Simple Practices to Secure Your Frontend362
javascript, dependencies, csp
Manifesto for a Humane Web (mic)361
websites, manifestos, web, principles, accessibility, dei, sustainability, user-experience
Securing Client-Side JavaScript360
javascript, graceful-degradation
Poor Express Authentication Patterns in Node.js and How to Avoid Them359
express, nodejs, authentication
Passkeys: A Shattered Dream (fir)358
authentication, passkeys
Using Legitimate GitHub URLs for Malware (sch)357
malware, github
When Security and Accessibility Clash: Why Are Banking Applications So Inaccessible? (nic)356
accessibility
Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects (rgi/ope)355
foss, openjs
Wednesday, April 10, 2024 Security Releases (raf/nod)354
release-notes, nodejs
Node.js Secure Coding: Mitigate and Weaponize Code Injection Vulnerabilities353
books, nodejs, vulnerabilities
The Free Software Commons (jen)352
foss, community
The V8 Sandbox351
v8
Building a Digital Fortress: How to Strengthen DNS Against DDoS Attacks?350
dns
Wednesday, April 3, 2024 Security Releases (nod)349
release-notes, nodejs
Using JSON Web Tokens With Node.js348
json-web-tokens, nodejs, authentication
In-App Browsers Are Still a Privacy, Security, and Choice Problem (tho/the)347
browsers, mobile, privacy
How Does Single Sign-On (SSO) Work? (mil)346
authentication
CORS Finally Explained—Simply345
csrf, cors, concepts
How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth)344
npm, dependencies, examples
Preventing SQL Injection Attacks in Node.js343
nodejs, databases, sql
Frontend Application Security: Tips and Tricks342
web-apps, xss, csrf, authentication, dependencies, csp, validation, tips-and-tricks
Wednesday, February 14, 2024 Security Releases (raf+/nod)341
release-notes, nodejs
How to Boost WordPress Security and Protect Your SEO Ranking340
how-tos, wordpress, seo
Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar/soc)339
npm, dependencies
Practice Safe DSD With “setHTMLUnsafe” (It’s Complicated) (jar/van)338
html, dom, shadow-dom, apis
Tuesday, February 6, 2024 Security Releases (raf/nod)337
release-notes, nodejs
JWT vs. Session Authentication336
authentication, json-web-tokens, comparisons
GitHub, npm Registry Abused to Host SSH Key-Stealing Malware335
github, npm, malware, foss
Navigating JavaScript Security: Recompiling Firefox to Bypass Anti-Debugger Techniques (gli)334
javascript, debugging, firefox, browsers
Deceptive Deprecation: The Truth About npm Deprecated Packages333
deprecation, npm, dependencies, research
Safely Accessing the DOM With Angular SSR332
dom, javascript, angular, server-side-rendering
Node.js Security Progress Report—Progress on Permission Model, Fuzzer, and Connections With Community (ope)331
nodejs
Secure Your Code: Auto-Fix Vulnerabilities With Dependabot (GitHub Tutorial)330
videos, dependencies, dependabot
I Hate CORS329
videos, cors
Building Multiple Progressive Web Apps on the Same Domain328
videos, web-apps, progressive-web-apps, architecture
Session-Based vs. Token-Based Authentication: Which Is Better?327
authentication, json-web-tokens, comparisons
10 Best Practices for Secure Code Review of Node.js Code326
best-practices, code-reviews, nodejs
Security Headers Using “<meta>” (sap/mat)325
csp, html
Blind CSS Exfiltration: Exfiltrate Unknown Web Pages324
css
Mastering Cryptography Fundamentals With Node’s “crypto” Module323
cryptography, nodejs
Secure Code Review Tips to Defend Against Vulnerable Node.js Code322
nodejs, code-reviews
Understanding CORS321
cors
Secret Scanning Scans Public npm Packages320
npm, dependencies
What the !#@% Is a Passkey? (eff)319
passkeys
Local HTTPS for Next.js 13.5 (ami)318
testing, http, nextjs
Understanding XSS Attacks317
xss
A Comprehensive Guide to the Dangers of Regular Expressions in JavaScript (phi)316
guides, javascript, regex
Best Practices for Securing Node.js Applications in Production315
best-practices, nodejs
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble)314
ssh, dependencies, npm
npm Provenance General Availability313
npm, provenance
Open Source Trends to Look for in 2024312
foss, trends, outlooks, ai
The WebP 0-Day311
webp, google, apple
Securing Your Node.js Apps by Analyzing Real-World Command Injection Examples310
nodejs, history, examples
How to Implement SSL/TLS Pinning in Node.js309
how-tos, ssl, tls, nodejs
A More Intelligent and Secure Web (ple/w3c)308
videos, w3c, standards, web, web-platform
Demystifying CORS: Understanding How Cross-Origin Resource Sharing Works307
cors, javascript
Towards HTTPS by Default (jde)306
browsers, chrome, http, tls
Sophisticated, Highly-Targeted Attacks Continue to Plague npm305
npm
An Update on Chrome Security Updates—Shipping Security Fixes to You Faster304
browsers, chrome
SECURITY.md: Should I Have It? (mry/ecl)303
documentation
Tuesday, August 8, 2023 Security Releases (raf/nod)302
release-notes, nodejs
Publishing With npm Provenance From Private Source Repositories Is No Longer Supported301
npm, provenance, foss
Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware (soc)300
malware, npm
Securing the Web Forward: Addressing Developer Concerns in Web Security (tor/w3c)299
web, surveys
Encoding: A Brief History and Its Role in Cybersecurity298
encoding, unicode, history
User Input Sanitization and Validation: Securing Your App297
sanitization, validation, conformance
Node.js Security Progress Report—17 Reports Closed (ope)296
nodejs
The Importance of Verifying Webhook Signatures295
webhooks
The Massive Bug at the Heart of the npm Ecosystem (dar/vlt)294
npm, dependencies, bugs
An Introduction to Command Injection Vulnerabilities in Node.js and JavaScript293
introductions, vulnerabilities, nodejs, javascript
Understanding Authorization Before Authentication: Enhancing Web API Security292
authorization, authentication, apis, comparisons
All You Need to Know About CORS and CORS Errors291
cors, errors
Django: A Security Improvement Coming to “format_html()” (ada)290
django, html
Tuesday, June 20, 2023 Security Releases (raf/nod)289
release-notes, nodejs
security.txt Now Mandatory for Dutch Government Websites288
legal
File Upload Security and Malware Protection (aus)287
malware, file-handling, edge-computing
Security Implications of HTTP Response Headers286
http, http-headers
The Case Against Automatic Dependency Updates (ben)285
dependencies, automation, ci-cd, maintenance
Automating Dependency Updates: The Big Debate284
dependencies, automation, ci-cd
Generating Provenance Statements283
npm, provenance
Introducing npm Package Provenance282
introductions, npm, provenance, foss
8 Best Tools for Cryptography and Encryption (sta)281
link-lists, tooling, comparisons, cryptography, encryption, privacy
Dissecting npm Malware: Five Packages and Their Evil Install Scripts280
npm, malware
Passkeys: What the Heck and Why? (css)279
passkeys
Senior Engineering Strategies for Advanced React and TypeScript (tec)278
strategies, react, typescript, architecture, testing, performance, accessibility, maintenance
Cryptographically Protecting Your SPA277
single-page-apps, cryptography
Tips for Handling Dependabot, CodeQL, and Secret Scanning Alerts276
alerting, dependabot, tips-and-tricks
Without Accessibility, There Is No Privacy or Security (lev)275
accessibility, privacy
How to Password-Protect a Static HTML Page With No JS (ede)274
how-tos, css, fonts
SSL Certificates Explained273
videos, certificates, ssl, protocols
Quick Tip: How to Hash a Password in PHP272
how-tos, php, passwords, tips-and-tricks
Sandboxing JavaScript Code (hea)271
javascript
Avoiding the Success Trap: Toward Policy for Open-Source Software as Infrastructure (atl)270
foss, infrastructure, policies, concepts
Unlocking Security Updates for Transitive Dependencies With npm269
npm, dependencies, maintenance
7 Required Steps to Secure Your Iframes Security268
iframes, xss, html, http-headers, csp
Conditional API Responses for JavaScript vs. HTML Forms (aus)267
javascript, html, forms, comparisons
Why Do We Need Authorization and Authentication?266
authorization, authentication
The Top 10 Security Vulnerabilities for Web Applications265
vulnerabilities, web-apps
Leaked a Secret? Check Your GitHub Alerts… for Free264
github
DOM Clobbering (fre/mat)263
dom
New npm Features for Secure Publishing and Safe Consumption262
npm, dependencies
Using SRI to Protect From Malicious JavaScript (mat)261
javascript
WordPress Versions 3.7–4.0 No Longer Get Security Updates (sar)260
wordpress
“Not Secure” Warning for IE Mode (eri)259
browsers, edge, internet-explorer
Node.js Security Best Practices (nod)258
nodejs, best-practices
npm Security: Preventing Supply Chain Attacks257
npm, dependencies
Secure JavaScript URL Validation256
javascript, validation, urls
Create a Passkey for Passwordless Logins (age)255
authentication, passkeys
Designing a Secure API254
software-design, apis
Phylum Detects Active Typosquatting Campaign Targeting npm Developers253
npm, dependencies
Security (htt)252
web-almanac, studies, research, metrics
Continue Using .env Files as Usual251
environments
Quick Reminder: HTML5 “required” and “pattern” Are Not a Security Feature (cod)250
html, forms
Stop Using .env Files Now249
environments
Debunking Myths About HTTPS248
http, myths
Secure Your Node.js App With JSON Web Tokens (app)247
nodejs, json-web-tokens
Dependabot Unlocks Transitive Dependencies for npm Projects246
dependencies, npm, dependabot
JavaScript Bugs Aplenty in Node.js Ecosystem—Found Automatically245
studies, research, nodejs, javascript, dependencies, quality, bugs
Introducing Even More Security Enhancements to npm244
introductions, npm
Top 5 npm Vulnerability Scanners243
npm, vulnerabilities, tooling
What Is Passwordless Authentication and How to Implement It242
authentication, passwords
GA4 Is Being Blocked by Content Security Policy241
csp, metrics, google
Please Remove That .git Folder240
git
Should I Have Separate GitHub Accounts for Personal and Professional Projects?239
discussions, github, career
Understanding CSRF Attacks (zel)238
csrf
npm Security Update: Attack Campaign Using Stolen OAuth Tokens237
oauth, version-control, npm
Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks236
javascript, npm, dependencies
Unexpectedly HTTPS? (eri)235
http
How to Respond to Growing Supply Chain Security Risks?234
how-tos, dependencies, nodejs, npm
The Web Is for Everyone: Our Vision for the Evolution of the Web (moz)233
web, outlooks, privacy, accessibility, performance, user-experience
Using HTTPS in Your Development Environment232
http, environments
How to Prevent SQL Injection Attacks in Node.js231
how-tos, nodejs, databases, sql
How to Fix Your Security Vulnerabilities With npm Override230
how-tos, vulnerabilities, npm, dependencies
Can You Get Pwned With CSS?229
css
Never, Ever, Ever Use Pixelation for Redacting Text228
content, images, obfuscation
Accessibly Insecure227
accessibility
Lessons Learned From Publishing a Content Security Policy226
lessons, csp
Ain’t No Party Like a Third Party (css)225
dependencies, embed-code
Security (htt)224
web-almanac, studies, research, metrics
GitHub’s Commitment to npm Ecosystem Security223
github, npm
Understanding and Implementing OAuth2 in Node.js (hon)222
nodejs, authorization, oauth
How to Win at CORS (jaf)221
how-tos, cors, html, http
The Options for Password-Revealing Inputs (chr/css)220
html, css, passwords, usability
npm Security Best Practices (owa)219
npm, best-practices
Encoding Data for POST Requests (jaf)218
javascript, encoding
NPM Global Audit217
packages, npm, quality, auditing
Understanding and Preventing Common Security Vulnerabilities216
vulnerabilities
Open Source Insights215
websites, foss, dependencies, licensing
I Learned to Love the Same-Origin Policy (eee/css)214
cors
TLS and mTLS Demystified213
tls, protocols
Is Edge Computing Secure? Here Are 4 Security Risks to Be Aware Of212
edge-computing
Best Practices for Inclusive Textual Websites211
performance, accessibility, best-practices
Clickjacking Attacks and How to Prevent Them210
how-tos
How to Safely Use GitHub Actions in Organizations (nza)209
how-tos, github-actions
What Is mTLS and How Does It Work?208
Mutual TLS: Stuff You Should Know207
tls, protocols
Don’t Try to Sanitize Input—Escape Output206
sanitization, escaping
Encrypting DNS Query Bad for Performance? (erw)205
performance, dns, http, encryption
Apple Joins FIDO Alliance, Commits to Getting Rid of Passwords (sjv/zdn)204
apple, fido, passwords, authentication
How to Automatically Update Your JavaScript Dependencies (spa/clo)203
how-tos, javascript, dependencies, automation, processes
What SSL Is, and Which Certificate Type Is Right for You202
ssl, certificates, privacy, concepts
Usability and Security; Better Together (24w)201
usability, user-experience
Server-Side Includes (SSI) Injection (owa)200
ssi
How Internet Security Works: TLS, SSL, and CA (osd)199
tls, ssl, protocols, certificates
Security and Privacy for Our Times (luk/w3c)198
privacy, web-platform
Web Feature Developers Told to Dial Up Attention on Privacy and Security (rip)197
w3c, privacy, web-platform
CSS Security Vulnerabilities (chr/css)196
css, privacy, vulnerabilities
Understanding Subresource Integrity (dre/sma)195
hashing, embed-code
W3C Strategic Highlights: Web for All (Security, Privacy, Identity) (w3c)194
w3c, privacy, authentication
Guide to Web Authentication193
websites, authentication, webauthn, javascript
It’s Beginning to Look a Lot Like XSSmas (24w)192
vulnerabilities, csrf, xss
Protecting Your Site With Feature Policy (sma)191
http-headers, http
AWS Security Guide: 7 Best Practices to Avoid Security Risks (wom)190
guides, aws, best-practices
WebAuthn, FIDO2 Infuse Browsers, Platforms With Strong Authentication (dar)189
w3c, fido, authentication, webauthn, browsers
In Your Face, Passwords: Big Three Browsers All Adopt Authentication API188
authentication, webauthn, apis, edge, chrome, firefox, browsers
HTTPS Is Easy (tro)187
websites, http
WordPress Security as a Process (sma)186
wordpress, processes
Making Your Website Faster and Safer With Cloudflare185
performance, caching, cloudflare
Validating Dependencies in the Project With npm-check and depcheck184
dependencies, maintenance, auditing, tooling, npm
Third Party CSS Is Not Safe (jaf)183
html, css, embed-code
Attackers Can Steal Sensitive Data by Abusing CSS—CSS Exfil Vulnerability182
css, csp
Building Secure JavaScript Applications181
javascript, xss, csrf, json-web-tokens, passwords
Creating Secure Password Resets With JSON Web Tokens (sma)180
passwords, json-web-tokens, nodejs
The Complete Guide to Switching From HTTP to HTTPS (sma)179
guides, http
Rate Limiting With nginx178
servers, nginx, rate-limiting
How (Not) to Control Your CDN (mno)177
content-delivery, caching, http
How to Secure WordPress With SSL176
how-tos, wordpress, ssl
Encrypting IP Addresses (ber)175
ip, network, privacy, encryption
How to Secure Your Web App With HTTP Headers (sma)174
how-tos, web-apps, http, http-headers, csp
Just Another HTTPS Nudge (chr/css)173
http
On EME in HTML5 (tim/w3c)172
eme, drm, html, legal, standards, w3c
What Is HTTPS and SSL, and Why Your Ecommerce Website Badly Needs Them Both171
http, ssl, ecommerce
Using SSH Securely (ann)170
ssh
More Than 300 Federal Gov Websites Fail to Meet Domain Encryption Deadline169
http, tls, protocols, encryption
Content Security Policy Level 2 (mik+/w3c)168
standards, csp
A Checklist for Website Reviews (hcr)167
checklists, performance, browsers, seo, accessibility
Content Security Policy, Your Future Best Friend (sma)166
csp, link-lists
A Refined Content Security Policy (web)165
html, csp, webkit, safari, browsers
The Performance Benefits of “rel=noopener” (jaf)164
html, links, performance
Web Platform Security Boundaries (ann)163
web-platform
Subresource Integrity (dev+/w3c)162
hashing, html, standards
npm Fails to Restrict the Actions of Malicious npm Packages161
npm, vulnerabilities
W3C Looks to Secure the Web (sdt)160
w3c, authentication
Distribution Packages Considered Insecure159
dependencies, unix-like
The Current State of Web Security (An Interview With Anselm Hannemann) (hel+/css)158
interviews, http, ssl, tls, encryption, cloudflare, lets-encrypt
Eliminating Known Vulnerabilities With Snyk (sma)157
vulnerabilities, tooling
10 Web Predictions for 2016 (cra)156
web, outlooks, site-generators, browsers, css, mobile, performance, webassembly, seo
HSTS and “Let’s Encrypt” (tka)155
http, http-headers, ssl, lets-encrypt
Indexing HTTPS Pages by Default154
google, search, http
An in-Depth Look at CORS153
cors, javascript, php
Why Passwordless Authentication Works (cra)152
authentication, passwords
Introduction to TLS and SSL (ope)151
introductions, tls, ssl, protocols, certificates
A Simple Developer Error Is Exposing Private Information on Thousands of Websites (owe)150
version-control, git, mistakes, vulnerabilities
More Tips to Further Secure WordPress (eli)149
wordpress, tips-and-tricks, plugins
Improving Web Security With the Content Security Policy148
csp, http
Deprecating HTTP147
http, protocols, deprecation
Mozilla Wants to Deprecate Non-Secure HTTP, Will Make Proposals to W3C “Soon” (epr/ven)146
mozilla, http, deprecation
Want Fancy Firefox Features? Secure Your Website (sts/cne)145
firefox, browsers, http
WordPress Front End Security: CSRF and Nonces (css)144
wordpress, csrf
Introduction to WordPress Front End Security: Escaping the Things (css)143
introductions, wordpress, escaping
What Are the Security Risks of HTML5 Apps?142
web-apps, sanitization
Moving to HTTPS on WordPress (chr/css)141
wordpress, http
Same-Origin Policy (ann)140
cors, web-platform
Securing the Web (w3c)139
web-platform
What I’d Tell My Younger Self About Learning Development as a Web Designer138
learning, programming, javascript, databases, servers, preprocessors, version-control, performance, career
HTTPS as a Ranking Signal (met)137
google, search, http, seo
mXSS (gaz)136
xss, html
It’s Time to Encrypt the Entire Internet (kli/wir)135
web, http, ssl, encryption
3 Tips to Find Hacking on Your Site, and Ways to Prevent and Fix It134
search, google, tips-and-tricks
Cross-Origin Resource Sharing (ann/w3c)133
cors, standards
Despite Automatic Updates, Old Browsers Are Still a Problem (edb/zdn)132
browsers, web-platform, chrome, firefox, internet-explorer, safari
Cross-Origin Resource Sharing on Track to Become a W3C Recommendation (sdt)131
w3c, cors, standards
Bid to Kill CAPTCHA Security Test Gains Momentum130
captcha, accessibility
We Should All Have Something to Hide129
privacy
Mobile Website Security128
mobile, hosting, policies
WordPress Security Tips127
wordpress, tips-and-tricks
Brad Hill: “HTML5 Security Realities” (chr/css)126
slides, xss, html
Bulletproof Your Drupal Website125
drupal
Top 10 PHP Security Vulnerabilities124
php, vulnerabilities
A Front End Engineer’s Manifesto (zac)123
websites, manifestos, user-experience, progressive-enhancement, simplicity, foss, accessibility, community, learning
A JavaScript Security Flaw122
javascript
The Secure Programmer’s Pledge121
manifestos
An Introduction to Content Security Policy (mik)120
introductions, csp
Rate Limiting With Apache and mod_security (joh)119
servers, apache, rate-limiting
Cross-Site Scripting Attacks (XSS)118
xss, examples
How to Secure Your WordPress Website (sma)117
how-tos, wordpress, link-lists