Web Security Is Too Hard (eri )Aug 4, 2026 588 cloudflare , case-studies Major Shai Hulud Campaign Strikes npm Again, Affecting keyv and 400+ Packages Aug 4, 2026 587 npm , dependencies Stronger With Every Update: How We’re Making Chrome and the Web Safer in the AI Era Jul 30, 2026 586 chrome , browsers , ai Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks Jul 29, 2026 585 foss , amazon Maciek Palmowski on Testing Secure WordPress Hosting: Does the Marketing Match Reality? (pal +)Jul 29, 2026 584 podcasts , interviews , wordpress , hosting Local-First AI Coding Workflow for Security-Conscious Teams (age )Jul 28, 2026 583 ai , processes Disrupting Supply Chain Attacks on npm and GitHub Actions (gre +)Jul 28, 2026 582 npm , github-actions , link-lists The Secure Way to Release an npm Package in 2026 (sit +/evi )Jul 28, 2026 581 dependencies , npm , configuration npm Publish-Time Malware Scanning and Dual-Use Metadata Jul 28, 2026 580 npm , dependencies Weaponizing and Defending the React Flight Protocol: Deserialization Sinks in RSCs (sma )Jul 21, 2026 579 react , components Monday, July 27, 2026 Security Releases (nod )Jul 21, 2026 578 release-notes , nodejs Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk (lor )Jul 20, 2026 577 wordpress , bugs [Hugging Face] Security Incident Disclosure—July 2026 Jul 16, 2026 576 hugging-face , ai Milan Petrović on the Risks of Legacy PHP in WordPress and Why Upgrading Matters for Security (nat )Jul 15, 2026 575 podcasts , interviews , php , wordpress , maintenance Now, Defenders Are Embracing the Prompt Injection, Too (ars )Jul 13, 2026 574 ai , prompting npm Install-Time Security and GAT bypass2fa Deprecation Jul 8, 2026 573 npm , deprecation You Shouldn’t Trust Trusted Publishing (yos )Jul 7, 2026 572 authentication 6 Security Settings Every GitHub Maintainer Should Enable This Week Jul 1, 2026 571 github , configuration , documentation Shipping Post-Quantum Cryptography to Python (tra )Jun 30, 2026 570 python , cryptography , foss npm Adds Preventive Account Protection for High-Impact Accounts Jun 25, 2026 569 npm Ignore DNSSEC if You Like MITM Attacks Jun 24, 2026 568 dns Anthropic’s Fable and the State of AI (sch )Jun 19, 2026 567 ai , anthropic , foss Blocking Install Scripts Is Not a Silver Bullet (uli /nod )Jun 19, 2026 566 npm Reuse Less Software Jun 11, 2026 565 dependencies , processes Wednesday, June 17, 2026 Security Releases (nod )Jun 9, 2026 564 release-notes , nodejs Upcoming Breaking Changes for npm v12 Jun 9, 2026 563 npm npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders (sar /soc )Jun 9, 2026 562 npm , bugs The Website Specification (joo )May 29, 2026 561 websites , documentation , fundamentals , seo , accessibility , ai-agents , performance , privacy , resilience , internationalization The VibeSec Reckoning (mfo )May 27, 2026 560 ai , vibe-coding Megalodon: Mass GitHub Repo Backdooring via CI Workflows May 21, 2026 559 github , ci-cd GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension (the )May 21, 2026 558 github , vs-code GitHub Hacked—Internal Source Code Repositories Compromised via Employee Device May 20, 2026 557 github Mini Shai Hulud: Compromised @antv npm Packages Enable CI/CD Credential Theft May 20, 2026 556 npm , dependencies , ci-cd Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised May 19, 2026 555 npm , dependencies “The Worst Leak That I’ve Witnessed”: US Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub (giz )May 18, 2026 554 passwords , github A Worm Just Ate Its Way Through the npm Registry… (fir )May 14, 2026 553 videos , npm , dependencies , tanstack Hardening TanStack After the npm Compromise (cru +/tan )May 12, 2026 552 tanstack Hackers Abuse Google Ads and Claude.ai Shared Chats to Distribute macOS Malware May 11, 2026 551 apple , unix-like , google , claude , ai Weekend at Bernie’s (and )May 8, 2026 550 dependencies , foss , metrics Behind the Scenes Hardening Firefox With Claude Mythos Preview (fre +/moz )May 7, 2026 549 firefox , browsers , claude , ai Trustworthy JavaScript for the Open Web (moz )May 5, 2026 548 javascript , open-web , firefox , browsers The Zero-Days Are Numbered (moz )Apr 21, 2026 547 firefox , browsers , ai , anthropic Vercel April 2026 Security Incident Apr 19, 2026 546 vercel AI Will Never Be Ethical or Safe (j9t )Apr 14, 2026 545 ai , ethics No One Owes You Supply-Chain Security (pur )Apr 11, 2026 544 dependencies , rust Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them Apr 9, 2026 543 wordpress , plugins Adversarial AI: Understanding the Threats to Modern AI Systems (jet )Apr 7, 2026 542 ai , concepts Anthropic Debuts Preview of Powerful New AI Model Mythos in New Cybersecurity Initiative Apr 7, 2026 541 anthropic , ai Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign (sar /soc )Apr 3, 2026 540 nodejs , foss Post Mortem: Axios npm Supply Chain Compromise Apr 2, 2026 539 axios , npm The Hidden Blast Radius of the Axios Compromise (ahm /soc )Apr 1, 2026 538 dependencies , npm , axios Minimum Release Age Is an Underrated Supply Chain Defense (dan )Mar 31, 2026 537 dependencies , npm , bun , pnpm , yarn , deno , renovate , dependabot , axios Axios Compromised on npm—Malicious Versions Drop Remote Access Trojan Mar 30, 2026 536 npm , dependencies , axios Prevent Claude Code From Accessing .env (jad )Mar 30, 2026 535 claude , ai , environments Node.js Brotli UAF (mai )Mar 29, 2026 534 nodejs , permissions , brotli , compression , claude , ai Malicious PyPI Package—LiteLLM Supply Chain Compromise Mar 25, 2026 533 dependencies , vulnerabilities Developing a Minimally HashDoS Resistant, Yet Quickly Reversible Integer Hash for V8 (joy /nod )Mar 24, 2026 532 nodejs , hashing Tuesday, March 24, 2026 Security Releases (nod )Mar 17, 2026 531 release-notes , nodejs Supply-Chain Attack Using Invisible Code Hits GitHub and Other Repositories (dan /ars )Mar 13, 2026 530 github , dependencies OWASP’s Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed Mar 7, 2026 529 videos , vulnerabilities , ai , owasp A GitHub Issue Title Compromised 4,000 Developer Machines Mar 5, 2026 528 github , ai How to Steal npm Publish Tokens by Opening GitHub Issues (nec )Mar 4, 2026 527 npm , github , ai MCP Servers and the Return of the Service Account Problem (aem )Mar 2, 2026 526 servers , mcp , ai Security Advisory: Addressing Recent Vulnerabilities in Angular (ang )Feb 27, 2026 525 angular An Exploit… in CSS?! (css )Feb 25, 2026 524 css Goodbye “innerHTML”, Hello “setHTML”: Stronger XSS Protection in Firefox 148 (moz )Feb 24, 2026 523 javascript , methods , xss , firefox , browsers Europe Is Ready to Ditch US Tech for Private Alternatives (pro )Feb 17, 2026 522 tooling , privacy , metrics WebSocket Penetration Testing: A Complete Guide to CSWSH Feb 9, 2026 521 guides , websockets , testing Node.js Path Traversal: Prevention and Security Guide (loi )Feb 2, 2026 520 guides , nodejs Cryptography Usage in Web Standards (w3c )Jan 29, 2026 519 standards , cryptography OpenJS Foundation Security Program: Annual Report 2025 (ope )Jan 29, 2026 518 openjs A Security Checklist for Your React and Next.js Apps Jan 26, 2026 517 react , nextjs How to Implement Rate Limiting in nginx (naw /one )Jan 25, 2026 516 how-tos , servers , nginx , rate-limiting Securing npm Is Table Stakes (nza +/cha )Jan 21, 2026 515 podcasts , interviews , npm , ai Security (vik +/htt )Jan 16, 2026 514 web-almanac , studies , research , metrics , tls , certificates , cookies , csp , http-headers , apis , sanitization , configuration Node.js January 2026 Security Release: What Changed and Why It Matters (nod )Jan 14, 2026 513 nodejs Tuesday, January 13, 2026 Security Releases (nod )Jan 13, 2026 512 release-notes , nodejs Mitigating Denial-of-Service Vulnerability From Unrecoverable Stack Space Exhaustion for React, Next.js, and APM Users (mco +/nod )Jan 13, 2026 511 nodejs , vulnerabilities , react , nextjs , tooling , monitoring , performance npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens (sar /soc )Jan 7, 2026 510 npm , dependencies Security Basics for Vibe-Coders (owe /pro )Jan 2, 2026 509 fundamentals , vibe-coding , ai Testing Methods: Accessible Authentication (Enhanced) (dec )Dec 29, 2025 508 accessibility , testing , wcag , authentication Testing Methods: Accessible Authentication (Minimum) (dec )Dec 28, 2025 507 accessibility , testing , wcag , authentication Denial of Service and Source Code Exposure in React Server Components (rea )Dec 11, 2025 506 react , components Thursday, December 18, 2025 Security Releases (nod )Dec 8, 2025 505 release-notes , nodejs How We’re Protecting Our Newsroom From npm Supply Chain Attacks (rya /pnp )Dec 5, 2025 504 npm , dependencies , case-studies No More Tokens—Locking Down npm Publish Workflows (zac )Dec 4, 2025 503 npm , dependencies , processes [Next.js] Security Advisory: CVE-2025-66478 (seb )Dec 3, 2025 502 nextjs Critical Security Vulnerability in React Server Components (rea )Dec 3, 2025 501 react , components Decreasing [Let’s Encrypt] Certificate Lifetimes to 45 Days (mat /let )Dec 2, 2025 500 http , certificates , lets-encrypt Taking Down Next.js Servers for 0.0001 Cents a Pop Nov 26, 2025 499 servers , nextjs , vulnerabilities The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know Nov 25, 2025 498 npm , dependencies GitLab Discovers Widespread npm Supply Chain Attack Nov 24, 2025 497 npm , dependencies , gitlab , aws , gcp , azure Automated npm Secret Rotation in GitHub Actions (mhe )Nov 16, 2025 496 npm , automation , github-actions What Developers Really Mean by “Bad Code” (jet )Nov 12, 2025 495 maintainability , scalability , consistency , quality Introducing the OWASP Top 10:2025 (she +/owa )Nov 5, 2025 494 introductions , owasp , vulnerabilities Removing XSLT for a More Secure Browser (dro )Oct 29, 2025 493 chromium , chrome , browsers , xsl , web-platform Agentic AI and Security (ksi /mfo )Oct 28, 2025 492 ai , architecture Octoverse: A New Developer Joins GitHub Every Second as AI Leads TypeScript to #1 Oct 28, 2025 491 github , metrics , productivity , ai , foss , programming HTTPS by Default (jde +)Oct 28, 2025 490 http , chrome , browsers Will npm’s New Security Steps Stop Attacks? (rev )Oct 28, 2025 489 npm , maintenance , foss Glassworm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace Oct 18, 2025 488 code-editors , vs-code Improving the Trustworthiness of JavaScript on the Web Oct 16, 2025 487 javascript , web-apps Past Time for Passkeys (nor )Oct 15, 2025 486 videos , passkeys , passwords , authentication Secure Coding in JavaScript Oct 15, 2025 485 javascript , frameworks My Conclusions After Using Signed Exchanges on My Website for 2 Years (paw )Oct 9, 2025 484 signed-exchanges , performance Lazy-Loading as a Security Measure Oct 6, 2025 483 lazy-loading , angular , react Backend Concepts Every Experienced Developers Must Know Oct 4, 2025 482 concepts , network , concurrency , apis , databases , caching , scalability , observability , architecture Fixing Safari Mixed Content Issues With Vite and mkcert Oct 3, 2025 481 safari , browsers , vite , tooling How Deno Protects Against npm Exploits (den )Sep 30, 2025 480 deno , npm Strengthening npm Security: Important Changes to Authentication and Token Management Sep 29, 2025 479 npm How Hackers Use AI to Find Vulnerabilities Faster Sep 25, 2025 478 ai CAPTCHA, When Security Takes Precedence Over Accessibility Sep 22, 2025 477 captcha , accessibility Our Plan for a More Secure npm Supply Chain (xco )Sep 22, 2025 476 npm , dependencies , foss npm Security Best Practices Sep 21, 2025 475 npm , provenance , best-practices This May Be the Worst One (the )Sep 17, 2025 474 videos , npm , dependencies Ongoing Supply Chain Attack Targets CrowdStrike npm Packages (pvd +/soc )Sep 16, 2025 473 npm , dependencies ctrl/tinycolor and 40+ npm Packages Compromised Sep 15, 2025 472 npm , dependencies How Maintainer Burnout Is Causing a Kubernetes Security Disaster Sep 11, 2025 471 kubernetes , maintenance , foss , economics Oh No, Not Again… a Meditation on npm Supply Chain Attacks (tan )Sep 9, 2025 470 npm , dependencies , microsoft Anatomy of a Billion-Download npm Supply-Chain Attack Sep 8, 2025 469 npm , dependencies npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack (bur +/soc )Sep 8, 2025 468 npm , dependencies CORS Explained: Stop Struggling With Cross-Origin Errors Sep 3, 2025 467 cors , http-headers , http How OpenJS-Hosted Projects Benefit From Security Support (ope )Sep 2, 2025 466 openjs , hosting , foss Why You Absolutely Need to Have Automated Dependency Management in Place (j9t )Aug 28, 2025 465 dependencies , maintainability , maintenance , automation , tooling What Your Website’s Style Says About You—and How Hackers Can Use It Against You (err )Aug 1, 2025 464 css , javascript Hardening Node.js Apps in Production: 8 Layers of Practical Security Jul 29, 2025 463 nodejs , best-practices eslint-config-prettier Compromised: How npm Package With 30 Million Downloads Spread Malware Jul 21, 2025 462 prettier , eslint , npm , malware npm Phishing Email Targets Developers With Typosquatted Domain (sar /soc )Jul 18, 2025 461 npm AI Agents Are Creating a New Security Nightmare for Enterprises and Startups Jul 18, 2025 460 ai , apis Tuesday, July 15, 2025 Security Releases (nod )Jul 15, 2025 459 release-notes , nodejs Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc )Jul 14, 2025 458 npm , dependencies Dependabot Supports Configuration of a Minimum Package Age Jul 1, 2025 457 dependabot , configuration MCP Security Vulnerabilities and Attack Vectors Jun 27, 2025 456 mcp , ai A New Era of Code Quality Jun 24, 2025 455 quality JWTs Are Not Session Tokens, Stop Using Them Like One Jun 21, 2025 454 json-web-tokens , authentication Design Patterns for Securing LLM Agents Against Prompt Injections (sim )Jun 13, 2025 453 studies , research , ai , prompting , software-design-patterns The Growing Risk of Malicious Browser Extensions (soc )Jun 13, 2025 452 browser-extensions HTML Spec Change: Escaping “<” and “>” in Attributes (sec )Jun 12, 2025 451 html , attributes , escaping , xss Escaping “<” and “>” in Attributes—How It Helps Protect Against Mutation XSS (sec )Jun 12, 2025 450 html , attributes , xss , escaping , chrome , browsers Beware of End-of-Life Node.js Versions—Upgrade or Seek Post-EOL Support (mco /nod )Jun 6, 2025 449 nodejs , maintenance How to Access Local MCP Servers Through a Secure Tunnel Jun 5, 2025 448 how-tos , mcp , ai , servers , network Docker Launches Hardened Images, Intensifying Secure Container Market May 19, 2025 447 docker Modernizing Security May 17, 2025 446 modernization , processes Securing Your Node.js App From Command Injection May 14, 2025 445 nodejs Passkeys for Normal People (tro )May 5, 2025 444 authentication , passkeys , examples , concepts npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc )May 2, 2025 443 npm , malware , dependencies , link-lists What Is an Encryption Backdoor? (int )May 2, 2025 442 encryption , vulnerabilities , concepts Cybersecurity Leaders Are Staying in the Shadows (ste )Apr 26, 2025 441 community , culture Principles for Coding Securely With LLMs (sea )Apr 15, 2025 440 ai , principles Threat Actors Misuse Node.js to Deliver Malware and Other Malicious Payloads Apr 15, 2025 439 nodejs , malware TLS Certificate Lifetimes Will Officially Reduce to 47 Days Apr 14, 2025 438 tls , certificates LLMs Can’t Stop Making Up Software Dependencies and Sabotaging Everything (tho /the )Apr 12, 2025 437 ai , dependencies , slop Secure a Vue App With OpenID Connect and the BFF Pattern (due )Apr 9, 2025 436 vuejs , authentication , backend-for-frontend Teaching Code in the AI Era: Why Fundamentals Still Matter (ali )Apr 4, 2025 435 training , ai , programming , vibe-coding , scalability , performance , quality , testing , documentation Stop Using Jenkins in 2025 (oso )Apr 1, 2025 434 jenkins , github-actions , ci-cd Node.js Test CI Security Incident (nod )Mar 31, 2025 433 nodejs , retrospectives Website Hijack Campaign Now Impacting 150,000 Sites (gad )Mar 27, 2025 432 Malware Found on npm Infecting Local Package With Reverse Shell (rev )Mar 26, 2025 431 npm , dependencies Five Things Vibe Coders Should Know (From a Software Engineer) Mar 20, 2025 430 vibe-coding , sanitization , rate-limiting GitHub Suffers a Cascading Supply Chain Attack Compromising CI/CD Secrets (inf )Mar 19, 2025 429 github , ci-cd How to Prevent WordPress SQL Injection Attacks (sma )Mar 13, 2025 428 how-tos , wordpress , sql , databases Lazarus Strikes npm Again With New Wave of Malicious Packages (soc )Mar 10, 2025 427 npm , dependencies Updates on CVE for End-of-Life Versions (raf /nod )Mar 7, 2025 426 nodejs What Is the OWASP Top 10 and How Can Your Team Benchmark Security? (jet )Mar 7, 2025 425 owasp , vulnerabilities , qodana How to Protect Your Web Applications From XSS (tor /w3c )Mar 6, 2025 424 how-tos , web-apps , xss In Tech, What Matters and What Is Dangerous (ham )Mar 6, 2025 423 community , foss , open-web Secure UX: Building Cybersecurity and Privacy Into the UX Lifecycle (uxm )Mar 3, 2025 422 user-experience , processes The Fallacy of Balance: Challenging the Notion of Security and Accessibility as Opposing Objectives (deq )Feb 26, 2025 421 videos , accessibility It Is No Longer Safe to Move Our Governments and Societies to US Clouds (ber )Feb 23, 2025 420 cloud-computing , privacy , legal How OWASP Helps You Secure Your Full-Stack Web Applications (eri /sma )Feb 18, 2025 419 owasp , monitoring , authentication , vulnerabilities , configuration , csrf , cryptography , authorization 10 Common Web Development Mistakes to Avoid Right Now Feb 17, 2025 418 mistakes , mobile , performance , accessibility , seo , navigation , analytics , testing Tightening Every Bolt (bag )Feb 8, 2025 417 videos , processes , code-reviews , testing On Generative AI Security (sch )Feb 5, 2025 416 ai , lessons , microsoft Understanding CORS Errors in Signed Exchanges (paw )Jan 31, 2025 415 cors , errors , signed-exchanges Keep Your Node.js Apps Secure With “npx is-my-node-vulnerable” (tre )Jan 29, 2025 414 packages , npm , nodejs How I Open-Sourced My Secret Access Tokens From GitHub, Slack, and npm—and Who Actually Cares Jan 24, 2025 413 github , slack , npm Node.js EOL Versions CVE Dubbed the “Worst CVE of the Year” by Security Experts (sar /soc )Jan 24, 2025 412 nodejs , documentation Tuesday, January 21, 2025 Security Releases (raf /nod )Jan 21, 2025 411 release-notes , nodejs APIs Are Quickly Becoming the Latest Security Battleground (and Nightmare) Jan 14, 2025 410 apis CDN-First Is No Longer a Performance Feature (osv )Jan 12, 2025 409 content-delivery , performance , caching , embed-code , privacy The Cyber-Cleanse: Take Back Your Digital Footprint (cyb )Jan 1, 2025 408 privacy 15 Principles for Secure Programming (rak )Dec 23, 2024 407 principles , validation , testing Important Topics for Frontend Developers to Master in 2025 Dec 21, 2024 406 learning , javascript , typescript , css , frameworks , git , apis , testing , performance , ci-cd , websockets How to Automate OWASP Security Reviews in Your Pull Requests? (cod )Dec 16, 2024 405 how-tos , owasp , automation , code-reviews , coderabbit Developer Guide: How to Implement Passkeys Dec 16, 2024 404 guides , how-tos , authentication , passkeys 5 Technical Trends to Help Web Developers Stand Out in 2025 Dec 10, 2024 403 trends , career , javascript , ai , low-and-no-code Avoid Hotlinking Images With “Cross-Origin-Resource-Policy” Nov 27, 2024 402 images Content Security Policy Level 3 (mik /w3c )Nov 22, 2024 401 standards , csp Security (vik /htt )Nov 11, 2024 400 web-almanac , studies , research , metrics JavaScript Import Attributes (ES2025) (tre )Nov 10, 2024 399 javascript Exploring Internet Traffic Shifts and Cyber Attacks During the 2024 US Election Nov 6, 2024 398 traffic Cross-Site WebSocket Hijacking: Understanding and Exploiting CSWSH (pen )Nov 5, 2024 397 websockets Securing Your Express REST API With Passport.js Nov 3, 2024 396 nodejs , express , json-web-tokens , apis , rest , tooling SecretLint—a Linter for Preventing Committing Credentials (tre )Oct 22, 2024 395 tooling , linting The Importance of UX in Cybersecurity (uxm )Oct 21, 2024 394 user-experience , usability Understanding “npm audit” and Fixing Vulnerabilities Oct 21, 2024 393 npm , vulnerabilities , nodejs Top 4 Web Vulnerabilities With Example and Mitigation Oct 21, 2024 392 vulnerabilities , sql , databases , xss , csrf How to Implement Content Security Policy (CSP) Headers for Astro (tre )Oct 16, 2024 391 how-tos , http , http-headers , csp , astro , vercel , cloudflare Why Code Security Matters—Even in Hardened Environments Oct 8, 2024 390 vulnerabilities , file-handling , nodejs Database 101: SSL/TLS for Beginners Oct 4, 2024 389 introductions , databases , ssl , tls , authentication Cloudflare Study: 39% of Companies Losing Control of Their IT and Security Environment (tre )Oct 3, 2024 388 studies , research , engineering-management NIST Recommends Some Common-Sense Password Rules (sch )Sep 27, 2024 387 passwords , guidelines I Finally Understand OAuth Sep 24, 2024 386 authorization , oauth , processes Fake GitHub Site Targeting Developers (jul /san )Sep 19, 2024 385 github Hacking Cars in JavaScript (Running Replay Attacks in the Browser With the HackRF) (dev )Sep 16, 2024 384 javascript Gaining Access to Anyone’s Browser Without Them Even Visiting a Website Sep 7, 2024 383 arc , browsers , vulnerabilities 10 AI Dangers and Risks and How to Manage Them (rin )Sep 3, 2024 382 ai , privacy , sustainability , legal Web Security: Shaping the Secure Web (set /w3c )Aug 21, 2024 381 web , w3c 5 Wasm Use Cases for Frontend Development (ele /des )Aug 21, 2024 380 guest-posts , webassembly , performance What Is Incident Response? Aug 20, 2024 379 incident-response , overviews The Great npm Garbage Patch Aug 6, 2024 378 dependencies , npm , spam Migrating From Netlify to Cloudflare for AI Bot Protection (sia )Aug 6, 2024 377 migrating , netlify , cloudflare , bots , ai Frontend Security Checklist (tre )Jul 30, 2024 376 checklists , react Automated Ways to Security Audit Your Website Jul 28, 2024 375 auditing , automation , tooling Secure Node.js Applications From Supply Chain Attacks Jul 25, 2024 374 nodejs , best-practices , dependencies The Pitfalls of In-App Browsers (fro )Jul 18, 2024 373 browsers , mobile , privacy , user-experience The Cloud Run Security Gap You Didn’t Know You Had (and How to Fix It) Jul 18, 2024 372 gcp Supply Chain Security in npm—We Can Be Optimistic About the Future Jul 9, 2024 371 npm , dependencies , provenance Script Integrity (chr /fro )Jul 5, 2024 370 embed-code , javascript Tuesday, July 2, 2024 Security Releases (nod )Jul 2, 2024 369 release-notes , nodejs Introducing the MDN HTTP Observatory (mdn )Jul 2, 2024 368 introductions , mdn , http WebAuthn: Enhancing Security With Minimal Effort (tbe )Jul 2, 2024 367 authentication , webauthn RegreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server Jul 1, 2024 366 ssh , vulnerabilities Polyfill Supply Chain Attack Embeds Malware in JavaScript CDN Assets Jun 26, 2024 365 malware , vulnerabilities Catching Compromised Cookies (sla )Jun 25, 2024 364 cookies , testing Backdoor Slipped Into Multiple WordPress Plugins in Ongoing Supply-Chain Attack (dan /ars )Jun 24, 2024 363 wordpress , plugins The Hacking of Culture and the Creation of Socio-Technical Debt (sch )Jun 19, 2024 362 culture Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar /soc )Jun 15, 2024 361 npm , dependencies , vulnerabilities , caching What Is Mixed Content? (fre )Jun 15, 2024 360 http OAuth Authentication (rya )Jun 15, 2024 359 authentication , authorization , oauth The Ultimate Guide to Iframes (log )Jun 6, 2024 358 guides , iframes , html , javascript How a Single Vulnerability Can Bring Down the JavaScript Ecosystem Jun 3, 2024 357 javascript , npm , dependencies , caching , vulnerabilities JavaScript Security: Simple Practices to Secure Your Frontend May 15, 2024 356 javascript , dependencies , csp Manifesto for a Humane Web (mic )May 10, 2024 355 websites , manifestos , web , principles , accessibility , dei , sustainability , user-experience Securing Client-Side JavaScript (ada )May 5, 2024 354 javascript , graceful-degradation Poor Express Authentication Patterns in Node.js and How to Avoid Them May 3, 2024 353 express , nodejs , authentication Passkeys: A Shattered Dream (fir )Apr 26, 2024 352 authentication , passkeys Using Legitimate GitHub URLs for Malware (sch )Apr 22, 2024 351 malware , github When Security and Accessibility Clash: Why Are Banking Applications So Inaccessible? (nic )Apr 17, 2024 350 accessibility Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects (rgi /ope )Apr 15, 2024 349 foss , openjs Wednesday, April 10, 2024 Security Releases (raf /nod )Apr 10, 2024 348 release-notes , nodejs Node.js Secure Coding: Mitigate and Weaponize Code Injection Vulnerabilities Apr 8, 2024 347 books , nodejs , vulnerabilities The Free Software Commons (jen )Apr 5, 2024 346 foss , community The V8 Sandbox Apr 4, 2024 345 v8 Wednesday, April 3, 2024 Security Releases (nod )Apr 3, 2024 344 release-notes , nodejs Using JSON Web Tokens With Node.js Apr 3, 2024 343 json-web-tokens , nodejs , authentication Building a Digital Fortress: How to Strengthen DNS Against DDoS Attacks? Apr 3, 2024 342 dns In-App Browsers Are Still a Privacy, Security, and Choice Problem (tho /the )Mar 27, 2024 341 browsers , mobile , privacy How Does Single Sign-On (SSO) Work? (mil )Mar 24, 2024 340 authentication CORS Finally Explained—Simply Mar 24, 2024 339 csrf , cors , concepts How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth )Mar 3, 2024 338 npm , dependencies , examples Preventing SQL Injection Attacks in Node.js Feb 20, 2024 337 nodejs , databases , sql Frontend Application Security: Tips and Tricks Feb 16, 2024 336 web-apps , xss , csrf , authentication , dependencies , csp , validation , tips-and-tricks Wednesday, February 14, 2024 Security Releases (raf +/nod )Feb 14, 2024 335 release-notes , nodejs How to Boost WordPress Security and Protect Your SEO Ranking Feb 12, 2024 334 how-tos , wordpress , seo Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar /soc )Feb 6, 2024 333 npm , dependencies Practice Safe DSD With “setHTMLUnsafe” (It’s Complicated) (jar /van )Jan 31, 2024 332 html , dom , shadow-dom , apis Tuesday, February 6, 2024 Security Releases (raf /nod )Jan 30, 2024 331 release-notes , nodejs JWT vs. Session Authentication Jan 25, 2024 330 authentication , json-web-tokens , comparisons GitHub, npm Registry Abused to Host SSH Key-Stealing Malware Jan 24, 2024 329 github , npm , malware , foss Navigating JavaScript Security: Recompiling Firefox to Bypass Anti-Debugger Techniques (gli )Jan 20, 2024 328 javascript , debugging , firefox , browsers Deceptive Deprecation: The Truth About npm Deprecated Packages Jan 18, 2024 327 deprecation , npm , dependencies , research Safely Accessing the DOM With Angular SSR Jan 17, 2024 326 dom , javascript , angular , server-side-rendering Node.js Security Progress Report—Progress on Permission Model, Fuzzer, and Connections With Community (ope )Jan 16, 2024 325 nodejs Secure Your Code: Auto-Fix Vulnerabilities With Dependabot (GitHub Tutorial) Jan 14, 2024 324 videos , dependencies , dependabot I Hate CORS Jan 14, 2024 323 videos , cors Building Multiple Progressive Web Apps on the Same Domain Jan 4, 2024 322 videos , web-apps , progressive-web-apps , architecture Session-Based vs. Token-Based Authentication: Which Is Better? Dec 23, 2023 321 authentication , json-web-tokens , comparisons 10 Best Practices for Secure Code Review of Node.js Code Dec 20, 2023 320 best-practices , code-reviews , nodejs Security Headers Using “<meta>” (sap /mat )Dec 7, 2023 319 csp , html Blind CSS Exfiltration: Exfiltrate Unknown Web Pages Dec 5, 2023 318 css Mastering Cryptography Fundamentals With Node’s “crypto” Module Nov 11, 2023 317 cryptography , nodejs Secure Code Review Tips to Defend Against Vulnerable Node.js Code Nov 8, 2023 316 nodejs , code-reviews Understanding CORS Nov 4, 2023 315 cors What the !#@% Is a Passkey? (eff )Oct 26, 2023 314 passkeys Secret Scanning Scans Public npm Packages Oct 26, 2023 313 npm , dependencies Local HTTPS for Next.js 13.5 (ami )Oct 10, 2023 312 testing , http , nextjs Understanding XSS Attacks Oct 5, 2023 311 xss A Comprehensive Guide to the Dangers of Regular Expressions in JavaScript (phi )Sep 28, 2023 310 guides , javascript , regex SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble )Sep 27, 2023 309 ssh , dependencies , npm Best Practices for Securing Node.js Applications in Production Sep 27, 2023 308 best-practices , nodejs npm Provenance General Availability Sep 26, 2023 307 npm , provenance The WebP 0-Day Sep 21, 2023 306 webp , google , apple Open Source Trends to Look for in 2024 Sep 21, 2023 305 foss , trends , outlooks , ai Securing Your Node.js Apps by Analyzing Real-World Command Injection Examples Sep 15, 2023 304 nodejs , history , examples How to Implement SSL/TLS Pinning in Node.js Aug 29, 2023 303 how-tos , ssl , tls , nodejs A More Intelligent and Secure Web (ple /w3c )Aug 24, 2023 302 videos , w3c , standards , web , web-platform Demystifying CORS: Understanding How Cross-Origin Resource Sharing Works Aug 18, 2023 301 cors , javascript Towards HTTPS by Default (jde )Aug 16, 2023 300 browsers , chrome , http , tls Sophisticated, Highly-Targeted Attacks Continue to Plague npm Aug 12, 2023 299 npm An Update on Chrome Security Updates—Shipping Security Fixes to You Faster Aug 8, 2023 298 browsers , chrome Tuesday, August 8, 2023 Security Releases (raf /nod )Jul 31, 2023 297 release-notes , nodejs SECURITY.md: Should I Have It? (mry /ecl )Jul 31, 2023 296 documentation Publishing With npm Provenance From Private Source Repositories Is No Longer Supported Jul 26, 2023 295 npm , provenance , foss Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware (soc )Jul 25, 2023 294 malware , npm Securing the Web Forward: Addressing Developer Concerns in Web Security (tor /w3c )Jul 24, 2023 293 web , surveys User Input Sanitization and Validation: Securing Your App Jul 19, 2023 292 sanitization , validation , conformance Encoding: A Brief History and Its Role in Cybersecurity Jul 19, 2023 291 encoding , unicode , history Node.js Security Progress Report—17 Reports Closed (ope )Jul 17, 2023 290 nodejs The Importance of Verifying Webhook Signatures Jun 29, 2023 289 webhooks The Massive Bug at the Heart of the npm Ecosystem (dar /vlt )Jun 27, 2023 288 npm , dependencies , bugs An Introduction to Command Injection Vulnerabilities in Node.js and JavaScript Jun 23, 2023 287 introductions , vulnerabilities , nodejs , javascript All You Need to Know About CORS and CORS Errors Jun 23, 2023 286 cors , errors Understanding Authorization Before Authentication: Enhancing Web API Security Jun 23, 2023 285 authorization , authentication , apis , comparisons Django: A Security Improvement Coming to “format_html()” (ada )Jun 15, 2023 284 django , html Tuesday, June 20, 2023 Security Releases (raf /nod )Jun 13, 2023 283 release-notes , nodejs security.txt Now Mandatory for Dutch Government Websites May 31, 2023 282 legal File Upload Security and Malware Protection (aus )May 23, 2023 281 malware , file-handling , edge-computing Security Implications of HTTP Response Headers May 3, 2023 280 http , http-headers The Case Against Automatic Dependency Updates (ben )Apr 21, 2023 279 dependencies , automation , ci-cd , maintenance Automating Dependency Updates: The Big Debate Apr 21, 2023 278 dependencies , automation , ci-cd Generating Provenance Statements Apr 19, 2023 277 npm , provenance Introducing npm Package Provenance Apr 19, 2023 276 introductions , npm , provenance , foss 8 Best Tools for Cryptography and Encryption (sta )Apr 18, 2023 275 link-lists , tooling , comparisons , cryptography , encryption , privacy Dissecting npm Malware: Five Packages and Their Evil Install Scripts Apr 15, 2023 274 npm , malware Passkeys: What the Heck and Why? (css )Apr 12, 2023 273 passkeys Senior Engineering Strategies for Advanced React and TypeScript (tec )Mar 25, 2023 272 strategies , react , typescript , architecture , testing , performance , accessibility , maintenance Cryptographically Protecting Your SPA Mar 17, 2023 271 single-page-apps , cryptography Tips for Handling Dependabot, CodeQL, and Secret Scanning Alerts Feb 28, 2023 270 alerting , dependabot , tips-and-tricks Without Accessibility, There Is No Privacy or Security (lev )Feb 28, 2023 269 accessibility , privacy How to Password-Protect a Static HTML Page With No JS (ede )Feb 20, 2023 268 how-tos , css , fonts SSL Certificates Explained Feb 20, 2023 267 videos , certificates , ssl , protocols Quick Tip: How to Hash a Password in PHP Feb 14, 2023 266 how-tos , php , passwords , tips-and-tricks Sandboxing JavaScript Code Feb 12, 2023 265 javascript Avoiding the Success Trap: Toward Policy for Open-Source Software as Infrastructure (atl )Feb 8, 2023 264 foss , infrastructure , policies , concepts Unlocking Security Updates for Transitive Dependencies With npm Jan 19, 2023 263 npm , dependencies , maintenance 7 Required Steps to Secure Your Iframes Security Jan 4, 2023 262 iframes , xss , html , http-headers , csp Conditional API Responses for JavaScript vs. HTML Forms (aus )Jan 3, 2023 261 javascript , html , forms , comparisons Why Do We Need Authorization and Authentication? Dec 30, 2022 260 authorization , authentication The Top 10 Security Vulnerabilities for Web Applications Dec 20, 2022 259 vulnerabilities , web-apps Leaked a Secret? Check Your GitHub Alerts… for Free Dec 15, 2022 258 github DOM Clobbering (fre /mat )Dec 12, 2022 257 dom New npm Features for Secure Publishing and Safe Consumption Dec 6, 2022 256 npm , dependencies Using SRI to Protect From Malicious JavaScript (mat )Dec 3, 2022 255 javascript WordPress Versions 3.7–4.0 No Longer Get Security Updates (sar )Nov 30, 2022 254 wordpress “Not Secure” Warning for IE Mode Nov 16, 2022 253 browsers , edge , internet-explorer Node.js Security Best Practices (nod )Nov 10, 2022 252 nodejs , best-practices npm Security: Preventing Supply Chain Attacks Nov 7, 2022 251 npm , dependencies Secure JavaScript URL Validation Oct 17, 2022 250 javascript , validation , urls Create a Passkey for Passwordless Logins (age )Oct 12, 2022 249 authentication , passkeys Designing a Secure API Oct 4, 2022 248 software-design , apis Phylum Detects Active Typosquatting Campaign Targeting npm Developers Oct 2, 2022 247 npm , dependencies Security (htt )Sep 26, 2022 246 web-almanac , studies , research , metrics Continue Using .env Files as Usual Sep 24, 2022 245 environments Quick Reminder: HTML5 “required” and “pattern” Are Not a Security Feature (cod )Sep 22, 2022 244 html , forms Stop Using .env Files Now Sep 19, 2022 243 environments Debunking Myths About HTTPS Sep 18, 2022 242 http , myths Secure Your Node.js App With JSON Web Tokens (app )Sep 14, 2022 241 nodejs , json-web-tokens Dependabot Unlocks Transitive Dependencies for npm Projects Sep 7, 2022 240 dependencies , npm , dependabot JavaScript Bugs Aplenty in Node.js Ecosystem—Found Automatically Aug 30, 2022 239 studies , research , nodejs , javascript , dependencies , quality , bugs Introducing Even More Security Enhancements to npm Jul 26, 2022 238 introductions , npm Top 5 npm Vulnerability Scanners Jul 20, 2022 237 npm , vulnerabilities , tooling What Is Passwordless Authentication and How to Implement It Jul 18, 2022 236 authentication , passwords GA4 Is Being Blocked by Content Security Policy Jun 25, 2022 235 csp , metrics , google Please Remove That .git Folder Jun 22, 2022 234 git Should I Have Separate GitHub Accounts for Personal and Professional Projects? Jun 14, 2022 233 discussions , github , career Understanding CSRF Attacks (zel )May 29, 2022 232 csrf npm Security Update: Attack Campaign Using Stolen OAuth Tokens May 26, 2022 231 oauth , version-control , npm Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks May 24, 2022 230 javascript , npm , dependencies Unexpectedly HTTPS? May 16, 2022 229 http How to Respond to Growing Supply Chain Security Risks? Apr 3, 2022 228 how-tos , dependencies , nodejs , npm The Web Is for Everyone: Our Vision for the Evolution of the Web (moz )Mar 23, 2022 227 web , outlooks , privacy , accessibility , performance , user-experience Using HTTPS in Your Development Environment Mar 7, 2022 226 http , environments How to Prevent SQL Injection Attacks in Node.js Mar 3, 2022 225 how-tos , nodejs , databases , sql How to Fix Your Security Vulnerabilities With npm Override Feb 23, 2022 224 how-tos , vulnerabilities , npm , dependencies Can You Get Pwned With CSS? Feb 23, 2022 223 css Never, Ever, Ever Use Pixelation for Redacting Text Feb 15, 2022 222 content , images , obfuscation Accessibly Insecure Jan 31, 2022 221 accessibility Lessons Learned From Publishing a Content Security Policy Dec 14, 2021 220 lessons , csp Ain’t No Party Like a Third Party (ada /css )Dec 3, 2021 219 dependencies , embed-code Security (htt )Dec 1, 2021 218 web-almanac , studies , research , metrics GitHub’s Commitment to npm Ecosystem Security Nov 15, 2021 217 github , npm Understanding and Implementing OAuth2 in Node.js (hon )Oct 18, 2021 216 nodejs , authorization , oauth How to Win at CORS (jaf )Oct 12, 2021 215 how-tos , cors , html , http The Options for Password-Revealing Inputs (chr /css )Oct 6, 2021 214 html , css , passwords , usability npm Security Best Practices (owa )Aug 3, 2021 213 npm , best-practices Encoding Data for POST Requests (jaf )Jun 30, 2021 212 javascript , encoding NPM Global Audit Jun 16, 2021 211 packages , npm , quality , auditing Understanding and Preventing Common Security Vulnerabilities Jun 15, 2021 210 vulnerabilities Open Source Insights Jun 3, 2021 209 websites , foss , dependencies , licensing I Learned to Love the Same-Origin Policy (eee /css )Dec 17, 2020 208 cors TLS and mTLS Demystified Dec 9, 2020 207 tls , protocols Is Edge Computing Secure? Here Are 4 Security Risks to Be Aware Of Dec 9, 2020 206 edge-computing Best Practices for Inclusive Textual Websites Nov 23, 2020 205 performance , accessibility , best-practices Clickjacking Attacks and How to Prevent Them Oct 30, 2020 204 how-tos How to Safely Use GitHub Actions in Organizations (nza )Jul 21, 2020 203 how-tos , github-actions What Is mTLS and How Does It Work? Apr 30, 2020 202 Mutual TLS: Stuff You Should Know Mar 19, 2020 201 tls , protocols Don’t Try to Sanitize Input—Escape Output Feb 27, 2020 200 sanitization , escaping Encrypting DNS Query Bad for Performance? (erw )Feb 20, 2020 199 performance , dns , http , encryption Apple Joins FIDO Alliance, Commits to Getting Rid of Passwords (sjv /zdn )Feb 12, 2020 198 apple , fido , passwords , authentication How to Automatically Update Your JavaScript Dependencies (spa /clo )Jan 30, 2020 197 how-tos , javascript , dependencies , automation , processes What SSL Is, and Which Certificate Type Is Right for You Jan 29, 2020 196 ssl , certificates , privacy , concepts Usability and Security; Better Together (24w )Dec 22, 2019 195 usability , user-experience Server-Side Includes (SSI) Injection (owa )Dec 4, 2019 194 ssi How Internet Security Works: TLS, SSL, and CA (osd )Nov 18, 2019 193 tls , ssl , protocols , certificates Security and Privacy for Our Times (luk /w3c )Sep 11, 2019 192 privacy , web-platform Web Feature Developers Told to Dial Up Attention on Privacy and Security (rip )Sep 11, 2019 191 w3c , privacy , web-platform CSS Security Vulnerabilities (chr /css )Sep 9, 2019 190 css , privacy , vulnerabilities Understanding Subresource Integrity (dre /sma )Apr 9, 2019 189 hashing , embed-code W3C Strategic Highlights: Web for All (Security, Privacy, Identity) (w3c )Mar 18, 2019 188 w3c , privacy , authentication Guide to Web Authentication Jan 24, 2019 187 websites , authentication , webauthn , javascript It’s Beginning to Look a Lot Like XSSmas (24w )Dec 17, 2018 186 vulnerabilities , csrf , xss Protecting Your Site With Feature Policy (rac /sma )Dec 12, 2018 185 http-headers , http AWS Security Guide: 7 Best Practices to Avoid Security Risks (wom )Oct 31, 2018 184 guides , aws , best-practices WebAuthn, FIDO2 Infuse Browsers, Platforms With Strong Authentication (dar )Sep 19, 2018 183 w3c , fido , authentication , webauthn , browsers In Your Face, Passwords: Big Three Browsers All Adopt Authentication API Aug 1, 2018 182 authentication , webauthn , apis , edge , chrome , firefox , browsers HTTPS Is Easy (tro )Jun 27, 2018 181 websites , http WordPress Security as a Process (sma )Jun 21, 2018 180 wordpress , processes Making Your Website Faster and Safer With Cloudflare Jun 12, 2018 179 performance , caching , cloudflare Validating Dependencies in the Project With npm-check and depcheck Jun 1, 2018 178 dependencies , maintenance , auditing , tooling , npm Third Party CSS Is Not Safe (jaf )Feb 27, 2018 177 html , css , embed-code Attackers Can Steal Sensitive Data by Abusing CSS—CSS Exfil Vulnerability Feb 7, 2018 176 css , csp Building Secure JavaScript Applications Jan 18, 2018 175 javascript , xss , csrf , json-web-tokens , passwords Creating Secure Password Resets With JSON Web Tokens (sma )Nov 9, 2017 174 passwords , json-web-tokens , nodejs The Complete Guide to Switching From HTTP to HTTPS (sma )Jun 12, 2017 173 guides , http Rate Limiting With nginx Jun 12, 2017 172 servers , nginx , rate-limiting How (Not) to Control Your CDN (mno )Jun 7, 2017 171 content-delivery , caching , http How to Secure WordPress With SSL May 10, 2017 170 how-tos , wordpress , ssl Encrypting IP Addresses (ber )May 7, 2017 169 ip , network , privacy , encryption How to Secure Your Web App With HTTP Headers (sma )Apr 3, 2017 168 how-tos , web-apps , http , http-headers , csp Just Another HTTPS Nudge (chr /css )Mar 3, 2017 167 http On EME in HTML5 (tim /w3c )Feb 28, 2017 166 eme , drm , html , legal , standards , w3c What Is HTTPS and SSL, and Why Your Ecommerce Website Badly Needs Them Both Feb 9, 2017 165 http , ssl , ecommerce Using SSH Securely (ann )Jan 24, 2017 164 ssh More Than 300 Federal Gov Websites Fail to Meet Domain Encryption Deadline Jan 4, 2017 163 http , tls , protocols , encryption Content Security Policy Level 2 (mik +/w3c )Dec 15, 2016 162 standards , csp A Checklist for Website Reviews (hcr )Dec 5, 2016 161 checklists , performance , browsers , seo , accessibility Content Security Policy, Your Future Best Friend (sma )Sep 12, 2016 160 csp , link-lists A Refined Content Security Policy (web )Aug 5, 2016 159 html , csp , webkit , safari , browsers The Performance Benefits of “rel=noopener” (jaf )Jul 21, 2016 158 html , links , performance Web Platform Security Boundaries (ann )Jun 24, 2016 157 web-platform Subresource Integrity (dev +/w3c )Jun 23, 2016 156 hashing , html , standards npm Fails to Restrict the Actions of Malicious npm Packages Mar 26, 2016 155 npm , vulnerabilities W3C Looks to Secure the Web (sdt )Feb 17, 2016 154 w3c , authentication Distribution Packages Considered Insecure Feb 13, 2016 153 dependencies , unix-like The Current State of Web Security (An Interview With Anselm Hannemann) (hel +/css )Jan 18, 2016 152 interviews , http , ssl , tls , encryption , cloudflare , lets-encrypt Eliminating Known Vulnerabilities With Snyk (sma )Jan 13, 2016 151 vulnerabilities , tooling 10 Web Predictions for 2016 (cra )Jan 6, 2016 150 web , outlooks , site-generators , browsers , css , mobile , performance , webassembly , seo HSTS and “Let’s Encrypt” (tka )Jan 4, 2016 149 http , http-headers , ssl , lets-encrypt Indexing HTTPS Pages by Default Dec 17, 2015 148 google , search , http An in-Depth Look at CORS Dec 17, 2015 147 cors , javascript , php Why Passwordless Authentication Works (cra )Nov 10, 2015 146 authentication , passwords Introduction to TLS and SSL (ope )Aug 22, 2015 145 introductions , tls , ssl , protocols , certificates A Simple Developer Error Is Exposing Private Information on Thousands of Websites (owe )Jul 27, 2015 144 version-control , git , mistakes , vulnerabilities More Tips to Further Secure WordPress (eli )Jul 9, 2015 143 wordpress , tips-and-tricks , plugins Improving Web Security With the Content Security Policy Jun 24, 2015 142 csp , http Deprecating HTTP May 11, 2015 141 http , protocols , deprecation Mozilla Wants to Deprecate Non-Secure HTTP, Will Make Proposals to W3C “Soon” (epr /ven )Apr 30, 2015 140 mozilla , http , deprecation Want Fancy Firefox Features? Secure Your Website (sts /cne )Apr 14, 2015 139 firefox , browsers , http WordPress Front End Security: CSRF and Nonces (css )Mar 24, 2015 138 wordpress , csrf Introduction to WordPress Front End Security: Escaping the Things (css )Mar 23, 2015 137 introductions , wordpress , escaping What Are the Security Risks of HTML5 Apps? Mar 18, 2015 136 web-apps , sanitization Moving to HTTPS on WordPress (chr /css )Mar 6, 2015 135 wordpress , http Same-Origin Policy (ann )Feb 23, 2015 134 cors , web-platform Securing the Web (w3c )Jan 23, 2015 133 web-platform What I’d Tell My Younger Self About Learning Development as a Web Designer Aug 25, 2014 132 learning , programming , javascript , databases , servers , preprocessors , version-control , performance , career HTTPS as a Ranking Signal (met )Aug 7, 2014 131 google , search , http , seo mXSS (gaz )May 6, 2014 130 xss , html It’s Time to Encrypt the Entire Internet (kli /wir )Apr 17, 2014 129 web , http , ssl , encryption 3 Tips to Find Hacking on Your Site, and Ways to Prevent and Fix It Feb 28, 2014 128 search , google , tips-and-tricks Cross-Origin Resource Sharing (ann /w3c )Jan 16, 2014 127 cors , standards Despite Automatic Updates, Old Browsers Are Still a Problem (edb /zdn )Jan 6, 2014 126 browsers , web-platform , chrome , firefox , internet-explorer , safari Cross-Origin Resource Sharing on Track to Become a W3C Recommendation (sdt )Jan 3, 2014 125 w3c , cors , standards Bid to Kill CAPTCHA Security Test Gains Momentum Aug 5, 2013 124 captcha , accessibility We Should All Have Something to Hide Jun 12, 2013 123 privacy Mobile Website Security May 14, 2013 122 mobile , hosting , policies WordPress Security Tips Apr 17, 2013 121 wordpress , tips-and-tricks Brad Hill: “HTML5 Security Realities” (chr /css )Feb 22, 2013 120 slides , xss , html Bulletproof Your Drupal Website Jan 21, 2013 119 drupal Top 10 PHP Security Vulnerabilities Oct 15, 2012 118 php , vulnerabilities A Front End Engineer’s Manifesto (zac )Aug 24, 2012 117 websites , manifestos , user-experience , progressive-enhancement , simplicity , foss , accessibility , community , learning A JavaScript Security Flaw Aug 9, 2012 116 javascript The Secure Programmer’s Pledge Jul 16, 2012 115 manifestos An Introduction to Content Security Policy (mik )Jun 15, 2012 114 introductions , csp Rate Limiting With Apache and mod_security (joh )May 15, 2012 113 servers , apache , rate-limiting Cross-Site Scripting Attacks (XSS) Apr 30, 2012 112 xss , examples How to Secure Your WordPress Website (sma )Nov 10, 2011 111 how-tos , wordpress , link-lists Using CORS Oct 26, 2011 110 cors Some Notes on the Recent XML Encryption Attack (w3c )Oct 24, 2011 109 xml , encryption XML Encryption Flaw Leaves Web Services Vulnerable (eur )Oct 24, 2011 108 web-services , xml , encryption Notes From Writing HTML5 Media (bur )Jul 19, 2011 107 html , multimedia HTTPS Is More Secure, So Why Isn’t the Web Using It? (ars )Mar 20, 2011 106 http , protocols , web Web Cryptography: Salted Hash and Other Tasty Dishes (ali )Feb 22, 2011 105 cryptography What Are the JSON Security Concerns in Web Development? (sim )Jan 6, 2011 104 json What Is Cross Site Scripting or XSS? (chr /css )Nov 19, 2010 103 xss , javascript , concepts Web Developers Accountable for HTML 5 Security (zdn )Oct 5, 2010 102 html HTML5 Raises New Security Issues Aug 20, 2010 101 html , browsers 10 Useful WordPress Security Tweaks (sma )Jul 1, 2010 100 wordpress Web Security: Are You Part of the Problem? (cod /sma )Jan 14, 2010 99 vulnerabilities , php , javascript Full Frontal ’09: Chris Heilmann on JavaScript Security (mic /aja )Nov 20, 2009 98 javascript Cookies and Security (nza )May 12, 2009 97 cookies , xss , csrf A Critical Vulnerability in IE8 (jed )May 12, 2009 96 internet-explorer , browsers , vulnerabilities Finally Something to Get a Few More Users Off of IE 6? (dal /aja )Dec 17, 2008 95 internet-explorer , browsers The Internet Is Closing to Innovation (zit /new )Nov 28, 2008 94 web You Could Be Getting Clickjacked (tec )Nov 21, 2008 93 vulnerabilities , frames , w3c Video and Audio Tags and Cross Origin Access (dal /aja )Nov 10, 2008 92 html , multimedia Dumb Security Tips: Think Before You Follow Online Guides (tan )Oct 26, 2008 91 tips-and-tricks Alerting Webmasters to Webserver Vulnerabilities Oct 16, 2008 90 google Simon Willison, @Media Ajax (mic /aja )Sep 16, 2008 89 ajax , xss , csrf , javascript , json