Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

DEV Community
dev.to > jenueldev > metas-ai-hacked-a-company-the-safety-test-was-the-weak-link-58kf

Meta's AI Hacked a Company. The Safety Test Was the Weak Link

1+ day, 3+ hour ago   (870+ words) Meta says an AI model hacked another company during security testing. The incident shows why agent builders need zero-trust sandboxes and tighter permissions. Tagged with ai, security, cybersecurity, programming....

DEV Community
dev.to > masaoshimadaopen > my-x-twitter-weekly-report-bot-showed-0-followers-for-two-months-the-culprit-was-a-non-existent-1edl

My X (Twitter) Weekly Report Bot Showed '0 Followers' for Two Months—The Culprit Was a Non-Existent Account Name in My.env File

1+ day, 11+ hour ago   (670+ words) Hey everyone, it's your friendly neighborhood old man developer here. I'm 38, dabbling in AI agents and automated trading bots on the side, in between my day job. Today, I want to share a story about one of my self-made bots…...

DEV Community
dev.to > dannwaneri > openai-just-solved-a-problem-open-since-1999-it-still-cant-ask-its-own-question-48j0

OpenAI Just Solved a Problem Open Since 1999. It Still Can't Ask Its Own Question.

1+ day, 23+ hour ago   (412+ words) Four days after I published a piece arguing LLMs can't make the jump, OpenAI announced that an internal model called Astra had solved ten open problems in mathematics and theoretical computer science. One of them had been open since 1999. I'm…...

DEV Community
dev.to > ninjafromqueens > two-hacks-one-day-two-completely-different-attack-surfaces-2fed

Two Hacks, One Day, Two Completely Different Attack Surfaces

6+ day, 14+ hour ago   (595+ words) Today we lost tens of millions of dollars to two separate attacks. Both are worth understanding. They're not the same problem, and they don't have the same solution. Attack 1: COLDCARD Firmware $38M–$70M in Bitcoin Effective entropy dropped from 128 bits to approximately…...

DEV Community
dev.to > ziizium > security-news-weekly-round-up-31st-july-2026-4odj

Security news weekly round-up - 31st July 2026

6+ day, 13+ hour ago   (661+ words) Interesting, to say the least, is how I qualify the articles that we have for this week's review. It's fascinating to know what's possible and reading articles that challenge your reality is something that you and I can put in…...

DEV Community
dev.to > anoymask > kindarails2shell-cve-2026-66066-arbitrary-file-read-and-rce-via-active-storage-uploads-1nd5

KindaRails2Shell (CVE-2026-66066): Arbitrary File Read and RCE via Active Storage Uploads

1+ week, 7+ hour ago   (1600+ words) 1. Basic Information Article Title: Alert on Vulnerability in Ruby on Rails Active Storage Leading to Remote Code Execution Publisher: JPCERT/CC Publication & Update Date: 2026-07-30 Original Article: https://www.jpcert.or.jp/at/2026/at260021.html Related Sources: https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm Related Entities: CVE-2026-66066, KindaRails2Shell, Ruby on Rails, Active Storage, libvips, ruby-vips…...

DEV Community
dev.to > adam_lewandowski_59/67/4796 > cisa-kev-catalog-a-working-sysadmins-guide-to-actually-using-it-2o15

CISA KEV catalog: a working sysadmin's guide to actually using it

1+ week, 10+ hour ago   (522+ words) This is a guide to the catalog itself: what it promises, what it doesn't, how the feeds are structured, how to map entries to your own estate without fooling yourself, and how to combine it with EPSS and vendor advisories…...

DEV Community
dev.to > nithiyarajesh > neutralizing-the-shield-the-escalation-of-byovd-attacks-in-kernel-level-evasion-1044

Neutralizing the Shield: The Escalation of BYOVD Attacks in Kernel-Level Evasion

1+ week, 2+ day ago   (631+ words) The contemporary threat landscape is characterized by a strategic shift toward the subversion of endpoint security primitives. As Endpoint Detection and Response (EDR) solutions have become more resilient, sophisticated threat actors have pivoted from user-mode obfuscation to kernel-mode neutralization. The…...

DEV Community
dev.to > etairos > 24650-exposed-bmcs-hand-out-ipmi-password-hashes-to-anyone-who-asks-2ckl

24,650 Exposed BMCs Hand Out IPMI Password Hashes to Anyone Who Asks

1+ week, 2+ day ago   (1727+ words) TL;DR what: Researchers at Lava scanned the internet on May 6, 2026 and found 36,872 hosts exposing IPMI on UDP port 623, of which 24,650 return password-derived HMAC-SHA1 authentication material to unauthenticated attackers before login via CVE-2013-4786. impact: Over 30% of collected hashes were cracked…...

DEV Community
dev.to > anoymask > fortios-cve-2025-68686-bypass-of-symlink-persistence-mitigation-for-already-compromised-devices-3534

FortiOS CVE-2025-68686: Bypass of Symlink Persistence Mitigation for Already Compromised Devices

1+ week, 3+ day ago   (1589+ words) 1. Basic Information Article Name: CISA Adds Two Known Exploited Vulnerabilities to Catalog Source: CISA Publication Date: July 27, 2026 Original Link: https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog Related Sources: https://fortiguard.fortinet.com/psirt/FG-IR-25-934 https://nvd.nist.gov/vuln/detail/CVE-2025-68686 Related Entities: CVE-2025-68686, FortiOS, SSL-VPN, symlink persistence, CISA KEV Severity: Critical 2. Summary This is an actively…...