Tech Skills

Cybersecurity

Ethical hacking, penetration testing, network security, CTFs and defensive security

32,194
lessons
Skills in this topic
View full skill map →
Security Basics
beginner
Fix OWASP top 10 vulnerabilities
Cryptography Fundamentals
intermediate
Explain how digital signatures prevent tampering
AI Security
intermediate
Identify and patch prompt injection vulnerabilities
Network Security
intermediate
Configure a firewall with proper inbound/outbound rules
Ethical Hacking & Pen Testing
intermediate
Conduct a full pen test with Kali Linux
Cloud Security
intermediate
Implement IAM least-privilege policies on AWS/GCP
Incident Response
intermediate
Build an incident response playbook
Security Compliance
intermediate
Map controls for SOC 2 Type II compliance
Defensive AI
advanced
Build an AI-powered log anomaly detector
All Reads (23,923) Articles (12933)Blog Posts (8657)Tutorials (835)Research Papers (68)News (1430)
Google Staff Security Engineer Interview Prep: Cloud CISO, Product Security, Coding, and Domain-Specific Questions
Dev.to · Olga Larionova 🔐 Cybersecurity ⚡ AI Lesson 9h ago
Google Staff Security Engineer Interview Prep: Cloud CISO, Product Security, Coding, and Domain-Specific Questions
Introduction to the Google Staff Security Engineer Interview Securing a Staff Security...
The Voice-AI Vendor Security Questionnaire: 12 Questions About Recordings, PII and Model Training
Dev.to · Peter Jackman 🔐 Cybersecurity ⚡ AI Lesson 12h ago
The Voice-AI Vendor Security Questionnaire: 12 Questions About Recordings, PII and Model Training
Short answer: Before signing an AI voice or AI sales-agent vendor, get written answers to twelve questions: recording storage and location, retention and deleti
Why TOTP 2FA Verification Fails in Production: 5 Cryptographic Edge Cases
Dev.to · Rasika Dangamuwa 🔐 Cybersecurity ⚡ AI Lesson 14h ago
Why TOTP 2FA Verification Fails in Production: 5 Cryptographic Edge Cases
Implementing Time-Based One-Time Passwords (TOTP, RFC 6238) seems straightforward: generate a 160-bit...
XopProtector: An Open Source Android APK Protection Framework Ready for Real-World Production
Dev.to · Android 小行家 🔐 Cybersecurity ⚡ AI Lesson 15h ago
XopProtector: An Open Source Android APK Protection Framework Ready for Real-World Production
XopProtector: An Open Source Android APK Protection Framework Ready for Real-World...
Your agent's 'secure' network policy was off unless you did four steps — so it was off
Dev.to · wartzar-bee 🔐 Cybersecurity ⚡ AI Lesson 17h ago
Your agent's 'secure' network policy was off unless you did four steps — so it was off
enclave 0.8.0 makes the safe autonomous-agent config the default instead of a ritual. The lesson: an opt-in control with a four-step activation cost is a contro
SBOM-for-Agents: The Missing Trust Layer for Agent Supply Chains
Dev.to · bozoinc 🔐 Cybersecurity ⚡ AI Lesson 18h ago
SBOM-for-Agents: The Missing Trust Layer for Agent Supply Chains
Introduction Software Bill of Materials (SBOMs) are now a standard requirement for enterprise...
A symlink walks straight out of an agent's write allow-list
Dev.to · Fewparts 🔐 Cybersecurity ⚡ AI Lesson 18h ago
A symlink walks straight out of an agent's write allow-list
path.resolve never opens anything. A link inside your allow-list reads as in scope, and the write lands outside it — here's the escape, the fix, and the bug the
Why Webhook HMAC Verification Fails in Production: 5 Cryptographic Traps Every Developer Misses
Dev.to · Rasika Dangamuwa 🔐 Cybersecurity ⚡ AI Lesson 18h ago
Why Webhook HMAC Verification Fails in Production: 5 Cryptographic Traps Every Developer Misses
You’ve set up your webhook endpoint to receive payment notifications from Stripe, pull request alerts...
CVE-2026-45019: CVE-2026-45019: Server-Side Request Forgery (SSRF) in Chainlit MCP Endpoint
Dev.to · CVE Reports 🔐 Cybersecurity ⚡ AI Lesson 19h ago
CVE-2026-45019: CVE-2026-45019: Server-Side Request Forgery (SSRF) in Chainlit MCP Endpoint
CVE-2026-45019: Server-Side Request Forgery (SSRF) in Chainlit MCP Endpoint Vulnerability...
GCS Race Conditions & Generation-Fenced Leases
Dev.to · Humza Tareen 🔐 Cybersecurity ⚡ AI Lesson 20h ago
GCS Race Conditions & Generation-Fenced Leases
Two race conditions in distributed step leasing where stale workers deleted fresh locks — fixed with GCS generation-based optimistic concurrency.
Taking control of cluster security: A deep dive into GKE ClusterNetworkPolicy
Dev.to · Olivier Bourgeois 🔐 Cybersecurity ⚡ AI Lesson 21h ago
Taking control of cluster security: A deep dive into GKE ClusterNetworkPolicy
Discover how GKE ClusterNetworkPolicy enables platform teams to establish global security guardrails without hindering developer agility
How to Detect Hidden Risks in Third-Party Software
Dev.to · Praveen 🔐 Cybersecurity ⚡ AI Lesson 23h ago
How to Detect Hidden Risks in Third-Party Software
Introduction Third-party software risk is no longer limited to known CVEs. Enterprise...
I broke an MCP server in 10 minutes — the exact prompt injection attack chain (with fixes)
Dev.to · Galeops 🔐 Cybersecurity ⚡ AI Lesson 23h ago
I broke an MCP server in 10 minutes — the exact prompt injection attack chain (with fixes)
Most MCP servers in production right now have the same flaw: nothing separates data from...
SharePoint Vulnerabilities And The Cost Of Patch Visibility Debt
Dev.to · NTCTech 🔐 Cybersecurity ⚡ AI Lesson 23h ago
SharePoint Vulnerabilities And The Cost Of Patch Visibility Debt
Patch visibility debt is what accumulates when remediation priority depends on confirmation signals...
Checking 800M Leaked Passwords in 2MB of RAM with Bloom Filters
Dev.to · Doaa H Alshawwa 🔐 Cybersecurity ⚡ AI Lesson 1d ago
Checking 800M Leaked Passwords in 2MB of RAM with Bloom Filters
When users register or change their passwords, security guidelines (like NIST SP 800-63B) recommend...
Your Detection Rules Have Ten Years of Windows Logic and Zero Lines for a Stolen IAM Key
Dev.to · Rocky 🔐 Cybersecurity ⚡ AI Lesson 1d ago
Your Detection Rules Have Ten Years of Windows Logic and Zero Lines for a Stolen IAM Key
Your team has a mature detection stack. Years of rules tuned against real incidents: suspicious...
The Scanner Came Back Clean. The Discount Code Still Worked 40 Times.
Dev.to · Rocky 🔐 Cybersecurity ⚡ AI Lesson 2d ago
The Scanner Came Back Clean. The Discount Code Still Worked 40 Times.
The automated scan on a checkout flow came back with nothing above low. No SQLi, no reflected XSS, no...
What a Zero-Network MCP Scanner Can (and Can't) Catch: All 10 Heuristics, Honestly
Dev.to · Ventrova 🔐 Cybersecurity ⚡ AI Lesson 2d ago
What a Zero-Network MCP Scanner Can (and Can't) Catch: All 10 Heuristics, Honestly
Every heuristic in our static MCP manifest scanner, what each one actually checks, and an honest line...
Everything you ever committed is the product
Dev.to · Alkis Yuv 🔐 Cybersecurity ⚡ AI Lesson 2d ago
Everything you ever committed is the product
A five-round leak audit, a marketplace leak no git check could catch, and the four doors that guard every exit now.
I Built an Open-Source AWS Cloud Security tool for solo devs & founders !
Dev.to · Kavee 🔐 Cybersecurity ⚡ AI Lesson 3d ago
I Built an Open-Source AWS Cloud Security tool for solo devs & founders !
If you're a solo dev running your own AWS account with no security team, you've probably had this...
BrunnerCTF - php-2003 Writeup
Dev.to · Yogeshwar Peela 🔐 Cybersecurity ⚡ AI Lesson 3d ago
BrunnerCTF - php-2003 Writeup
Summary A "Brunnerne Hosting" customer portal exposed a legacy reservation import form...
IRGC-Linked Hackers Disable British Power Plant in Cyber Attack
Dev.to · BeyondMachines 🔐 Cybersecurity ⚡ AI Lesson 3d ago
IRGC-Linked Hackers Disable British Power Plant in Cyber Attack
Iranian-affiliated hackers linked to the IRGC disabled a small UK power plant for four days in July 2026 by exploiting internet-exposed industrial controllers.
Re: @anp2network — fixtures shipped first, evidence-carrying response shipped second
Dev.to · Edison Flores 🔐 Cybersecurity ⚡ AI Lesson 3d ago
Re: @anp2network — fixtures shipped first, evidence-carrying response shipped second
36 test vectors, 480 tests, evidence-carrying receipts, Merkle audit log.
Introducing T-PHANTOM OS 5.3: A Saudi-Developed Bilingual Linux Platform for DFIR and Cybersecurity
Dev.to · م. طلال السحيمي 🔐 Cybersecurity ⚡ AI Lesson 3d ago
Introducing T-PHANTOM OS 5.3: A Saudi-Developed Bilingual Linux Platform for DFIR and Cybersecurity
By Eng. Talal Fawaz Al-Sohimiy Designer & Developer of T-PHANTOM OS Saudi Arabia I built...
You Can Change Your Password. You Can't Change Your Fingerprints.
Dev.to · CaraComp 🔐 Cybersecurity ⚡ AI Lesson 4d ago
You Can Change Your Password. You Can't Change Your Fingerprints.
The engineering blind spots in national biometric identity rollouts highlight a fundamental reality...
I Built a Password Strength Calculator That Never Sends Your Password Anywhere Here's the Entropy Math
Dev.to · G S 🔐 Cybersecurity ⚡ AI Lesson 4d ago
I Built a Password Strength Calculator That Never Sends Your Password Anywhere Here's the Entropy Math
Type Your Real Password Into a Random Website. What Could Go Wrong? Go search "password...
cyber security
Dev.to · excellence technology 🔐 Cybersecurity ⚡ AI Lesson 4d ago
cyber security
Cybersecurity: Building a Safer Digital Future Cybersecurity has become one of the most important...
Day 30: Hard Reset Forgets on Purpose, and NAT Needs a Guardrail Switched Off
Dev.to · Nnamdi Felix Ibe 🔐 Cybersecurity ⚡ AI Lesson 4d ago
Day 30: Hard Reset Forgets on Purpose, and NAT Needs a Guardrail Switched Off
Thirty days in, and today both tasks required deliberately switching off something that exists to...
E4del / PINHOLE Using FTP Banners for Command Retrieval
Dev.to · Anoymask 🔐 Cybersecurity ⚡ AI Lesson 4d ago
E4del / PINHOLE Using FTP Banners for Command Retrieval
1. Basic Information Article Title: FTP Banners: The New Dead Drop Resolver Delivering...
TrueConf Server Exploitation: PhantomCore Delivered via CVE-2026-72529 / 72530
Dev.to · Anoymask 🔐 Cybersecurity ⚡ AI Lesson 4d ago
TrueConf Server Exploitation: PhantomCore Delivered via CVE-2026-72529 / 72530
1. Basic Information Article Title: Head Mare APT Group exploits vulnerabilities in...
Three Russian-Linked Clusters Abuse Legitimate Authentication Flows
Dev.to · Anoymask 🔐 Cybersecurity ⚡ AI Lesson 4d ago
Three Russian-Linked Clusters Abuse Legitimate Authentication Flows
1. Basic Information Article Title: Going with the Flow(s): Distinct Clusters Target...
Security news weekly round-up - 21st August 2026
Dev.to · Habdul Hazeez 🔐 Cybersecurity ⚡ AI Lesson 4d ago
Security news weekly round-up - 21st August 2026
Learn about the top cybersecurity news between August 14, 2026, and August 21, 2026. Read now and increase your cybersecurity knowledge.
Defender's Own BTR.sys Driver Can Delete Your EDR During Boot
Dev.to · Etairos.ai 🔐 Cybersecurity ⚡ AI Lesson 4d ago
Defender's Own BTR.sys Driver Can Delete Your EDR During Boot
TL;DR what: Check Point Research disclosed BTR Reforged, a technique that loads...
What a Website Can Learn From Your Browser: IP, WebRTC, and IPv6
Dev.to · Mustafa Kaçaroğlu 🔐 Cybersecurity ⚡ AI Lesson 4d ago
What a Website Can Learn From Your Browser: IP, WebRTC, and IPv6
Most people think browser privacy begins and ends with cookies. Cookies matter, but a website can...
GHSA-8CFW-PCWH-V63W: GHSA-8CFW-PCWH-V63W: Authenticated Twig Sandbox Escape and Remote Code Execution in Winter CMS
Dev.to · CVE Reports 🔐 Cybersecurity ⚡ AI Lesson 4d ago
GHSA-8CFW-PCWH-V63W: GHSA-8CFW-PCWH-V63W: Authenticated Twig Sandbox Escape and Remote Code Execution in Winter CMS
GHSA-8CFW-PCWH-V63W: Authenticated Twig Sandbox Escape and Remote Code Execution in Winter...
Building Cencurity: What Two Reversals Taught Me About Shipping a Security Tool
Dev.to · Sangyeon Park 🔐 Cybersecurity ⚡ AI Lesson 4d ago
Building Cencurity: What Two Reversals Taught Me About Shipping a Security Tool
Problem definition, an architecture I got wrong the first time, and an honest read of a modest...
Elementor Pro Logic Flaw Allows Unauthenticated Remote Code Execution
Dev.to · BeyondMachines 🔐 Cybersecurity ⚡ AI Lesson 5d ago
Elementor Pro Logic Flaw Allows Unauthenticated Remote Code Execution
Elementor Pro versions before 4.2.2 contain a critical logic flaw in the file upload module that allows unauthenticated attackers to bypass extension filters an
UMC Utrecht Third-Party Breach Exposes Data of 5,000 Guesthouse Visitors
Dev.to · BeyondMachines 🔐 Cybersecurity ⚡ AI Lesson 5d ago
UMC Utrecht Third-Party Breach Exposes Data of 5,000 Guesthouse Visitors
UMC Utrecht suffered a data breach affecting 5,000 guesthouse visitors after an unauthorized actor compromised its third-party booking provider, VIPS PMS. The s
Announcing Suijin
Dev.to · William Jiang 🔐 Cybersecurity ⚡ AI Lesson 5d ago
Announcing Suijin
Check out Suijin here Security testing, defense and penetration testing today is completely...
🌐 What is Cyberspace?
Dev.to · Yashpal Patel 🔐 Cybersecurity ⚡ AI Lesson 5d ago
🌐 What is Cyberspace?
🌐 What is Cyberspace? Most people confuse Cyberspace with the Internet, but they aren't the same. 💻...
Finding Network Blind Spots: A Practical Guide to Scanning and Scripting with ScanSearch
Dev.to · Billy 🔐 Cybersecurity ⚡ AI Lesson 5d ago
Finding Network Blind Spots: A Practical Guide to Scanning and Scripting with ScanSearch
Ever been in a situation where you need to quickly check if a specific port is exposed on a range of...
Vulnerability advisories grew 2.3x-6.6x in 5 years; open-source tool count stayed flat
Dev.to · hamelin123 🔐 Cybersecurity ⚡ AI Lesson 5d ago
Vulnerability advisories grew 2.3x-6.6x in 5 years; open-source tool count stayed flat
We bucketed every advisory in OSV.dev's public per-ecosystem archives by its record-publication year...
Defending Your Rust Builds Against Malicious Proc Macros
Dev.to · RobustTrueTry 🔐 Cybersecurity ⚡ AI Lesson 5d ago
Defending Your Rust Builds Against Malicious Proc Macros
Learn practical steps to detect and block build‑time malware like the Arrayref crate before it infects your CI.
An immutable audit log cannot prove a decision that was never written
Dev.to · Mads Hansen 🔐 Cybersecurity ⚡ AI Lesson 5d ago
An immutable audit log cannot prove a decision that was never written
An agent proposes an action from database evidence. A reviewer changes it and approves. The action...
Two authenticated MCP gateways can still disagree about authorization
Dev.to · Mads Hansen 🔐 Cybersecurity ⚡ AI Lesson 5d ago
Two authenticated MCP gateways can still disagree about authorization
An internal IAM gateway and an external OAuth gateway expose the same database tool. Both...
The Principle of Least Privilege: Why File Permissions Like 600/644/755 Exist
Dev.to · Susumu Takahashi 🔐 Cybersecurity ⚡ AI Lesson 5d ago
The Principle of Least Privilege: Why File Permissions Like 600/644/755 Exist
Anyone who has worked with SSH private keys has run into an instruction to "set it to 600." Config...
SPF record hygiene: the security debt nobody logs
Dev.to · Pierre Bengevenga 🔐 Cybersecurity ⚡ AI Lesson 5d ago
SPF record hygiene: the security debt nobody logs
Nobody opens a ticket for an SPF record. There is no alert, no dashboard turning red, no user calling...
The Rust vs. JavaScript Undefined Behavior Crisis: Lessons from Recent Security Incidents and Cross-Language Compilation Bugs
Dev.to · Tamiz Uddin 🔐 Cybersecurity ⚡ AI Lesson 5d ago
The Rust vs. JavaScript Undefined Behavior Crisis: Lessons from Recent Security Incidents and Cross-Language Compilation Bugs
Analyze recent security incidents where Rust and JavaScript undefined behavior caused critical failures, exploring cross-language compilation bugs and lessons f