Articles
Essays, 30
OWASP Top 10:2025 Is Live. SSRF Is Gone, Supply Chain Is #3.
OWASP published the 2025 revision of the Top 10 in May 2026. Three structural changes deserve real attention from anyone writing or auditing application code.
Mini Shai-Hulud: The TanStack Supply Chain Attack That Hit OpenAI, Mistral, and 160+ Packages
A self-propagating supply chain worm compromised TanStack npm packages through GitHub Actions cache poisoning. No credentials stolen, just OIDC tokens extracted from runner memory.
Shift-Left Pentesting: Why Offensive Security Belongs in Your IDE
Traditional penetration testing happens after deployment. A new generation of tools moves attack-surface analysis into the IDE, where the cost of a fix is measured in developer-minutes rather than incident reports.
Copy Fail: 732 Bytes to Root on Every Linux Distribution Since 2017
CVE-2026-31431 is a local privilege escalation in the Linux kernel cryptographic subsystem. A 732-byte Python script can edit a setuid binary in memory and obtain root. CISA added it to KEV on May 7.
Exchange Server XSS-to-Spoofing: CVE-2026-42897 Added to CISA KEV
A cross-site scripting flaw in on-premises Microsoft Exchange Server enables email spoofing via crafted messages. CISA added it to KEV on May 15 with a May 29 federal deadline.
NGINX Rift: An 18-Year-Old Heap Buffer Overflow Just Got a CVE and a PoC
CVE-2026-42945 is a critical heap buffer overflow in NGINX rewrite module that has existed since 2008. CVSS 9.2, public PoC, zero authentication required.
Cisco SD-WAN Authentication Bypass: CVSS 10.0 and the Sixth Zero-Day of 2026
CVE-2026-20182 is a maximum-severity authentication bypass in Cisco Catalyst SD-WAN Controller. CISA added it to KEV with a May 17 federal remediation deadline.
Salt Typhoon and the Telecom Backbone: Why Application-Layer Encryption Just Became Non-Negotiable
The Salt Typhoon intrusions into major US telecom carriers exposed lawful intercept systems and call metadata at unprecedented scale. The takeaway for software teams: assume the transport layer is hostile.
CISA KEV in 2025: What the Five-Day Exploitation Window Means for Developers
CISA's Known Exploited Vulnerabilities catalog added 187 entries in the past 12 months. The median time from CVE disclosure to active exploitation has dropped to 5 days. Here's what that means for development teams.
Prompt Injection in Agentic AI: The 2026 Vulnerability Class That Acts Like Remote Code Execution
Agentic AI systems combining LLMs with tool use and persistent memory have created a new vulnerability class. When the agent has shell or API access, prompt injection behaves like RCE.
HHS Wants Annual Pentests in the HIPAA Security Rule. Here's What That Looks Like.
HHS proposed updates to the HIPAA Security Rule in early 2025 that would make penetration testing an explicit requirement for covered entities. Here's what the proposed rule says and how to prepare.
CMMC Level 2 Is Enforced. Here's What Your Code Has to Show.
CMMC Level 2 enforcement is active for DoD contracts. Most compliance failures trace back to code, not policy. Here's the control mapping every developer on a defense program needs to understand.
NIST CSF 2.0: Govern Got the Headlines, ID.AM-07 Will Cost You the Audit
NIST released Cybersecurity Framework 2.0 with a new Govern function and expanded scope beyond critical infrastructure. Here's what the update means at the code level.
PCI-DSS v4.0.1 Requirements That Live in Your Code, Not Your Network
PCI-DSS v4.0.1 is the only valid revision, and its last future-dated requirements took effect in March 2025. Requirements 6.2 and 6.3 are the ones developers own, and they are stricter than v3.2.1 in ways most teams have not yet absorbed.
The HIPAA Breach Report 2025: The Code Patterns Behind Healthcare's Biggest Incidents
HHS recorded 725 healthcare data breaches in 2024 affecting more than 180 million records. Their disclosed technical causes cluster around a small set of CWEs, and every one of them is detectable at write time.
XZ Utils One Year Later: The Supply Chain Attack Surface Hiding in Developer Environments
The XZ Utils backdoor (CVE-2024-3094) demonstrated that supply chain attacks target developer environments as much as production systems. Here's what changed and what hasn't.
FedRAMP Rev 5: The 80 New Controls Your Code Has to Pass
FedRAMP updated its baselines to align with NIST 800-53 Rev 5. For developers building cloud services targeting government customers, here's which controls live in code.
Tuning Your Scanner to the 2024 CWE Top 25 Without Drowning in False Positives
MITRE published the 2024 CWE Top 25. Several rankings shifted meaningfully. Here's how to configure your scanner for maximum coverage of the current threat landscape.
The Vulnerability Class That Arrived With AI Coding Assistants
LLM-generated code passes syntax checks, passes type checks, and fails security checks at higher rates than hand-written code. Here's why and what to do about it.
Zero-Trust for Developer Environments: What Air-Gapped AI Actually Means
Zero-trust architecture applied to developer environments means more than network segmentation. It means the AI tools developers use can't exfiltrate code they weren't meant to see.
SOC 2 Type II and the Code Controls Auditors Are Now Testing
SOC 2 Type II auditors are moving beyond policy documentation to code-level evidence. Here's which Trust Services Criteria map directly to your application code and what auditors want to see.
GDPR Article 25 Is a Code-Level Requirement, Not an Architecture Diagram
Article 25 of the GDPR requires 'data protection by design and by default.' Most organizations implement this at the architecture level. Here's what it means at the code level.
Log4Shell Three Years Later: Why Unpatched Dependencies Still Dominate Enterprise Risk
CVE-2021-44228 (Log4Shell) was disclosed in December 2021 and is still being actively exploited four years on. The cause is not ignorance. It is dependency graph blindness.
CISA Secure by Design: The Shift from Compliance to Structural Safety
CISA's Secure by Design initiative argues that meeting a compliance checklist is not the same as building safe software. The alternative is structural: design that makes whole vulnerability classes impossible rather than rare.
The SOX ITGCs Auditors Actually Sample (And Where They Live in Your Code)
SOX IT General Controls (ITGCs) are designed for auditors, but many of them directly affect how software is written, reviewed, and deployed. Here's the developer's translation.
Research and findings
Citable findings, benchmarks, and original analysis from the DevSecCode Team. Each entry includes a headline number, methodology, and a ready-to-paste citation block.
Security playbook for vibe-coded apps
Based on 77+ CWE types from real-world vulnerability research. These are the exact issues AI coding agents miss, and Deva catches.
Deva vs GitHub Copilot
Both Deva and GitHub Copilot are AI coding assistants. They optimize for different audiences: Copilot is built for the broadest possible developer market with cloud-only model access, while Deva targets developers in regulated industries (healthcare, finance, defense, classified environments) where source code cannot leave the boundary and every change must map to a compliance framework.
Deva vs Snyk
Both Deva and Snyk scan code for security vulnerabilities. Snyk is a mature developer-first platform with strong SCA, container, and IaC coverage and a cloud-based scanning model. Deva is a local CLI and editor-extension scanner with AI-assisted fix generation, multi-model AI routing, and on-device operation suitable for air-gapped environments.
Deva vs Cursor
Cursor is an AI-first code editor built on VS Code. Deva is a CLI and an extension that runs in VS Code-compatible editors, including Cursor. They target overlapping audiences but optimize for different constraints: Cursor focuses on the best possible AI coding experience with cloud-based model routing, while Deva adds security scanning, compliance mapping, and on-device operation for developers in regulated industries.
Explainers, 27
OWASP A01:2025 Broken Access Control
Authorization that fails to enforce who can do what.
OWASP A02:2025 Security Misconfiguration
Insecure defaults, unnecessary features, or misapplied permissions left in production.
OWASP A03:2025 Software Supply Chain Failures
Breakdowns or malicious changes in the process of building, distributing, or updating software.
OWASP A04:2025 Cryptographic Failures
Sensitive data exposed because cryptography is missing, weak, or misused.
OWASP A05:2025 Injection
Untrusted input interpreted as code or commands by a downstream interpreter.
OWASP A06:2025 Insecure Design
Architectural decisions that create vulnerabilities no amount of clean implementation can fix.
OWASP A07:2025 Authentication Failures
Weak, missing, or improperly implemented authentication.
OWASP A08:2025 Software or Data Integrity Failures
Code or data accepted from untrusted sources without integrity verification.
OWASP A09:2025 Security Logging and Alerting Failures
Attacks succeed undetected because the application does not log enough, or no alert is raised when something is logged.
OWASP A10:2025 Mishandling of Exceptional Conditions
Programs that fail to prevent, detect, and respond to unusual situations, leading to crashes, unexpected behavior, and vulnerabilities.
CWE-22: Path Traversal
CWE-22 occurs when an application accepts user input as a file path and resolves it without restricting access to an intended directory. Attackers use sequences like ../ or absolute paths to escape the intended directory and read or write arbitrary files (typically /etc/passwd, application source code, or AWS credentials).
CWE-78: OS Command Injection
CWE-78 exists when an application passes user-controlled data to a system shell or external process without proper neutralization. The attacker injects shell metacharacters (;, &&, |, backticks) that cause the operating system to execute additional commands beyond the intended one.
CWE-79: Cross-site Scripting (XSS)
CWE-79 covers all variants of cross-site scripting: reflected, stored, and DOM-based. The weakness exists when a web application embeds user-controlled input into a page without proper neutralization. An attacker who controls the input can inject script that executes in the victim's browser session.
CWE-89: SQL Injection
CWE-89 occurs when an application constructs SQL queries by concatenating user input rather than using parameterized queries or prepared statements. An attacker who controls part of the query can modify its meaning: read arbitrary data, modify data, run administrative commands, or in the worst case execute arbitrary code via DBMS-specific features.
CWE-94: Code Injection
CWE-94 exists when an application takes user input and treats it as code that the application then executes. Unlike OS command injection (which targets a shell), code injection targets the application's own interpreter: JavaScript eval, Python exec, Ruby eval, PHP eval, or any dynamic code path that compiles or evaluates strings at runtime.
CWE-200: Sensitive Data Exposure
CWE-200 is a broad category covering any path that reveals sensitive information (credentials, tokens, internal identifiers, PII, business secrets, stack traces) to a party that should not have access. The disclosure can be active (an endpoint returns the data) or passive (a log file or cache stores it).
CWE-287: Improper Authentication
CWE-287 covers a family of weaknesses where an application fails to correctly verify the identity of an entity (user, service, device) that interacts with it. Variants include missing authentication for critical functions, broken authentication logic, weak credentials, predictable session identifiers, and authentication bypass via parameter manipulation.
CWE-306: Missing Authentication
CWE-306 exists when an application exposes a sensitive function (administrative action, configuration change, account creation, data export) without requiring authentication. Anyone who discovers the endpoint can invoke it. Distinct from CWE-287 (improper authentication, where the check exists but is broken) and CWE-862 (missing authorization, where auth passes but ownership is unchecked).
CWE-327: Broken Cryptography
CWE-327 covers the use of cryptographic algorithms that are known to be broken (DES, MD4), known to be unsuitable for the use case (MD5 for password hashing, ECB mode for encryption), or used incorrectly (predictable IVs, missing authentication on ciphertexts).
CWE-352: Cross-Site Request Forgery (CSRF)
CWE-352 occurs when a web application accepts state-changing requests from a user without verifying that the user actually intended to make the request. An attacker hosts a page that issues a request to the target site; if the victim is authenticated and the target site does not check origin, referrer, or a CSRF token, the request executes with the victim's credentials.
CWE-434: Unrestricted File Upload
CWE-434 exists when a web application accepts file uploads without restricting type, size, or storage location, allowing an attacker to upload a file that is then executed or served as a different type than expected. The classic exploitation is uploading a PHP or JSP script to a web root and requesting it to obtain remote code execution.
CWE-502: Insecure Deserialization
CWE-502 exists when an application deserializes data from an untrusted source using a deserializer that can instantiate arbitrary objects or trigger code paths during reconstruction. Many serialization formats (Python pickle, Java Serializable, PHP unserialize, .NET BinaryFormatter, Ruby Marshal) allow gadget chains that execute attacker-controlled code during deserialization.
CWE-611: XML External Entity (XXE)
CWE-611 exists when an XML parser processes documents with external entity references enabled, allowing an attacker who controls the XML input to read local files, issue HTTP requests from the server (SSRF), enumerate ports on the internal network, or cause denial of service via entity expansion attacks.
CWE-798: Hardcoded Credentials
CWE-798 exists when credentials (API keys, database passwords, signing keys, encryption keys, OAuth secrets) are embedded in source code or configuration files committed to version control. Anyone who reads the code, decompiles a binary, or accesses the version-control history obtains the credential.
CWE-862: Missing Authorization
CWE-862 exists when an application confirms a requester is authenticated but does not check that the requester is authorized to perform the specific action on the specific resource. The endpoint trusts that any authenticated user is also authorized, which fails as soon as any privileged operation or any per-user data is involved.
CWE-863: Incorrect Authorization
CWE-863 exists when an application performs an authorization check that is present but logically wrong: it verifies the wrong principal, checks the wrong resource, uses OR where AND is required, or relies on a token that the requester controls. The result is broken access control with a check that looked correct in review.
CWE-918: Server-Side Request Forgery (SSRF)
CWE-918 exists when an application fetches a URL supplied (directly or indirectly) by an attacker, without sufficient validation of the destination. An attacker uses this to probe internal services, exfiltrate cloud-metadata credentials (AWS IMDS, GCP metadata), reach databases or admin panels not exposed to the internet, or proxy traffic through the application.