Tech is political: The people under attack in Palestine 🇵🇸, Iran 🇮🇷, and Lebanon 🇱🇧 are people like us. They’re our brothers and sisters, too. Read up on their history, scrutinize what you’re told, and demand that they be respected. Hide

Frontend Dogma

“security” News Archive

Definition, related topics, and tag feed

Definition · Supertopics: user-experience · Subtopics: authentication, authorization, bot-detection, certificates, cors, cryptography, csp, csrf, hashing, malware, privacy, provenance, randomness, rate-limiting, sanitization, ssh, ssl, tls, validation, vulnerabilities, xss (non-exhaustive) · “security” RSS feed (per email)

Entry (Sources) and Additional TopicsDate#
npm Install-Time Security and GAT bypass2fa Deprecation567
npm, deprecation
You Shouldn’t Trust Trusted Publishing (yos)566
authentication
npm Adds Preventive Account Protection for High-Impact Accounts565
npm
Ignore DNSSEC if You Like MITM Attacks564
dns
Anthropic’s Fable and the State of AI (sch)563
ai, anthropic, foss
Blocking Install Scripts Is Not a Silver Bullet (uli/nod)562
npm
Reuse Less Software561
dependencies, processes
Wednesday, June 17, 2026 Security Releases (nod)560
release-notes, nodejs
Upcoming Breaking Changes for npm v12559
npm
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders (sar/soc)558
npm, bugs
The Website Specification (joo)557
websites, documentation, fundamentals, seo, accessibility, ai-agents, performance, privacy, resilience, internationalization
The VibeSec Reckoning (mfo)556
ai, vibe-coding
Megalodon: Mass GitHub Repo Backdooring via CI Workflows555
github, ci-cd
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension (the)554
github, vs-code, microsoft
GitHub Hacked—Internal Source Code Repositories Compromised via Employee Device553
github
Mini Shai Hulud: Compromised @antv npm Packages Enable CI/CD Credential Theft552
npm, dependencies, ci-cd
Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised551
npm, dependencies
“The Worst Leak That I’ve Witnessed”: US Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub (giz)550
passwords, github
A Worm Just Ate Its Way Through the npm Registry… (fir)549
videos, npm, dependencies, tanstack
Hardening TanStack After the npm Compromise (cru+/tan)548
tanstack
Hackers Abuse Google Ads and Claude.ai Shared Chats to Distribute macOS Malware547
apple, unix-like, google, claude, anthropic, ai
Weekend at Bernie’s (and)546
dependencies, foss, metrics
Behind the Scenes Hardening Firefox With Claude Mythos Preview (fre+/moz)545
firefox, mozilla, browsers, claude, anthropic, ai
Trustworthy JavaScript for the Open Web (moz)544
javascript, open-web, firefox, mozilla, browsers
The Zero-Days Are Numbered (moz)543
firefox, mozilla, browsers, ai, anthropic
Vercel April 2026 Security Incident542
vercel
AI Will Never Be Ethical or Safe (j9t)541
ai, ethics
No One Owes You Supply-Chain Security (pur)540
dependencies, rust
Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them539
wordpress, plugins
Anthropic Debuts Preview of Powerful New AI Model Mythos in New Cybersecurity Initiative (tec)538
anthropic, ai
Adversarial AI: Understanding the Threats to Modern AI Systems (jet)537
ai, concepts
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign (sar/soc)536
nodejs, foss
Post Mortem: Axios npm Supply Chain Compromise535
axios, npm
The Hidden Blast Radius of the Axios Compromise (ahm/soc)534
dependencies, npm, axios
Minimum Release Age Is an Underrated Supply Chain Defense (dan)533
dependencies, npm, bun, pnpm, yarn, deno, renovate, dependabot, axios
Prevent Claude Code From Accessing .env (jad)532
claude, anthropic, ai, environments
Axios Compromised on npm—Malicious Versions Drop Remote Access Trojan531
npm, dependencies, axios
Node.js Brotli UAF (mai)530
nodejs, permissions, brotli, compression, claude, ai
Malicious PyPI Package—LiteLLM Supply Chain Compromise529
dependencies, vulnerabilities
Developing a Minimally HashDoS Resistant, Yet Quickly Reversible Integer Hash for V8 (joy/nod)528
nodejs, hashing
Tuesday, March 24, 2026 Security Releases (nod)527
release-notes, nodejs
Supply-Chain Attack Using Invisible Code Hits GitHub and Other Repositories (dan/ars)526
github, dependencies
OWASP’s Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed525
videos, vulnerabilities, ai, owasp
A GitHub Issue Title Compromised 4,000 Developer Machines524
github, ai
How to Steal npm Publish Tokens by Opening GitHub Issues (nec)523
npm, github, ai
MCP Servers and the Return of the Service Account Problem (aem)522
servers, mcp, ai
Security Advisory: Addressing Recent Vulnerabilities in Angular (ang)521
angular
An Exploit… in CSS?! (css)520
css
Goodbye “innerHTML”, Hello “setHTML”: Stronger XSS Protection in Firefox 148 (moz)519
javascript, methods, xss, firefox, mozilla, browsers
Europe Is Ready to Ditch US Tech for Private Alternatives (pro)518
tooling, privacy, metrics
WebSocket Penetration Testing: A Complete Guide to CSWSH517
guides, websockets, testing
Node.js Path Traversal: Prevention and Security Guide (loi)516
guides, nodejs
Cryptography Usage in Web Standards (w3c)515
standards, cryptography
OpenJS Foundation Security Program: Annual Report 2025 (ope)514
openjs
A Security Checklist for Your React and Next.js Apps513
react, nextjs
How to Implement Rate Limiting in nginx (naw/one)512
how-tos, servers, nginx, rate-limiting
Securing npm Is Table Stakes (nza+/cha)511
podcasts, interviews, npm, ai
Security (vik+/htt)510
web-almanac, studies, research, metrics, tls, certificates, cookies, csp, http-headers, apis, sanitization, configuration
Node.js January 2026 Security Release: What Changed and Why It Matters (nod)509
nodejs
Tuesday, January 13, 2026 Security Releases (nod)508
release-notes, nodejs
Mitigating Denial-of-Service Vulnerability From Unrecoverable Stack Space Exhaustion for React, Next.js, and APM Users (mco+/nod)507
nodejs, vulnerabilities, react, nextjs, tooling, monitoring, performance
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens (sar/soc)506
npm, dependencies, github
Security Basics for Vibe-Coders (owe/pro)505
fundamentals, vibe-coding, ai
Testing Methods: Accessible Authentication (Enhanced) (dec)504
accessibility, testing, wcag, authentication
Testing Methods: Accessible Authentication (Minimum) (dec)503
accessibility, testing, wcag, authentication
Denial of Service and Source Code Exposure in React Server Components (rea)502
react, components
Thursday, December 18, 2025 Security Releases (nod)501
release-notes, nodejs
How We’re Protecting Our Newsroom From npm Supply Chain Attacks (rya/pnp)500
npm, dependencies, case-studies
No More Tokens—Locking Down npm Publish Workflows (zac)499
npm, dependencies, github, processes
[Next.js] Security Advisory: CVE-2025-66478 (seb)498
nextjs
Critical Security Vulnerability in React Server Components (rea)497
react, components
Decreasing [Let’s Encrypt] Certificate Lifetimes to 45 Days (mat/let)496
http, certificates, lets-encrypt
Taking Down Next.js Servers for 0.0001 Cents a Pop495
servers, nextjs, vulnerabilities
The Shai-Hulud 2.0 npm Worm: Analysis, and What You Need to Know494
npm, dependencies
GitLab Discovers Widespread npm Supply Chain Attack (git)493
npm, dependencies, gitlab, github, aws, gcp, azure
Automated npm Secret Rotation in GitHub Actions (mhe)492
npm, automation, github-actions
What Developers Really Mean by “Bad Code” (jet)491
maintainability, scalability, consistency, quality
Introducing the OWASP Top 10:2025 (she+/owa)490
introductions, owasp, vulnerabilities
Removing XSLT for a More Secure Browser (dro)489
chromium, chrome, google, browsers, xsl, web-platform
Will npm’s New Security Steps Stop Attacks? (rev)488
npm, github, maintenance, foss
HTTPS by Default (jde+)487
http, chrome, google, browsers
Agentic AI and Security (ksi/mfo)486
ai, architecture
Octoverse: A New Developer Joins GitHub Every Second as AI Leads TypeScript to #1485
github, metrics, productivity, ai, foss, programming
Glassworm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace484
code-editors, vs-code, microsoft
Improving the Trustworthiness of JavaScript on the Web483
javascript, web-apps
Past Time for Passkeys (nor)482
videos, passkeys, passwords, authentication
Secure Coding in JavaScript481
javascript, frameworks
My Conclusions After Using Signed Exchanges on My Website for 2 Years (paw)480
signed-exchanges, performance
Lazy-Loading as a Security Measure479
lazy-loading, angular, react
Backend Concepts Every Experienced Developers Must Know478
concepts, network, concurrency, apis, databases, caching, scalability, observability, architecture
Fixing Safari Mixed Content Issues With Vite and mkcert477
safari, apple, browsers, vite, tooling
How Deno Protects Against npm Exploits (den)476
deno, npm
Strengthening npm Security: Important Changes to Authentication and Token Management475
npm
How Hackers Use AI to Find Vulnerabilities Faster474
ai
CAPTCHA, When Security Takes Precedence Over Accessibility473
captcha, accessibility
Our Plan for a More Secure npm Supply Chain (xco)472
npm, dependencies, foss
npm Security Best Practices471
npm, provenance, best-practices
This May Be the Worst One (the)470
videos, npm, dependencies
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages (pvd+/soc)469
npm, dependencies
ctrl/tinycolor and 40+ npm Packages Compromised468
npm, dependencies
How Maintainer Burnout Is Causing a Kubernetes Security Disaster467
kubernetes, maintenance, foss, economics
Oh No, Not Again… a Meditation on npm Supply Chain Attacks (tan)466
npm, dependencies, microsoft
Anatomy of a Billion-Download npm Supply-Chain Attack465
npm, dependencies
npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack (bur+/soc)464
npm, dependencies
CORS Explained: Stop Struggling With Cross-Origin Errors463
cors, http-headers, http
How OpenJS-Hosted Projects Benefit From Security Support (ope)462
openjs, hosting, foss
Why You Absolutely Need to Have Automated Dependency Management in Place (j9t)461
dependencies, maintainability, maintenance, automation, tooling
What Your Website’s Style Says About You—and How Hackers Can Use It Against You (err)460
css, javascript
Hardening Node.js Apps in Production: 8 Layers of Practical Security459
nodejs, best-practices
eslint-config-prettier Compromised: How npm Package With 30 Million Downloads Spread Malware458
prettier, eslint, npm, malware
npm Phishing Email Targets Developers With Typosquatted Domain (sar/soc)457
npm
AI Agents Are Creating a New Security Nightmare for Enterprises and Startups456
ai, apis
Tuesday, July 15, 2025 Security Releases (nod)455
release-notes, nodejs
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader (soc)454
npm, dependencies
Dependabot Supports Configuration of a Minimum Package Age453
dependabot, configuration
MCP Security Vulnerabilities and Attack Vectors452
mcp, ai
A New Era of Code Quality451
quality
JWTs Are Not Session Tokens, Stop Using Them Like One450
json-web-tokens, authentication
Design Patterns for Securing LLM Agents Against Prompt Injections (sim)449
studies, research, ai, prompting, software-design-patterns
The Growing Risk of Malicious Browser Extensions (soc)448
browser-extensions
Escaping “<” and “>” in Attributes—How It Helps Protect Against Mutation XSS (sec)447
html, attributes, xss, escaping, chrome, google, browsers
HTML Spec Change: Escaping “<” and “>” in Attributes (sec)446
html, attributes, escaping, xss
Beware of End-of-Life Node.js Versions—Upgrade or Seek Post-EOL Support (mco/nod)445
nodejs, maintenance
How to Access Local MCP Servers Through a Secure Tunnel444
how-tos, mcp, ai, servers, network
Docker Launches Hardened Images, Intensifying Secure Container Market443
docker
Modernizing Security442
modernization, processes
Securing Your Node.js App From Command Injection441
nodejs
Passkeys for Normal People (tro)440
authentication, passkeys, examples, concepts
npm Targeted by Malware Campaign Mimicking Familiar Library Names (soc)439
npm, malware, dependencies, link-lists
What Is an Encryption Backdoor? (int)438
encryption, vulnerabilities, concepts
Cybersecurity Leaders Are Staying in the Shadows (ste)437
community, culture
Principles for Coding Securely With LLMs (sea)436
ai, principles
Threat Actors Misuse Node.js to Deliver Malware and Other Malicious Payloads435
nodejs, malware
TLS Certificate Lifetimes Will Officially Reduce to 47 Days434
tls, certificates
LLMs Can’t Stop Making Up Software Dependencies and Sabotaging Everything (tho/the)433
ai, dependencies, slop
Secure a Vue App With OpenID Connect and the BFF Pattern (due)432
vuejs, authentication, backend-for-frontend
Teaching Code in the AI Era: Why Fundamentals Still Matter (ali)431
training, ai, programming, vibe-coding, scalability, performance, quality, testing, documentation
Stop Using Jenkins in 2025 (oso)430
jenkins, github-actions, ci-cd
Node.js Test CI Security Incident (nod)429
nodejs, retrospectives
Website Hijack Campaign Now Impacting 150,000 Sites (gad)428
Malware Found on npm Infecting Local Package With Reverse Shell (rev)427
npm, dependencies
Five Things Vibe Coders Should Know (From a Software Engineer)426
vibe-coding, sanitization, rate-limiting
GitHub Suffers a Cascading Supply Chain Attack Compromising CI/CD Secrets (inf)425
github, ci-cd
How to Prevent WordPress SQL Injection Attacks (sma)424
how-tos, wordpress, sql, databases
Lazarus Strikes npm Again With New Wave of Malicious Packages (soc)423
npm, dependencies
Updates on CVE for End-of-Life Versions (raf/nod)422
nodejs
What Is the OWASP Top 10 and How Can Your Team Benchmark Security? (jet)421
owasp, vulnerabilities, qodana, jetbrains
How to Protect Your Web Applications From XSS (tor/w3c)420
how-tos, web-apps, xss
In Tech, What Matters and What Is Dangerous (ham)419
community, foss, open-web
Secure UX: Building Cybersecurity and Privacy Into the UX Lifecycle (uxm)418
user-experience, processes
The Fallacy of Balance: Challenging the Notion of Security and Accessibility as Opposing Objectives (deq)417
videos, accessibility
It Is No Longer Safe to Move Our Governments and Societies to US Clouds (ber)416
cloud-computing, privacy, legal
How OWASP Helps You Secure Your Full-Stack Web Applications (eri/sma)415
owasp, monitoring, authentication, vulnerabilities, configuration, csrf, cryptography, authorization
10 Common Web Development Mistakes to Avoid Right Now414
mistakes, mobile, performance, accessibility, seo, navigation, analytics, testing
Tightening Every Bolt (bag)413
videos, processes, code-reviews, testing
On Generative AI Security (sch)412
ai, lessons, microsoft
Understanding CORS Errors in Signed Exchanges (paw)411
cors, errors, signed-exchanges
Keep Your Node.js Apps Secure With “npx is-my-node-vulnerable” (tre)410
packages, npm, nodejs
How I Open-Sourced My Secret Access Tokens From GitHub, Slack, and npm—and Who Actually Cares409
github, slack, npm
Node.js EOL Versions CVE Dubbed the “Worst CVE of the Year” by Security Experts (sar/soc)408
nodejs, documentation
Tuesday, January 21, 2025 Security Releases (raf/nod)407
release-notes, nodejs
APIs Are Quickly Becoming the Latest Security Battleground (and Nightmare)406
apis
CDN-First Is No Longer a Performance Feature (osv)405
content-delivery, performance, caching, embed-code, privacy
The Cyber-Cleanse: Take Back Your Digital Footprint (cyb)404
privacy
15 Principles for Secure Programming (rak)403
principles, validation, testing
Important Topics for Frontend Developers to Master in 2025402
learning, javascript, typescript, css, frameworks, git, apis, testing, performance, ci-cd, websockets
How to Automate OWASP Security Reviews in Your Pull Requests? (cod)401
how-tos, owasp, automation, code-reviews, coderabbit
Developer Guide: How to Implement Passkeys400
guides, how-tos, authentication, passkeys
5 Technical Trends to Help Web Developers Stand Out in 2025399
trends, career, javascript, ai, low-and-no-code
Avoid Hotlinking Images With “Cross-Origin-Resource-Policy”398
images
Content Security Policy Level 3 (mik/w3c)397
standards, csp
Security (htt)396
web-almanac, studies, research, metrics
JavaScript Import Attributes (ES2025) (tre)395
javascript
Exploring Internet Traffic Shifts and Cyber Attacks During the 2024 US Election394
traffic
Cross-Site WebSocket Hijacking: Understanding and Exploiting CSWSH (pen)393
websockets
Securing Your Express REST API With Passport.js392
nodejs, express, json-web-tokens, apis, rest, tooling
SecretLint—a Linter for Preventing Committing Credentials (tre)391
tooling, linting
The Importance of UX in Cybersecurity (uxm)390
user-experience, usability
Understanding “npm audit” and Fixing Vulnerabilities389
npm, vulnerabilities, nodejs
Top 4 Web Vulnerabilities With Example and Mitigation388
vulnerabilities, sql, databases, xss, csrf
How to Implement Content Security Policy (CSP) Headers for Astro (tre)387
how-tos, http, http-headers, csp, astro, vercel, cloudflare
Why Code Security Matters—Even in Hardened Environments386
vulnerabilities, file-handling, nodejs
Database 101: SSL/TLS for Beginners385
introductions, databases, ssl, tls, authentication
Cloudflare Study: 39% of Companies Losing Control of Their IT and Security Environment (tre)384
studies, research, engineering-management
NIST Recommends Some Common-Sense Password Rules (sch)383
passwords, guidelines
I Finally Understand OAuth382
authorization, oauth, processes
Fake GitHub Site Targeting Developers (jul/san)381
github
Hacking Cars in JavaScript (Running Replay Attacks in the Browser With the HackRF) (dev)380
javascript
Gaining Access to Anyone’s Browser Without Them Even Visiting a Website379
arc, the-browser-company, browsers, vulnerabilities
10 AI Dangers and Risks and How to Manage Them (rin)378
ai, privacy, sustainability, legal
Web Security: Shaping the Secure Web (set/w3c)377
web, w3c
5 Wasm Use Cases for Frontend Development (ele/des)376
guest-posts, webassembly, performance
What Is Incident Response?375
incident-response, overviews
The Great npm Garbage Patch374
dependencies, npm, spam
Migrating From Netlify to Cloudflare for AI Bot Protection (sia)373
migrating, netlify, cloudflare, bots, ai
Frontend Security Checklist (tre)372
checklists, react
Automated Ways to Security Audit Your Website371
auditing, automation, tooling
Secure Node.js Applications From Supply Chain Attacks370
nodejs, best-practices, dependencies
The Cloud Run Security Gap You Didn’t Know You Had (and How to Fix It)369
google, gcp
The Pitfalls of In-App Browsers (fro)368
browsers, mobile, privacy, user-experience
Supply Chain Security in npm—We Can Be Optimistic About the Future367
npm, dependencies, provenance
Script Integrity (chr/fro)366
embed-code, javascript
Introducing the MDN HTTP Observatory (mdn)365
introductions, mdn, mozilla, http
Tuesday, July 2, 2024 Security Releases (nod)364
release-notes, nodejs
WebAuthn: Enhancing Security With Minimal Effort (tbe)363
authentication, webauthn
RegreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH Server362
ssh, vulnerabilities
Polyfill Supply Chain Attack Embeds Malware in JavaScript CDN Assets361
malware, vulnerabilities
Catching Compromised Cookies (sla)360
cookies, testing
Backdoor Slipped Into Multiple WordPress Plugins in Ongoing Supply-Chain Attack (dan/ars)359
wordpress, plugins
The Hacking of Culture and the Creation of Socio-Technical Debt (sch)358
culture
OAuth Authentication (rya)357
authentication, authorization, oauth
Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks (sar/soc)356
npm, dependencies, vulnerabilities, caching
What Is Mixed Content? (fre)355
http
The Ultimate Guide to Iframes (log)354
guides, iframes, html, javascript
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem353
javascript, npm, dependencies, caching, vulnerabilities
JavaScript Security: Simple Practices to Secure Your Frontend352
javascript, dependencies, csp
Manifesto for a Humane Web (mic)351
websites, manifestos, web, principles, accessibility, dei, sustainability, user-experience
Securing Client-Side JavaScript (ada)350
javascript, graceful-degradation
Poor Express Authentication Patterns in Node.js and How to Avoid Them349
express, nodejs, authentication
Passkeys: A Shattered Dream (fir)348
authentication, passkeys
Using Legitimate GitHub URLs for Malware (sch)347
malware, github
When Security and Accessibility Clash: Why Are Banking Applications So Inaccessible? (nic)346
accessibility
Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects (ope)345
foss, openjs
Wednesday, April 10, 2024 Security Releases (raf/nod)344
release-notes, nodejs
Node.js Secure Coding: Mitigate and Weaponize Code Injection Vulnerabilities343
books, nodejs, vulnerabilities
The Free Software Commons (jen)342
foss, community
The V8 Sandbox341
v8
Wednesday, April 3, 2024 Security Releases (nod)340
release-notes, nodejs
Using JSON Web Tokens With Node.js339
json-web-tokens, nodejs, authentication
Building a Digital Fortress: How to Strengthen DNS Against DDoS Attacks?338
dns
In-App Browsers Are Still a Privacy, Security, and Choice Problem (tho/the)337
browsers, mobile, privacy
How Does Single Sign-On (SSO) Work? (mil)336
authentication
CORS Finally Explained—Simply335
csrf, cors, concepts
How npm Install Scripts Can Be Weaponized: A Real-World Example of a Harmful npm Package (eth)334
npm, dependencies, examples
Preventing SQL Injection Attacks in Node.js333
nodejs, databases, sql
Frontend Application Security: Tips and Tricks332
web-apps, xss, csrf, authentication, dependencies, csp, validation, tips-and-tricks
Wednesday, February 14, 2024 Security Releases (raf+/nod)331
release-notes, nodejs
How to Boost WordPress Security and Protect Your SEO Ranking330
how-tos, wordpress, seo
Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data Theft (sar/soc)329
npm, dependencies
Practice Safe DSD With “setHTMLUnsafe” (It’s Complicated) (jar/van)328
html, dom, shadow-dom, apis
Tuesday, February 6, 2024 Security Releases (raf/nod)327
release-notes, nodejs
JWT vs. Session Authentication326
authentication, json-web-tokens, comparisons
GitHub, npm Registry Abused to Host SSH Key-Stealing Malware325
github, npm, malware, foss
Navigating JavaScript Security: Recompiling Firefox to Bypass Anti-Debugger Techniques (gli)324
javascript, debugging, firefox, mozilla, browsers
Deceptive Deprecation: The Truth About npm Deprecated Packages323
deprecation, npm, dependencies, research
Safely Accessing the DOM With Angular SSR322
dom, javascript, angular, server-side-rendering
Node.js Security Progress Report—Progress on Permission Model, Fuzzer, and Connections With Community (ope)321
nodejs
I Hate CORS320
videos, cors
Secure Your Code: Auto-Fix Vulnerabilities With Dependabot (GitHub Tutorial)319
videos, dependencies, dependabot
Building Multiple Progressive Web Apps on the Same Domain318
videos, web-apps, progressive-web-apps, architecture
Session-Based vs. Token-Based Authentication: Which Is Better?317
authentication, json-web-tokens, comparisons
10 Best Practices for Secure Code Review of Node.js Code316
best-practices, code-reviews, nodejs
Security Headers Using “<meta>” (sap/mat)315
csp, html
Blind CSS Exfiltration: Exfiltrate Unknown Web Pages314
css
Mastering Cryptography Fundamentals With Node’s “crypto” Module313
cryptography, nodejs
Secure Code Review Tips to Defend Against Vulnerable Node.js Code312
nodejs, code-reviews
Understanding CORS311
cors
What the !#@% Is a Passkey? (eff)310
passkeys
Secret Scanning Scans Public npm Packages309
github, npm, dependencies
Local HTTPS for Next.js 13.5 (ami)308
testing, http, nextjs
Understanding XSS Attacks307
xss
A Comprehensive Guide to the Dangers of Regular Expressions in JavaScript (phi)306
guides, javascript, regex
SSH Keys Stolen by Stream of Malicious PyPI and npm Packages (ble)305
ssh, dependencies, npm
Best Practices for Securing Node.js Applications in Production304
best-practices, nodejs
npm Provenance General Availability303
github, npm, provenance
The WebP 0-Day302
webp, google, apple
Open Source Trends to Look for in 2024301
foss, trends, outlooks, ai
Securing Your Node.js Apps by Analyzing Real-World Command Injection Examples300
nodejs, history, examples
How to Implement SSL/TLS Pinning in Node.js299
how-tos, ssl, tls, nodejs
A More Intelligent and Secure Web (ple/w3c)298
videos, w3c, standards, web, web-platform
Demystifying CORS: Understanding How Cross-Origin Resource Sharing Works297
cors, javascript
Towards HTTPS by Default (jde)296
browsers, google, chrome, http, tls
Sophisticated, Highly-Targeted Attacks Continue to Plague npm295
npm
An Update on Chrome Security Updates—Shipping Security Fixes to You Faster294
browsers, google, chrome
Tuesday, August 8, 2023 Security Releases (raf/nod)293
release-notes, nodejs
SECURITY.md: Should I Have It? (mry/ecl)292
documentation
Publishing With npm Provenance From Private Source Repositories Is No Longer Supported291
github, npm, provenance, foss
Social Engineering Campaign Targeting Tech Employees Spreading Through npm Malware (soc)290
malware, npm
Securing the Web Forward: Addressing Developer Concerns in Web Security (tor/w3c)289
web, surveys
User Input Sanitization and Validation: Securing Your App288
sanitization, validation, conformance
Encoding: A Brief History and Its Role in Cybersecurity287
encoding, unicode, history
Node.js Security Progress Report—17 Reports Closed (ope)286
nodejs
The Importance of Verifying Webhook Signatures285
webhooks
The Massive Bug at the Heart of the npm Ecosystem284
npm, dependencies, bugs
Understanding Authorization Before Authentication: Enhancing Web API Security283
authorization, authentication, apis, comparisons
An Introduction to Command Injection Vulnerabilities in Node.js and JavaScript282
introductions, vulnerabilities, nodejs, javascript
All You Need to Know About CORS and CORS Errors281
cors, errors
Django: A Security Improvement Coming to “format_html()” (ada)280
django, html
Tuesday, June 20, 2023 Security Releases (raf/nod)279
release-notes, nodejs
security.txt Now Mandatory for Dutch Government Websites278
legal
File Upload Security and Malware Protection (aus)277
malware, file-handling, edge-computing
Security Implications of HTTP Response Headers276
http, http-headers
The Case Against Automatic Dependency Updates (ben)275
dependencies, automation, ci-cd, maintenance
Automating Dependency Updates: The Big Debate274
dependencies, automation, ci-cd
Introducing npm Package Provenance273
introductions, github, npm, provenance, foss
Generating Provenance Statements272
npm, provenance
8 Best Tools for Cryptography and Encryption (sta)271
link-lists, tooling, comparisons, cryptography, encryption, privacy
Dissecting npm Malware: Five Packages and Their Evil Install Scripts270
npm, malware
Passkeys: What the Heck and Why? (css)269
passkeys
Senior Engineering Strategies for Advanced React and TypeScript (tec)268
strategies, react, typescript, architecture, testing, performance, accessibility, maintenance
Cryptographically Protecting Your SPA267
single-page-apps, cryptography
Tips for Handling Dependabot, CodeQL, and Secret Scanning Alerts266
alerting, dependabot, tips-and-tricks
Without Accessibility, There Is No Privacy or Security (lev)265
accessibility, privacy
How to Password-Protect a Static HTML Page With No JS (ede)264
how-tos, css, fonts
SSL Certificates Explained263
videos, certificates, ssl, protocols
Quick Tip: How to Hash a Password in PHP262
how-tos, php, passwords, tips-and-tricks
Sandboxing JavaScript Code261
javascript
Avoiding the Success Trap: Toward Policy for Open-Source Software as Infrastructure (atl)260
foss, infrastructure, policies, concepts
Unlocking Security Updates for Transitive Dependencies With npm259
npm, dependencies, maintenance
7 Required Steps to Secure Your Iframes Security258
iframes, xss, html, http-headers, csp
Conditional API Responses for JavaScript vs. HTML Forms (aus)257
javascript, html, forms, comparisons
Why Do We Need Authorization and Authentication?256
authorization, authentication
The Top 10 Security Vulnerabilities for Web Applications255
vulnerabilities, web-apps
Leaked a Secret? Check Your GitHub Alerts… for Free254
github
DOM Clobbering (fre/mat)253
dom
New npm Features for Secure Publishing and Safe Consumption252
npm, dependencies
Using SRI to Protect From Malicious JavaScript (mat)251
javascript
WordPress Versions 3.7–4.0 No Longer Get Security Updates (sar)250
wordpress
“Not Secure” Warning for IE Mode249
browsers, microsoft, edge, internet-explorer
Node.js Security Best Practices (nod)248
nodejs, best-practices
npm Security: Preventing Supply Chain Attacks247
npm, dependencies
Secure JavaScript URL Validation246
javascript, validation, urls
Create a Passkey for Passwordless Logins (age)245
authentication, passkeys
Designing a Secure API244
software-design, apis
Phylum Detects Active Typosquatting Campaign Targeting npm Developers243
npm, dependencies
Security (htt)242
web-almanac, studies, research, metrics
Continue Using .env Files as Usual241
environments
Quick Reminder: HTML5 “required” and “pattern” Are Not a Security Feature (cod)240
html, forms
Stop Using .env Files Now239
environments
Debunking Myths About HTTPS238
http, myths
Secure Your Node.js App With JSON Web Tokens (app)237
nodejs, json-web-tokens
Dependabot Unlocks Transitive Dependencies for npm Projects236
dependencies, npm, dependabot
JavaScript Bugs Aplenty in Node.js Ecosystem—Found Automatically235
studies, research, nodejs, javascript, dependencies, quality, bugs
Introducing Even More Security Enhancements to npm234
introductions, npm
Top 5 npm Vulnerability Scanners233
npm, vulnerabilities, tooling
What Is Passwordless Authentication and How to Implement It232
authentication, passwords
GA4 Is Being Blocked by Content Security Policy231
csp, metrics, google
Please Remove That .git Folder230
git
Should I Have Separate GitHub Accounts for Personal and Professional Projects?229
discussions, github, career
Understanding CSRF Attacks (zel)228
csrf
npm Security Update: Attack Campaign Using Stolen OAuth Tokens227
oauth, version-control, npm, github
Snyk Finds 200+ Malicious npm Packages, Including Cobalt Strike Dependency Confusion Attacks226
javascript, npm, dependencies
Unexpectedly HTTPS?225
http
How to Respond to Growing Supply Chain Security Risks?224
how-tos, dependencies, nodejs, npm
The Web Is for Everyone: Our Vision for the Evolution of the Web (moz)223
web, outlooks, privacy, accessibility, performance, user-experience
Using HTTPS in Your Development Environment222
http, environments
How to Prevent SQL Injection Attacks in Node.js221
how-tos, nodejs, databases, sql
Can You Get Pwned With CSS?220
css
How to Fix Your Security Vulnerabilities With npm Override219
how-tos, vulnerabilities, npm, dependencies
Never, Ever, Ever Use Pixelation for Redacting Text218
content, images, obfuscation
Accessibly Insecure217
accessibility
Lessons Learned From Publishing a Content Security Policy216
lessons, csp
Ain’t No Party Like a Third Party (ada/css)215
dependencies, embed-code
Security (htt)214
web-almanac, studies, research, metrics
GitHub’s Commitment to npm Ecosystem Security213
github, npm
Understanding and Implementing OAuth2 in Node.js (hon)212
nodejs, authorization, oauth
How to Win at CORS (jaf)211
how-tos, cors, html, http
The Options for Password-Revealing Inputs (chr/css)210
html, css, passwords, usability
npm Security Best Practices (owa)209
npm, best-practices
Encoding Data for POST Requests (jaf)208
javascript, encoding
NPM Global Audit207
packages, npm, quality, auditing
Understanding and Preventing Common Security Vulnerabilities206
vulnerabilities
Open Source Insights205
websites, foss, dependencies, licensing
I Learned to Love the Same-Origin Policy (eee/css)204
cors
Is Edge Computing Secure? Here Are 4 Security Risks to Be Aware Of203
edge-computing
TLS and mTLS Demystified202
tls, protocols
Best Practices for Inclusive Textual Websites201
performance, accessibility, best-practices
Clickjacking Attacks and How to Prevent Them200
how-tos
How to Safely Use GitHub Actions in Organizations (nza)199
how-tos, github-actions
What Is mTLS and How Does It Work?198
Mutual TLS: Stuff You Should Know197
tls, protocols
Don’t Try to Sanitize Input—Escape Output196
sanitization, escaping
Encrypting DNS Query Bad for Performance? (erw)195
performance, dns, http, encryption
Apple Joins FIDO Alliance, Commits to Getting Rid of Passwords (zdn)194
apple, fido, passwords, authentication
How to Automatically Update Your JavaScript Dependencies (spa/clo)193
how-tos, javascript, dependencies, automation, processes
What SSL Is, and Which Certificate Type Is Right for You192
ssl, certificates, privacy, concepts
Usability and Security; Better Together (24w)191
usability, user-experience
Server-Side Includes (SSI) Injection (owa)190
ssi
How Internet Security Works: TLS, SSL, and CA (osd)189
tls, ssl, protocols, certificates
Security and Privacy for Our Times (luk/w3c)188
privacy, web-platform
Web Feature Developers Told to Dial Up Attention on Privacy and Security (rip/tec)187
w3c, privacy, web-platform
CSS Security Vulnerabilities (chr/css)186
css, privacy, vulnerabilities
Understanding Subresource Integrity (dre/sma)185
hashing, embed-code
W3C Strategic Highlights: Web for All (Security, Privacy, Identity) (w3c)184
w3c, privacy, authentication
Guide to Web Authentication183
websites, authentication, webauthn, javascript
It’s Beginning to Look a Lot Like XSSmas (24w)182
vulnerabilities, csrf, xss
Protecting Your Site With Feature Policy (rac/sma)181
http-headers, http
AWS Security Guide: 7 Best Practices to Avoid Security Risks (wom)180
guides, aws, best-practices
WebAuthn, FIDO2 Infuse Browsers, Platforms With Strong Authentication (dar)179
w3c, fido, authentication, webauthn, browsers
In Your Face, Passwords: Big Three Browsers All Adopt Authentication API178
authentication, webauthn, apis, edge, microsoft, chrome, google, firefox, mozilla, browsers
HTTPS Is Easy (tro)177
websites, http
WordPress Security as a Process (sma)176
wordpress, processes
Making Your Website Faster and Safer With Cloudflare175
performance, caching, cloudflare
Validating Dependencies in the Project With npm-check and depcheck174
dependencies, maintenance, auditing, tooling, npm
Third Party CSS Is Not Safe (jaf)173
html, css, embed-code
Attackers Can Steal Sensitive Data by Abusing CSS—CSS Exfil Vulnerability172
css, csp
Building Secure JavaScript Applications171
javascript, xss, csrf, json-web-tokens, passwords
Creating Secure Password Resets With JSON Web Tokens (sma)170
passwords, json-web-tokens, nodejs
The Complete Guide to Switching From HTTP to HTTPS (sma)169
guides, http
Rate Limiting With nginx168
servers, nginx, rate-limiting
How (Not) to Control Your CDN (mno)167
content-delivery, caching, http
How to Secure WordPress With SSL166
how-tos, wordpress, ssl
Encrypting IP Addresses (ber)165
ip, network, privacy, encryption
How to Secure Your Web App With HTTP Headers (sma)164
how-tos, web-apps, http, http-headers, csp
Just Another HTTPS Nudge (chr/css)163
http
On EME in HTML5 (tim/w3c)162
eme, drm, html, legal, standards, w3c
What Is HTTPS and SSL, and Why Your Ecommerce Website Badly Needs Them Both161
http, ssl, ecommerce
Using SSH Securely (ann)160
ssh
More Than 300 Federal Gov Websites Fail to Meet Domain Encryption Deadline159
http, tls, protocols, encryption
Content Security Policy Level 2 (mik+/w3c)158
standards, csp
A Checklist for Website Reviews (hcr)157
checklists, performance, browsers, seo, accessibility
Content Security Policy, Your Future Best Friend (sma)156
csp, link-lists
A Refined Content Security Policy (web)155
html, csp, webkit, safari, apple, browsers
The Performance Benefits of “rel=noopener” (jaf)154
html, links, performance
Web Platform Security Boundaries (ann)153
web-platform
Subresource Integrity (dev+/w3c)152
hashing, html, standards
npm Fails to Restrict the Actions of Malicious npm Packages151
npm, vulnerabilities
W3C Looks to Secure the Web (sdt)150
w3c, authentication
Distribution Packages Considered Insecure149
dependencies, unix-like
The Current State of Web Security (An Interview With Anselm Hannemann) (hel+/css)148
interviews, http, ssl, tls, encryption, cloudflare, lets-encrypt
Eliminating Known Vulnerabilities With Snyk (sma)147
vulnerabilities, tooling
10 Web Predictions for 2016 (cra)146
web, outlooks, site-generators, browsers, css, mobile, performance, webassembly, seo
HSTS and “Let’s Encrypt” (tka)145
http, http-headers, ssl, lets-encrypt
Indexing HTTPS Pages by Default144
google, search, http
An in-Depth Look at CORS143
cors, javascript, php
Why Passwordless Authentication Works (cra)142
authentication, passwords
Introduction to TLS and SSL (ope)141
introductions, tls, ssl, protocols, certificates
A Simple Developer Error Is Exposing Private Information on Thousands of Websites (owe)140
version-control, git, mistakes, vulnerabilities
More Tips to Further Secure WordPress (eli)139
wordpress, tips-and-tricks, plugins
Improving Web Security With the Content Security Policy138
csp, http
Deprecating HTTP137
http, protocols, deprecation
Mozilla Wants to Deprecate Non-Secure HTTP, Will Make Proposals to W3C “Soon” (epr/ven)136
mozilla, http, deprecation
Want Fancy Firefox Features? Secure Your Website (sts/cne)135
firefox, mozilla, browsers, http
WordPress Front End Security: CSRF and Nonces (css)134
wordpress, csrf
Introduction to WordPress Front End Security: Escaping the Things (css)133
introductions, wordpress, escaping
What Are the Security Risks of HTML5 Apps?132
web-apps, sanitization
Moving to HTTPS on WordPress (chr/css)131
wordpress, http
Same-Origin Policy (ann)130
cors, web-platform
Securing the Web (w3c)129
web-platform
What I’d Tell My Younger Self About Learning Development as a Web Designer128
learning, programming, javascript, databases, servers, preprocessors, version-control, performance, career
HTTPS as a Ranking Signal (met)127
google, search, http, seo
mXSS (gaz)126
xss, html
It’s Time to Encrypt the Entire Internet (kli/wir)125
web, http, ssl, encryption
3 Tips to Find Hacking on Your Site, and Ways to Prevent and Fix It124
search, google, tips-and-tricks
Cross-Origin Resource Sharing (ann/w3c)123
cors, standards
Despite Automatic Updates, Old Browsers Are Still a Problem (edb/zdn)122
browsers, web-platform, chrome, google, firefox, mozilla, internet-explorer, microsoft, safari, apple
Cross-Origin Resource Sharing on Track to Become a W3C Recommendation (sdt)121
w3c, cors, standards
Bid to Kill CAPTCHA Security Test Gains Momentum120
captcha, accessibility
We Should All Have Something to Hide119
privacy
Mobile Website Security118
mobile, hosting, policies
WordPress Security Tips117
wordpress, tips-and-tricks
Brad Hill: “HTML5 Security Realities” (chr/css)116
slides, xss, html
Bulletproof Your Drupal Website115
drupal
Top 10 PHP Security Vulnerabilities114
php, vulnerabilities
A Front End Engineer’s Manifesto (zac)113
websites, manifestos, user-experience, progressive-enhancement, simplicity, foss, accessibility, community, learning
A JavaScript Security Flaw112
javascript
The Secure Programmer’s Pledge111
manifestos
An Introduction to Content Security Policy (mik)110
introductions, csp
Rate Limiting With Apache and mod_security (joh)109
servers, apache, rate-limiting
Cross-Site Scripting Attacks (XSS)108
xss, examples
How to Secure Your WordPress Website (sma)107
how-tos, wordpress, link-lists
Using CORS106
cors
Some Notes on the Recent XML Encryption Attack (w3c)105
xml, encryption
XML Encryption Flaw Leaves Web Services Vulnerable (eur)104
web-services, xml, encryption
Notes From Writing HTML5 Media (bur)103
html, multimedia
HTTPS Is More Secure, So Why Isn’t the Web Using It? (ars)102
http, protocols, web
Web Cryptography: Salted Hash and Other Tasty Dishes (ali)101
cryptography
What Are the JSON Security Concerns in Web Development? (sim)100
json
What Is Cross Site Scripting or XSS? (chr/css)99
xss, javascript, concepts
Web Developers Accountable for HTML 5 Security (zdn)98
html
HTML5 Raises New Security Issues97
html, browsers
10 Useful WordPress Security Tweaks (sma)96
wordpress
Web Security: Are You Part of the Problem? (cod/sma)95
vulnerabilities, php, javascript
Full Frontal ’09: Chris Heilmann on JavaScript Security (mic/aja)94
javascript
Cookies and Security (nza)93
cookies, xss, csrf
A Critical Vulnerability in IE8 (jed)92
internet-explorer, microsoft, browsers, vulnerabilities
Finally Something to Get a Few More Users Off of IE 6? (dal/aja)91
internet-explorer, microsoft, browsers
The Internet Is Closing to Innovation (zit/new)90
web
You Could Be Getting Clickjacked (tec)89
vulnerabilities, frames, w3c
Video and Audio Tags and Cross Origin Access (dal/aja)88
html, multimedia
Dumb Security Tips: Think Before You Follow Online Guides (tan)87
tips-and-tricks
Alerting Webmasters to Webserver Vulnerabilities86
google
Simon Willison, @Media Ajax (mic/aja)85
ajax, xss, csrf, javascript, json
Frame-Busting Gadgets (mic)84
frames, iframes
Evil GIFs: Hiding Java in Your Image (dal/aja)83
gif, images, java
What’s in a “window.name”? (cod/aja)82
javascript
Internet Explorer 8 Promises Better Standards Compliance… and a Whole Lot More (est/cio)81
internet-explorer, microsoft, browsers, standards
Ajaxian Roundup for January 2008: JavaScript Turtles and IE 8 (dal/aja)80
javascript, prototypejs, dojo, extjs, jquery, gwt, yui, dwr, gears, flash, air, json, browsers, standards, css, design, comet, ajaxian, link-lists
Book Recommendation: “AJAX Security” by Hoffman and Sullivan79
books, ajax, javascript
Ajaxian Roundup for December 2007: It’s the End of the Year as We Know It (dal/aja)78
browsers, javascript, prototypejs, extjs, yui, jquery, microsoft, dwr, performance, gwt, comet, css, mobile, ajaxian, link-lists
Cross Site Scripting Joy (tri)77
xss
Making JavaScript Safe With No Script (dal/aja)76
javascript
Obscurity, Security, and Captcha (zac)75
captcha, accessibility
Automated Security Scanners Choke on AJAX (rey/aja)74
ajax, javascript
Quick Security Checklist for Webmasters73
checklists
How to Protect a JSON or JavaScript Service72
how-tos, json, javascript
Securing Your JSON71
json, javascript, arrays
“phpinfo()” XSS Vulnerability (jed)70
php, xss, vulnerabilities
CSRF Protection Idea (dal/aja)69
csrf
JavaScript Security Experiments (mar)68
javascript, experiments