DZone
Thanks for visiting DZone today,
Edit Profile
  • Manage Email Subscriptions
  • How to Post to DZone
  • Article Submission Guidelines
Sign Out View Profile
  • Post an Article
  • Manage My Drafts
Over 2 million developers have joined DZone.
Log In / Join
Refcards Trend Reports
Events Video Library
Refcards
Trend Reports

Events

View Events Video Library

The Latest Security Topics

article thumbnail
Compliance Automated Standard Solution (COMPASS), Part 11: Compliance as Code, the OSCAL MCP Server Way
How AI-native tooling is finally closing the loop between compliance personas and OSCAL artifacts with an MCP-standardized, AI-agent-ready interface.
June 4, 2026
by Yuji Watanabe
· 3,033 Views · 1 Like
article thumbnail
Building Threat Intelligence Pipelines Using Python, APIs, and Elasticsearch
STIX/TAXII in, ECS normalized, provenance preserved deterministic IDs, correct bulk writes, ingest pipelines keep threat indicator data reliable and queryable under load.
June 3, 2026
by Krishnaveni Musku
· 3,403 Views
article thumbnail
Identity in Action
A practical guide to SSO migration covering risks, MFA, phased rollout, and governance to ensure secure identity transitions without disruption.
June 3, 2026
by Kapil Chakravarthy Sanubala
· 3,410 Views · 5 Likes
article thumbnail
Compliance Automated Standard Solution (COMPASS), Part 10: How OSCAL Mapping Paves the Way for Continuous Compliance Scalability
Mapping Model is the missing architectural layer that transforms multi-framework compliance from exponential complexity to a linear scale.
June 3, 2026
by Vikas Agarwal
· 2,726 Views
article thumbnail
The Missing `bandit` for AI Agents: How I Built a Static Analyzer for Prompt Injection
Static analysis for LLM agents that flags prompt-injection risks—like confused deputy flows and dynamic prompts—before runtime, improving security and auditability.
June 2, 2026
by Sanjay Krishnegowda
· 2,596 Views · 2 Likes
article thumbnail
5 AI Security Incidents That Broke Things in Production (and What They Have in Common)
Five real incidents from late 2025 and early 2026 show what happens when automated systems outpace the controls around them.
June 2, 2026
by Lavanya Chandrasekharan
· 2,672 Views · 1 Like
article thumbnail
Offline-First Patch Management for 10,000 Edge Nodes: A Practical Architecture That Scales
How we stopped fighting the network and started treating bandwidth as a scarce resource — and what happened to our patch success rate when we did.
June 1, 2026
by srinivas thotakura
· 1,731 Views
article thumbnail
Implementing Secure API Gateways for Microservices Architecture
Use Kong as an API gateway to centralize JWT auth, rate limiting, and access control across all microservices, keeping individual services focused on business logic.
May 29, 2026
by Mugunth Chandran
· 4,586 Views · 3 Likes
article thumbnail
5 Common Security Pitfalls in Serverless Architectures
Developers should watch for over-privileged IAM roles, implicit trust in internal triggers, insecure secrets handling, and more.
May 29, 2026
by Zac Amos
· 2,695 Views · 1 Like
article thumbnail
Why Your DLP Policies Fall Short the Moment AI Agents Enter the Picture
AI agents have access, move at machine speed, and raise no alarms. Your DLP was built for humans — by the time it flags risk, the data is already gone.
May 28, 2026
by Priyanka Neelakrishnan
· 2,806 Views
article thumbnail
Detecting Advanced Persistent Threats Using Behavioral Analytics and Log Correlation
Behavior is the signal, correlation is the proof. Adaptive baselines plus time-windowed cross-plane correlation are limited by log quality, not model sophistication.
May 28, 2026
by Krishnaveni Musku
· 2,009 Views
article thumbnail
Stateless JWT Auth Microservice Architecture With Spring Boot 3 and Redis Sentinel
Design a stateless JWT auth service with Spring Boot 3, Redis caching, and Sentinel for high availability, faster token validation, and reduced DB load.
May 27, 2026
by Erkin Karanlık
· 4,344 Views · 1 Like
article thumbnail
You Don't Get to Retrofit Trust: Why API Security Must Be Designed In, Not Bolted On
A field-level examination of how one startup got it right — and what the rest of the industry keeps getting catastrophically wrong.
May 27, 2026
by Igboanugo David Ugochukwu DZone Core CORE
· 3,467 Views
article thumbnail
Architecting Zero-Trust AI Agents: How to Handle Data Safely
Transitioning AI agents from POC to production requires moving beyond permissive access to a zero-trust architecture. This covers the essential security layers.
May 26, 2026
by Felicia Thomson
· 6,742 Views · 3 Likes
article thumbnail
Catching Data Perimeter Drift Before It Reaches Production
A development-time validation pattern to catch data perimeter setup issues and preserve the historical context of a data perimeter project.
May 26, 2026
by Suresh Gururajan
· 3,667 Views
article thumbnail
The Hidden Cost of Overprivileged Tokens: Designing Messaging Platforms That Assume Compromise
Learn why overprivileged tokens are a platform design failure, not a security bug, and how runtime enforcement, granular scoping, and safe migration fix them.
May 25, 2026
by Prakash Wagle
· 2,200 Views
article thumbnail
A 5-Step SOC Guide That Meets RBI Expectations and Strengthens Security Operations
This article is a five-step SOC guide aligning security operations with RBI expectations, covering governance, risk mapping, tech selection, and performance measurement.
May 25, 2026
by Shivani chavan
· 2,198 Views
article thumbnail
Evaluating SOC Effectiveness Using Detection Coverage and Response Metrics
Coverage plus response speed, not alert counts, ATT&CK-mapped detections, emulation-validated claims, timed from structured incident timestamps.
May 21, 2026
by Krishnaveni Musku
· 2,597 Views
article thumbnail
How to Detect Spam Content in Documents Using C#
Spam detection isn't just about cleaning up our email inbox. Document-level spam detection at file intake is becoming just as important.
May 21, 2026
by Brian O'Neill DZone Core CORE
· 2,471 Views
article thumbnail
Your API Authentication Isn’t Broken; It’s Quietly Failing in These 6 Ways
API authentication rarely fails outright. It weakens over time due to gaps in validation, access control, internal trust, which become harder to detect as systems scale.
May 21, 2026
by Jay Goradia
· 1,754 Views · 1 Like
  • Previous
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • ...
  • Next
  • RSS
  • X
  • Facebook

ABOUT US

  • About DZone
  • Support and feedback
  • Community research

ADVERTISE

  • Advertise with DZone

CONTRIBUTE ON DZONE

  • Article Submission Guidelines
  • Become a Contributor
  • Core Program
  • Visit the Writers' Zone

LEGAL

  • Terms of Service
  • Privacy Policy

CONTACT US

  • 3343 Perimeter Hill Drive
  • Suite 215
  • Nashville, TN 37211
  • [email protected]

Let's be friends:

  • RSS
  • X
  • Facebook
×