⤷ Title: Business Logic Vulnerabilities Are Engineering Bugs
════════════════════════
𐀪 Author: Phani Varun Munukuntla
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 02:20:01 GMT
════════════════════════
⌗ Tags: #backend_engineering #software_architecture #application_security #product_security #security_engineering
════════════════════════
𐀪 Author: Phani Varun Munukuntla
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 02:20:01 GMT
════════════════════════
⌗ Tags: #backend_engineering #software_architecture #application_security #product_security #security_engineering
Medium
Business Logic Vulnerabilities Are Engineering Bugs
Introduction
⤷ Title: Hashing vs Encoding vs Encryption
════════════════════════
𐀪 Author: Rifat
════════════════════════
ⴵ Time: Fri, 02 Jan 2026 15:29:40 GMT
════════════════════════
⌗ Tags: #backend_engineering #jwt #api_security #cybersecurity #system_design_concepts
════════════════════════
𐀪 Author: Rifat
════════════════════════
ⴵ Time: Fri, 02 Jan 2026 15:29:40 GMT
════════════════════════
⌗ Tags: #backend_engineering #jwt #api_security #cybersecurity #system_design_concepts
Medium
Hashing vs Encoding vs Encryption
Many security bugs happen because engineers confuse intent.
⤷ Title: Your Password Hashing Strategy Will Fail — Here’s Why
════════════════════════
𐀪 Author: Suhail Muhammed
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 13:03:12 GMT
════════════════════════
⌗ Tags: #authentication #system_design_concepts #backend_engineering #application_security #design_best_practices
════════════════════════
𐀪 Author: Suhail Muhammed
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 13:03:12 GMT
════════════════════════
⌗ Tags: #authentication #system_design_concepts #backend_engineering #application_security #design_best_practices
Medium
Your Password Hashing Strategy Will Fail — Here’s Why
Password storage is often treated as boilerplate.
⤷ Title: NestJS Tool APIs for Agents That Don’t Get Abused
════════════════════════
𐀪 Author: Syntal
════════════════════════
ⴵ Time: Sat, 07 Feb 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #nestjs #backend_engineering #llm_agent #devops #api_security
════════════════════════
𐀪 Author: Syntal
════════════════════════
ⴵ Time: Sat, 07 Feb 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #nestjs #backend_engineering #llm_agent #devops #api_security
Medium
NestJS Tool APIs for Agents That Don’t Get Abused
Build “tool endpoints” your agents can call safely — scoped permissions, hard validation, audit trails, and guardrails that survive…
⤷ Title: NestJS Rate Limiting Without Angry Users
════════════════════════
𐀪 Author: Bhagya Rana
════════════════════════
ⴵ Time: Sat, 07 Feb 2026 12:01:01 GMT
════════════════════════
⌗ Tags: #nestjs #backend_engineering #redis #api_security #rate_limiting
════════════════════════
𐀪 Author: Bhagya Rana
════════════════════════
ⴵ Time: Sat, 07 Feb 2026 12:01:01 GMT
════════════════════════
⌗ Tags: #nestjs #backend_engineering #redis #api_security #rate_limiting
Medium
NestJS Rate Limiting Without Angry Users
Build abuse-resistant throttling in NestJS that stops bots, respects real humans, and avoids nuking everyone behind the same IP.
⤷ Title: TIMING ATTACK — Why Generic Authentication Errors Are Not Enough (And How Response Time Can Betray U
════════════════════════
𐀪 Author: Luke Emmanuel
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 09:53:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #system_design_interview #backend_engineering #api_security #authentication
════════════════════════
𐀪 Author: Luke Emmanuel
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 09:53:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #system_design_interview #backend_engineering #api_security #authentication
Medium
TIMING ATTACK — Why Generic Authentication Errors Are Not Enough (And How Response Time Can Betray You)
TIMING ATTACK — Why Generic Authentication Errors Are Not Enough (And How Response Time Can Betray You) As backend engineers, we’re often taught a core security practice when building …
⤷ Title: Prompt Injection in 2026: What Breaks, What Holds
════════════════════════
𐀪 Author: Bytecraft
════════════════════════
ⴵ Time: Wed, 18 Feb 2026 14:31:00 GMT
════════════════════════
⌗ Tags: #application_security #ai_security #llm_agent #prompt_injection #backend_engineering
════════════════════════
𐀪 Author: Bytecraft
════════════════════════
ⴵ Time: Wed, 18 Feb 2026 14:31:00 GMT
════════════════════════
⌗ Tags: #application_security #ai_security #llm_agent #prompt_injection #backend_engineering
Medium
Prompt Injection in 2026: What Breaks, What Holds
A practical field guide to the defenses that still work when agents browse the web, read documents, and press real buttons.
⤷ Title: Tool Permissions for Agents: The Missing Security Layer
════════════════════════
𐀪 Author: Bytecraft
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 03:31:01 GMT
════════════════════════
⌗ Tags: #backend_engineering #ai_security #devops #llm_agent_frameworks #application_security
════════════════════════
𐀪 Author: Bytecraft
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 03:31:01 GMT
════════════════════════
⌗ Tags: #backend_engineering #ai_security #devops #llm_agent_frameworks #application_security
Medium
Tool Permissions for Agents: The Missing Security Layer
How to stop your agent from becoming a “confused deputy” by putting least-privilege, scoped approvals, and auditability between the model…
⤷ Title: How Mobile API Rate Limiting Fails in Real Attacks
════════════════════════
𐀪 Author: Vaibhav Shakya | Mr Neo
════════════════════════
ⴵ Time: Thu, 26 Feb 2026 04:47:05 GMT
════════════════════════
⌗ Tags: #system_architecture #mobile_security #backend_engineering #trust_boundaries #api_security
════════════════════════
𐀪 Author: Vaibhav Shakya | Mr Neo
════════════════════════
ⴵ Time: Thu, 26 Feb 2026 04:47:05 GMT
════════════════════════
⌗ Tags: #system_architecture #mobile_security #backend_engineering #trust_boundaries #api_security
Medium
How Mobile API Rate Limiting Fails in Real Attacks
Rate limiting is commonly treated as a protective control: restrict how often an API can be called, and abuse becomes expensive or…
⤷ Title: Secure Coding for Mobile APIs: What Most Backend Teams Miss
════════════════════════
𐀪 Author: Vaibhav Shakya | Mr Neo
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 05:06:59 GMT
════════════════════════
⌗ Tags: #secure_coding #mobile_security #web_app_security #api_security #backend_engineering
════════════════════════
𐀪 Author: Vaibhav Shakya | Mr Neo
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 05:06:59 GMT
════════════════════════
⌗ Tags: #secure_coding #mobile_security #web_app_security #api_security #backend_engineering
Medium
Secure Coding for Mobile APIs: What Most Backend Teams Miss
Mobile APIs sit at one of the most misunderstood trust boundaries in modern distributed systems.
⤷ Title: Why Your Backend Should Never Trust the Frontend
════════════════════════
𐀪 Author: Endurance Orisabinone
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 05:32:27 GMT
════════════════════════
⌗ Tags: #backend_engineering #financial_services #application_security #software_engineering #banking
════════════════════════
𐀪 Author: Endurance Orisabinone
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 05:32:27 GMT
════════════════════════
⌗ Tags: #backend_engineering #financial_services #application_security #software_engineering #banking
Medium
Why Your Backend Should Never Trust the Frontend
A look at how frontend assumptions break financial systems and why backend validation is non-negotiable
⤷ Title: How Android Apps Communicate with Servers Without Exposing APIs
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 14:07:23 GMT
════════════════════════
⌗ Tags: #devops #backend_engineering #cybersecurity #android_development #api_security
════════════════════════
𐀪 Author: SwayamOps
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 14:07:23 GMT
════════════════════════
⌗ Tags: #devops #backend_engineering #cybersecurity #android_development #api_security
Medium
How Android Apps Communicate with Servers Without Exposing APIs
If you’ve ever been curious about how apps like WhatsApp, Instagram, Uber, Spotify, or Amazon communicate with their backend servers…