ASP.NET Core and .NET Security Articles, Tutorials & News

ASP.NET Core and .NET Security articles, tutorials, and news from the DotNetNews archive.

423 articles Updated

Start here

Editor picks for Security

  1. Implementing Passkey Authentication in ASP.NET Core Applications

    c-sharpcorner.com Issue #502

    Passkeys keep moving from nice-to-have to baseline. Good starter piece for WebAuthn in ASP.NET Core.

    Read article Issue #502

  2. OWASP Top 10 for .NET Developers - Part 8: Preventing Software and Data Integrity Failures

    medium.com Issue #497

    A worthwhile security reminder that clean scans and passing tests do not cover supply-chain and integrity failure risks.

    Read article Issue #497

  3. Why and When We Need to Use [CustomAuthorize] in ASP.NET

    masumkazi.medium.com Issue #497

    Custom authorization is easy to overuse, so the "when" is the important part of this discussion.

    Read article Issue #497

  4. How to Implement Passkey Authentication in ASP.NET Core Applications

    c-sharpcorner.com Issue #491

    Passkeys are moving from nice-to-have to expected. Useful if you want stronger auth without dragging users through password friction.

    Read article Issue #491

  5. How Hidden Security Vulnerabilities Turn Into Business-Critical Incidents in Modern Applications

    medium.com Issue #490

    Less framework-specific, but the business framing around hidden vulnerabilities and incident cost is still relevant for engineering leads.

    Read article Issue #490

  6. Elsa 3.8 Preview: Secrets, State Machines, and a Security Hardening Pass

    topuzas.medium.com Issue #489

    Worth a skim if Elsa is on your radar and you care about security posture.

    Read article Issue #489

  7. Building for the agentic web with .NET 11

    youtube.com Issue #472

    Agentic web apps on .NET 11 shift from request-response to autonomous agent patterns.

    Read article Issue #472

  8. Stop prompt injection from hijacking your agent, new security capabilities now released within Agent Framework

    devblogs.microsoft.com Issue #465

    Prompt injection is still the biggest agent risk, so I'm glad to see more concrete platform defenses landing here.

    Read article Issue #465

ASP.NET Core security from the DotNetNews archive, curated for .NET developers who already ship production code. This is a reading list pulled from daily issues, not a substitute for the official docs on ASP.NET Core and .NET Security.

Use Start here for the editorial shortlist, then browse Latest or the full archive when you need more depth. Coverage leans toward ASP.NET Core security, .NET security, secure coding C#. Recent pieces worth opening: “Password hashing done right: PBKDF2-SHA512, 600k iterations, timing-safe” and “Cross-service auth without a shared secret: JWKS dual-fetch”.

Every item links out to the original publisher and back to the DotNetNews issue where it ran.

Latest

Newest Security from the archive

Archive

Page 1 of 17

Newest first