Forem

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
LiteLLM Supply Chain Attack: How TeamPCP Backdoored AI Infrastructure
Cover image for LiteLLM Supply Chain Attack: How TeamPCP Backdoored AI Infrastructure

LiteLLM Supply Chain Attack: How TeamPCP Backdoored AI Infrastructure

Comments
12 min read
Week 10: Security Engineering Phone Screen: 10 Questions You Must Answer Fluently

Week 10: Security Engineering Phone Screen: 10 Questions You Must Answer Fluently

1
Comments
12 min read
Let Humans Write. Let AI Critique -- A Manifesto for Security Engineers

Let Humans Write. Let AI Critique -- A Manifesto for Security Engineers

1
Comments 1
8 min read
Automated Security Audits With AI Agent Teams

Automated Security Audits With AI Agent Teams

Comments
2 min read
Week 9: Audit 15 Code Snippets for SQL Injection

Week 9: Audit 15 Code Snippets for SQL Injection

1
Comments
20 min read
EU Cyber Resilience Act: What It Means for Your Codebase and How to Prepare

EU Cyber Resilience Act: What It Means for Your Codebase and How to Prepare

Comments
3 min read
Awareness, Not Safety Net: Set Correct Expectations
Cover image for Awareness, Not Safety Net: Set Correct Expectations

Awareness, Not Safety Net: Set Correct Expectations

Comments
2 min read
Why CodeGate Exists: Inspect Before Trust
Cover image for Why CodeGate Exists: Inspect Before Trust

Why CodeGate Exists: Inspect Before Trust

Comments
3 min read
The Cornucopia of Gamified Threat Modeling
Cover image for The Cornucopia of Gamified Threat Modeling

The Cornucopia of Gamified Threat Modeling

3
Comments 2
7 min read
Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners
Cover image for Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners

Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners

Comments
3 min read
SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist
Cover image for SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist

SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist

6
Comments 3
1 min read
Architectural Asymmetry in Authentication: Part 2 — Risk Before Context

Architectural Asymmetry in Authentication: Part 2 — Risk Before Context

3
Comments
2 min read
39 CVEs in WebGoat. Only 36 Were Reachable.

39 CVEs in WebGoat. Only 36 Were Reachable.

1
Comments
10 min read
Week 8 Challenge: Build an Anti-XSS Escape Encoding Framework in Python

Week 8 Challenge: Build an Anti-XSS Escape Encoding Framework in Python

2
Comments
9 min read
What We Learned Securing a SaaS Product with Automated DAST

What We Learned Securing a SaaS Product with Automated DAST

3
Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.