AppSec Brief · 69 articles · 18 guides · 51 vuln classes · 17 languages Subscribe

Application Security for Developers

Secure code is
readable code.

Deep-dive guides on SQL injection, JWT attacks, supply chain security, and more. Code-forward. No fluff.

Recent Articles View all

vuln
ML Model Deserialization Attacks: Pickle, ONNX, and Safetensors Security
OWASP A08:2021
python
vuln
Server-Side Template Injection: How Template Engines Become Remote Code Execution
OWASP A03:2021
pythonjavajavascript
vuln
Second-Order SQL Injection: When Sanitised Input Becomes Tomorrow's Exploit
pythonsqljavascript
guide
Dockerfile and Container Image Security: Hardcoded Secrets, Root Execution, and Base Image Risks
dockerbashyaml
vuln
Server-Side Request Forgery (SSRF): From Internal Port Scan to Cloud Metadata Theft
OWASP A10:2021
pythonjavascriptgo
guide
OAuth 2.0 Security for Developers: PKCE, Implicit Flow Risks, and Secure Token Storage
javascriptpython
vuln
Zip Slip: Archive Extraction Path Traversal in Java, Python, Node.js, and Go
vuln
Prototype Pollution in JavaScript and Node.js: Exploitation and Prevention
All articles →