AppSec Brief · 104 articles · 27 guides · 76 vuln classes · 21 languages Subscribe

Application Security for Developers

Secure code is
readable code.

Deep-dive guides on SQL injection, JWT attacks, supply chain security, and more. Code-forward. No fluff.

Recent Articles View all

vuln
AI Coding Agent Hooks: A New Persistence Layer for Supply-Chain Malware
OWASP A03:2026
javascriptbashjson
vuln
CVE-2026-78676: How a Newline in a Git Config Value Becomes Remote Code Execution
OWASP A03:2021
PythonJavaScript
vuln
CVE-2026-78155: How an Untrusted Search Path Let StackGres Tenants Become Admins
OWASP A08:2021
PythonGo
vuln
The Env Var Trap: How VITE_ and NEXT_PUBLIC_ Prefixes Leak Secrets Into the Browser
javascript
vuln
Unsafe Deserialization in GraphQL Pagination Cursors: Lessons from CVE-2026-59285
tool
npm 12's allowScripts: Turning Install Scripts Into an Explicit Allowlist
OWASP A08:2021
javascriptbash
guide
Password Hashing Done Right: Argon2id, bcrypt, and the Mistakes That Still Get Apps Breached
OWASP A02:2021
pythonjavascriptgo
vuln
ChainDrop: How a Preinstall Hook Turned keyv and cacheable Into a Self-Propagating npm Worm
OWASP A08:2021
javascriptbash
All articles →