DEV Community

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Let Humans Write. Let AI Critique -- A Manifesto for Security Engineers

Let Humans Write. Let AI Critique -- A Manifesto for Security Engineers

1
Comments 1
8 min read
Automated Security Audits With AI Agent Teams

Automated Security Audits With AI Agent Teams

Comments
2 min read
Week 9: Audit 15 Code Snippets for SQL Injection

Week 9: Audit 15 Code Snippets for SQL Injection

1
Comments
20 min read
EU Cyber Resilience Act: What It Means for Your Codebase and How to Prepare

EU Cyber Resilience Act: What It Means for Your Codebase and How to Prepare

Comments
3 min read
Awareness, Not Safety Net: Set Correct Expectations

Awareness, Not Safety Net: Set Correct Expectations

Comments
2 min read
Why CodeGate Exists: Inspect Before Trust

Why CodeGate Exists: Inspect Before Trust

Comments
3 min read
Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners

Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners

Comments
3 min read
SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist

SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist

6
Comments 3
1 min read
Architectural Asymmetry in Authentication: Part 2 — Risk Before Context

Architectural Asymmetry in Authentication: Part 2 — Risk Before Context

3
Comments
2 min read
39 CVEs in WebGoat. Only 36 Were Reachable.

39 CVEs in WebGoat. Only 36 Were Reachable.

1
Comments
10 min read
Week 8 Challenge: Build an Anti-XSS Escape Encoding Framework in Python

Week 8 Challenge: Build an Anti-XSS Escape Encoding Framework in Python

2
Comments
9 min read
What We Learned Securing a SaaS Product with Automated DAST

What We Learned Securing a SaaS Product with Automated DAST

3
Comments
5 min read
How to Attack a RAG System — and Why Your Security Scanner Won't Catch It

How to Attack a RAG System — and Why Your Security Scanner Won't Catch It

Comments 1
6 min read
Week 7 Scripting Challenge: JWT Token Validation

Week 7 Scripting Challenge: JWT Token Validation

3
Comments
21 min read
Why Modern AppSec Needs Location-Aware Security Testing

Why Modern AppSec Needs Location-Aware Security Testing

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.