AppSec Brief · 74 articles · 19 guides · 55 vuln classes · 17 languages Subscribe

Application Security for Developers

Secure code is
readable code.

Deep-dive guides on SQL injection, JWT attacks, supply chain security, and more. Code-forward. No fluff.

Recent Articles View all

vuln
Node.js Code Injection: eval(), Function Constructor, and vm Module Escapes
javascript
vuln
LDAP Injection: Authentication Bypass in Directory Service Integrations
pythonjavajavascript
guide
Browser Extension Security: What Developers Need to Know in 2026
javascript
vuln
GitHub Actions Pwn Requests: How pull_request_target Exposes Your CI/CD Secrets to Attackers
yaml
vuln
Server-Side Template Injection: Exploiting and Defending Jinja2, Freemarker, and Pebble
vuln
ML Model Deserialization Attacks: Pickle, ONNX, and Safetensors Security
OWASP A08:2021
python
vuln
Server-Side Template Injection: How Template Engines Become Remote Code Execution
OWASP A03:2021
pythonjavajavascript
vuln
Second-Order SQL Injection: When Sanitised Input Becomes Tomorrow's Exploit
pythonsqljavascript
All articles →