AppSec Brief · 101 articles · 27 guides · 73 vuln classes · 20 languages Subscribe

Application Security for Developers

Secure code is
readable code.

Deep-dive guides on SQL injection, JWT attacks, supply chain security, and more. Code-forward. No fluff.

Recent Articles View all

vuln
The Env Var Trap: How VITE_ and NEXT_PUBLIC_ Prefixes Leak Secrets Into the Browser
javascript
vuln
Unsafe Deserialization in GraphQL Pagination Cursors: Lessons from CVE-2026-59285
tool
npm 12's allowScripts: Turning Install Scripts Into an Explicit Allowlist
OWASP A08:2021
javascriptbash
guide
Password Hashing Done Right: Argon2id, bcrypt, and the Mistakes That Still Get Apps Breached
OWASP A02:2021
pythonjavascriptgo
vuln
ChainDrop: How a Preinstall Hook Turned keyv and cacheable Into a Self-Propagating npm Worm
OWASP A08:2021
javascriptbash
vuln
Unsafe Consumption of APIs: Why Trusting Third-Party Responses Is a Vulnerability
OWASP API10:2023
javascriptpythongo
vuln
ReDoS: Regular Expression Denial of Service — Detection and Safe Regex Patterns
javascriptpythonjava
vuln
WebRTC Security: TURN Servers, IP Leakage, and Peer Connection Vulnerabilities
OWASP A05:2021
javascript
All articles →