Application security, made easier.
Research you can reference, training you can follow, and CVE intelligence for software builders.
Training — 37 lessons across 6 pathways
Start learning →A hands-on, lifecycle-first journey through application security. Six pathways follow the software lifecycle — from building a security mindset to breaking your own apps before someone else does.
We've modernised appsec training around the way software actually gets built:
- 1ThinkBuild a security mindset: threats, boundaries, and intent.5 lessons
- 2CodeWrite secure code: injection, auth, validation, and defence in depth.8 lessons
- 3BuildDesign systems that defend themselves: frameworks, APIs, and architecture.6 lessons
- 4ShipSecure the pipeline: CI/CD, dependencies, containers, and provenance.6 lessons
- 5RunDetect and respond: logging, monitoring, incidents, and compliance.6 lessons
- 6BreakFind what others miss: testing, review, and offensive techniques.6 lessons
Research — 21 topics
View all →Deep dives on how attacks work, real-world impact, and prevention guidance. Got a topic request? Let us know.
- Authentication
- Business Logic Abuse
- Command Injection
- Cross-Origin Resource Sharing (CORS)
- Cross-Site Request Forgery (CSRF)
- Cross-Site Scripting (XSS)
- File Upload Security
- Insecure Direct Object References (IDOR)
- JSON Web Tokens (JWT)
- Mass Assignment
- Password Storage
- Path Traversal
- Prompt Injection
- Prototype Pollution
- Row-Level Security Patterns for Postgres
- Secure Software Development Lifecycle
- Server-Side Request Forgery (SSRF)
- Session Management
- SQL Injection
- Template Injection
- Threat Modeling
CVE Database
Search CVEs →Searchable CVE records with CVSS scores, severity filters, and affected-product lookups. Filter by critical/high severity, recently published, or recently updated.
AppSec Scorecard
Take the assessment →We love the maturity metrics that already exist, but sometimes you just need a quick dirty metric without all the admin. We've boiled it down to 10 yes/no questions that you can answer in 5 minutes to get a rough score and some quick wins to work on.
Latest news
All news →- @fastify/middie patches path normalization auth bypass in path-scoped middleware (CVE-2026-2880)
- OCaml fixes Marshal deserialization buffer over-read that can enable RCE (CVE-2026-28364)
- Hoppscotch patches unauthenticated onboarding config takeover (CVE-2026-28215)
- OpenLIT patches critical GitHub Actions workflow issue that could expose secrets (CVE-2026-27941)
- CVE-2026-27900: terraform-provider-linode debug logs could expose passwords and TLS private keys (fixed in v3.9.0)
