AppSec
In-depth guides and analysis on appsec from the Safeguard engineering team.
309 articles
Web Application Penetration Testing: What to Expect
A real web application penetration test follows a scoped, multi-phase process — here's what happens before, during, and after the engagement so the report doesn't surprise you.
IAST Meaning: What Interactive Application Security Testing Does
IAST instruments a running application from the inside, watching real execution to confirm vulnerabilities with far fewer false positives than static scanning.
CVSS 4.0 Release Date, Changes, and Adoption Status
The CVSS 4.0 release date was November 1, 2023 — here is what changed from v3.1, how the new metric groups work, and where real-world adoption stands.
jQuery UI 1.12.1 and 1.13.1 Vulnerabilities: CVE Guide
jQuery UI 1.13.1 vulnerabilities come down to one checkboxradio XSS, while 1.12.1 carries four. A practical guide to the CVEs, exploit conditions, and the upgrade to 1.13.2+.
White Box Pentesting: A Practical Guide to Full-Knowledge Testing
White box pentesting gives the tester source code, architecture, and credentials up front. Here is when that full-knowledge approach beats black box, and how an engagement actually runs.
SAST and DAST Tools: A Combined Buying Guide
Buying SAST and DAST tools separately usually means paying for two dashboards that don't talk to each other — here's how to evaluate them as a combined purchase in 2026.
JavaScript Vulnerability Scanners: How They Actually Work
A javascript vulnerability scanner has to reason about a dynamically typed, dependency-heavy language — which is why the good ones combine static analysis with dependency-graph lookups rather than relying on either alone.
Free Web Security Scanners: What to Expect From the Free Tier
What a free web security scanner will and won't catch, how the free tiers of popular tools are actually limited, and when you need to pay for real coverage.
simple-git: Command Injection CVEs and Safe Usage Patterns
The npm simple-git library went through a chain of argument injection CVEs in 2022, each an incomplete fix of the last. The history is a case study in why wrapping a CLI safely is hard.
Web Scanners: How They Work and What to Use
A web scanner probes a running application for vulnerabilities the way an attacker would. Here is how the different types work and how to pick one that finds real bugs.
Log4j 1.2.17 Vulnerabilities: Why Log4j 1.x Cannot Be Fixed
The only real log4j 1.2.17 vulnerability fix is migrating off the 1.x line — it reached end of life in 2015 and its RCE-class CVEs will never be patched. Here is the case and the path.
Website Security Scanners: How a Site Scanner Works and What to Use
A site scanner crawls a live website and probes it for security issues, from missing headers to injection flaws. Here is how the scan works and how to pick one.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.