Safeguard
Topic

AppSec

In-depth guides and analysis on appsec from the Safeguard engineering team.

309 articles

AppSec

Website Scanner: How It Works and What to Use

A website scanner probes a live site for security flaws like injection, misconfiguration, and known CVEs. Here is how the different scanner types work and when each one fits.

Jun 5, 20266 min read
AppSec

Code Vulnerability Scanning Tools: How to Choose the Right One

Code vulnerability scanning tools fall into distinct categories that see different risks. Knowing which does what is the difference between coverage and false confidence.

Jun 4, 20266 min read
AppSec

OWASP Top 10 and XSS: Where Cross-Site Scripting Fits Now

In the OWASP Top 10, XSS is no longer its own category. As of the 2021 list it lives inside A03: Injection. Here is what changed, why, and how to defend against it.

Jun 4, 20265 min read
AppSec

VAPT Services: What They Are and How to Choose One

VAPT services combine vulnerability assessment with penetration testing to both find weaknesses and prove which ones are actually exploitable. Here is what to expect and what to ask for.

Jun 3, 20265 min read
AppSec

react-quill and Quill: XSS History and Safe Rich-Text Editing

Using Quill in React means understanding CVE-2021-3163, the react-quill maintenance gap, and why editor output must always be sanitized server-side before display.

Jun 3, 20266 min read
AppSec

Dynamic Application Security Testing Tools, Compared

Dynamic application security testing tools test running applications the way an attacker would, but they differ sharply on API coverage, auth handling, and CI integration — here's how to tell them apart.

Jun 3, 20264 min read
AppSec

Report Scanner: How Vulnerability Scan Reports Work

A report scanner turns raw scan output into something a team can act on — deduplicated, prioritized, and mapped to owners — which is where most scanning programs actually stall.

Jun 3, 20266 min read
AppSec

OWASP Top 10 Certification: What It Actually Means

There is no official OWASP Top 10 certification, but here is how to prove OWASP Top 10 competence, which credentials cover it, and how teams demonstrate coverage.

Jun 2, 20266 min read
AppSec

API Security Posture Management, Explained

API security posture management inventories every API you actually have, then continuously checks it against the rules you meant to enforce.

Jun 2, 20265 min read
AppSec

Application Security Management: Programs That Actually Work

What separates an application security management program that actually reduces risk from one that just generates dashboards, based on where ownership and monitoring break down.

Jun 2, 20265 min read
AppSec

Apache Tomcat and Coyote Connector Vulnerabilities Explained

Apache tomcat vulnerabilities keep surfacing because Tomcat sits directly in the request path of so many Java applications; here is what the Coyote connector does and which vulnerability classes recur most.

Jun 1, 20266 min read
AppSec

How a Source Code Security Scanner Works and Which One to Use

A source code security scanner reads your code without running it to find injection, secrets, and logic flaws. Here is how the analysis works and how to pick one that fits.

May 31, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

AppSec (Page 6) — Supply Chain Security Blog | Safeguard