Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

591 articles

Security

Enterprise Security Tools: What Actually Belongs in Your Stack

Enterprise security tools span identity, endpoint, network, application, and data layers. Here is a practical map of what each category does and how to avoid buying overlap.

Jun 18, 20256 min read
AppSec

How a Web Application Penetration Test Actually Works (and What It Finds)

A web application penetration test simulates a real attacker against your app. Here is what the phases look like and how to act on the report.

Jun 18, 20256 min read
AppSec

DAST Testing: How Dynamic Scans Probe Running Applications

DAST testing attacks your app the way an outsider would — no source code, just HTTP requests against a running target. Here is how the scan works, what it catches that SAST misses, and where it falls short.

Jun 18, 20257 min read
AppSec

What Is a White Box Penetration Test?

A clear explanation of the white box penetration test: how full-knowledge testing differs from black and gray box, what testers get, and when it is the right choice.

Jun 17, 20257 min read
Security

What a Website Security Checker Really Checks

A website security checker scans a site for exposed vulnerabilities, misconfigurations, and known-bad dependencies. Here is what it catches and where it stops.

Jun 16, 20256 min read
AppSec

DAST Scanning Tools: What They Are and How to Choose One

DAST scanning tools test a running application from the outside to find runtime flaws. Here is how they work, what they catch, and how to pick one.

Jun 16, 20255 min read
AppSec

SCA Full Form in Engineering: What Software Composition Analysis Means

In software engineering and security, the SCA full form is Software Composition Analysis: the practice of inventorying and vetting the open-source components your code depends on.

Jun 14, 20255 min read
AppSec

sanitize-html Vulnerabilities: History and Correct Configuration

A walk through the real npm sanitize-html vulnerabilities, from the 2016 recursion bypass to the 2024 style-attribute leak, and the configuration that keeps the library safe.

Jun 11, 20257 min read
AppSec

cookie-parser in Express: Security Guide and Best Practices

The cookie-parser npm middleware is deceptively simple, but signed-cookie misuse and a 2024 CVE in its underlying cookie library still catch Express teams out.

Jun 11, 20256 min read
AppSec

How to Scan a Web App for Vulnerabilities (Without Fooling Yourself)

To scan web applications well you need the right tool for the right layer. Here is what a web scan actually catches, where each type falls short, and how to combine them.

Jun 11, 20256 min read
AppSec

MySQL Injection Cheat Sheet: How to Detect and Stop SQLi

A defender's MySQL injection cheat sheet: the query patterns attackers probe for, how login bypass and UNION-based extraction work, and how to shut them down.

Jun 11, 20256 min read
AppSec

How to Run a Secret Scan Across Your Codebase

A secret scan finds hardcoded credentials, API keys, and tokens in your code and history before an attacker does. Here is how to scan, what to catch, and how to respond.

Jun 11, 20257 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 32) — Safeguard Blog