Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

591 articles

AppSec

SQL Injection for Beginners: How It Works and How to Stop It

SQL injection for beginners, explained without the hype: what the attack actually is, why string-built queries cause it, and the one habit — parameterized queries — that closes the door.

Jun 9, 20256 min read
Security

Vulnerability Assessment as a Service: What It Is and When You Need It

How vulnerability assessment as a service works, what it covers, and how to tell whether a managed scanning service fits your team better than in-house tooling.

Jun 9, 20256 min read
AppSec

What Is a CSRF Attack? Detection and Prevention Guide

A CSRF attack tricks a logged-in user's browser into sending forged requests. Here is how the attack works and how to shut it down with modern defenses.

Jun 9, 20257 min read
Security

Nuxt Security: Hardening Your Nuxt App Against Real Threats

A practical Nuxt security guide covering the nuxt-security module, Content Security Policy with SSR nonces, server-route risks, and dependency hygiene.

Jun 9, 20256 min read
Open Source

react-query (TanStack Query): Package Health and Data-Fetching Safety

The npm react-query package froze at v3.39.3 when the project moved to @tanstack/react-query. Here is how to tell which one you are running, and how to keep server-state caching from leaking data.

Jun 4, 20257 min read
AppSec

DAST vs Pen Testing: Which One Does Your App Actually Need?

DAST is automated, continuous, and scales; penetration testing is manual, creative, and deep. Here is how they differ and why serious teams run both.

Jun 4, 20256 min read
AppSec

Free Web Security Scanner: How They Work and What to Use

A free web security scanner can find real vulnerabilities in a web app, but only if you understand what each type actually tests. Here is a practitioner's breakdown.

Jun 4, 20255 min read
Vulnerabilities

Stored XSS: Why Persistent Injection Hurts Most

Stored XSS saves the attacker's script server-side and serves it to everyone. Here is why persistent injection is the most damaging XSS variant and how to stop it.

Jun 3, 20256 min read
Security Concepts

The Threat Modeling Process, Step by Step

Threat modeling answers four questions: what are we building, what can go wrong, what are we doing about it, and did we do enough? A concrete step-by-step process your team can run in an afternoon.

Jun 3, 20256 min read
AppSec

SSRF Vulnerability Explained: How Server-Side Request Forgery Works and How to Stop It

An SSRF vulnerability lets an attacker make your server send requests on their behalf — the flaw behind the Capital One breach. Here's how it works and how to defend against it.

May 30, 20257 min read
Security

API Security Software: What It Does and How to Choose It

API security software protects the endpoints that carry most of your traffic and data. Here is what these tools actually do, the categories that matter, and how to choose without duplicating coverage.

May 29, 20256 min read
AppSec

Web Security Scan: How to Find Vulnerabilities Before Attackers Do

A web security scan probes your application for exploitable flaws the way an attacker would. Here is how the main scan types work and how to run them well.

May 27, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 34) — Safeguard Blog