Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

591 articles

AppSec

SQL Injection Commands Explained: How the Attack Works and How to Stop It

Understanding the SQL injection commands attackers rely on is the fastest way to learn how to defend against them. This guide explains the classes conceptually and focuses on detection and remediation.

Apr 3, 20256 min read
Security

How to Run a Software Security Assessment

A software security assessment is a structured evaluation of an application's security posture across code, dependencies, configuration, and process. Here is how to run one that produces action, not a PDF.

Apr 3, 20256 min read
Security

Vulnerable Websites List: Legal Sites to Practice Security Testing

A curated vulnerable websites list of intentionally insecure apps and labs built for legal, hands-on security practice — plus the rules that keep your training from becoming a crime.

Mar 30, 20255 min read
Security

Vulnerability Checker: How to Scan Your Code and Websites for Flaws

What a vulnerability checker does, the different kinds (dependency, website, container), and how to choose and use one to actually reduce risk rather than generate noise.

Mar 30, 20256 min read
Security

JavaScript Injection Attack: How It Works and How to Stop It

A JavaScript injection attack runs attacker-controlled script in a victim's browser or a Node.js process. Here is how the attack class works and the defenses that actually neutralize it.

Mar 27, 20256 min read
AppSec

OWASP API Top 10 2023: What Changed and How to Defend

The OWASP API Security Top 10 2023 puts authorization failures at the top and adds new risks around business flows and API consumption. Here's the full list with defenses.

Mar 25, 20256 min read
Security

"The Code Is Correct!" and Other Myths That Hide Security Bugs

Passing tests and a clean review tell you the code is correct, but correctness and security are not the same thing. Here is where the gap lives.

Mar 18, 20256 min read
AppSec

What Is a DAST Assessment? A Practical Security Guide

A DAST assessment tests a running application from the outside to find exploitable flaws. Here is how it works, what it catches, and where it fits alongside SAST and SCA.

Mar 18, 20257 min read
Security

Application Security Meaning Explained

The application security meaning boils down to protecting software from threats across its whole life: design, code, dependencies, and runtime. Here is what the term actually covers.

Mar 18, 20255 min read
Security

Benefits Of Ethical Hacking: A Security Guide

The benefits of ethical hacking come down to one thing: finding your weaknesses before an attacker does, on your terms and with a report you can act on.

Mar 18, 20255 min read
Security

Code Review Best Practices for Java: A Security-First Guide

Security-focused code review best practices for Java teams: what to look for, how to structure reviews, and the recurring bug classes that slip past compilers.

Mar 18, 20255 min read
Security

Enterprise App Security: How Large Organizations Protect Their Software

Enterprise app security is the practice of protecting business-critical applications across their whole lifecycle. Here is how mature teams actually run it.

Mar 18, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 41) — Safeguard Blog