appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
591 articles
NoSQL Injection: A Practical Tutorial
NoSQL databases don't use SQL syntax, but they're not immune to injection attacks — this NoSQL injection tutorial covers how the attack actually works against MongoDB-style queries.
What Is a Secure Development Model? A Practical Guide
A secure development model bakes security into every phase of building software instead of bolting it on at the end. Here is how the model works and how to adopt one without slowing delivery.
Java Vulnerability Classes: A Reference List
A java vulnerability list organized by class — deserialization, injection, XXE, and the rest — because Java's ecosystem produces a specific, recurring set of vulnerability patterns worth knowing by name.
What Is a Security Champions Program?
AppSec teams are outnumbered 100 to 1 by developers. A security champions program is the only staffing model that scales — here is how to build one that lasts.
IAST Security: Interactive Application Security Testing Explained
IAST security instruments a running application to watch real requests flow through real code, catching vulnerabilities that static analysis and black-box scanning both miss.
Choosing an Enterprise Security Solution: What Actually Matters
An enterprise security solution is less about a single flagship product and more about how well a set of controls integrates, scales, and produces evidence for auditors.
DAST Solutions: How to Choose the Right Dynamic Testing Tool
DAST solutions test a running application from the outside to find exploitable flaws. Here is how they work, what they catch, and how to evaluate one for your pipeline.
Ethical Hacking Workshop: How to Read and Learn Online
Looking to read an ethical hacking workshop online? Here is how to learn ethical hacking legally and safely, what a good curriculum covers, and how it connects to defending real software.
Types of Vulnerability Assessment, Explained
Not every vulnerability assessment tests the same thing. Here's how network, application, host, and wireless assessments differ, and when each one is the right call.
SQL Injection Example: How It Works and How to Stop It
A clear SQL injection example makes the vulnerability obvious. Here are illustrative cases, the main attack types, and the fixes that actually eliminate the risk.
XXE Attack Demo: Understanding and Defending Against XML External Entities
An XXE attack demo makes the vulnerability click: an XML parser that trusts external entities can be tricked into reading files or making requests. Here is how it works and how to shut it down.
SQL Injection Examples: Real Attack Patterns and How to Stop Them
SQL injection examples that show the attack patterns behind the CWE, why they work, and the parameterized-query fix that stops all of them at once.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.