Application Security articles

AppSec fundamentals, vulnerability management, secure coding, and testing strategies to help teams build and ship secure software at scale.

From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Blog critical CVE 2025 55182

From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications

Discover a critical security flaw that enables remote code execution in React Server Components.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Open Source Security post

Ultimate Guide to Open Source Security: Risks, Attacks & Defenses

Explore top risks and proven open source security strategies.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Container Security blog

Building Strong Container Security for Modern Applications

Discover how to protect containerized applications.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Code Scanning

Code Scanning: Why, How & the Role of Scanning in AI Security

Explore code scanning benefits, tools, and best practices.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - SAST Tools for DevSecOps

Top 7 SAST tools for DevSecOps Teams in 2025

Discover the top SAST tools empowering DevSecOps teams in 2025.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Blog What is Application Security Posture Management ASPM

What Is Application Security Posture Management (ASPM)?

Discover how ASPM improves risk visibility, reduces alert fatigue, and accelerates secure development.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Blog image What is SCA @2x

What is Software Composition Analysis (SCA)?

Learn about Software Composition Analysis (SCA) and how it helps manage open source code to reduce security risks.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Blog image Kubernetes Security Risks and Critical Best Practices@2x

Kubernetes Security Risks and Critical Best Practices

Learn about Kubernetes Security Best Practices, a crucial aspect of managing containerized workflows at scale.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Application Security โ€” The Complete Guide

Security Testing in 2025: Testing Apps, AI, Cloud Native, and More

Learn about key trends in modern security and the OWASP Top 10.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - The 2021 OWASP Top 10 post

What Are OWASP Top 10 Threats & When Will the Top 10 Be Updated?

Stay updated on the latest in application security with the OWASP Top 10 vulnerabilities.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - AST Security Scanning blog post

Application Security Testing: Security Scanning and Runtime Protection Tools

Learn about the differences between security scanning and runtime protection in application security testing. Explore tools and tech.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Blog OWASP Dependency Check

OWASP Dependency Check: How Does It Work?

Learn how OWASP Dependency Check helps secure open source components.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Blog image Top Ten Tips to Choose a Great SAST Tool@2x

Top Ten Tips to Choose a Great SAST Tool

The top ten tips for choosing a SAST tool for application security.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - Dynamic Application Security Testing DAST Basics 1

Dynamic Application Security Testing: DAST Basics

Learn about dynamic application security testing (DAST).

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - The Top 11 Web Vulnerability Scanners

The Top 11 Web Vulnerability Scanners

Discover the top 11 web vulnerability scanners and learn why they are essential for protecting your web applications from hackers.

Read More
From Zero to RCE: How a Single HTTP Request Compromises React and Next.js Applications - cvss3.1 vs cvss4 blog

CVSS 3.1 vs CVSS 4.0: A Look at the Data

CVSS base scores are up in the latest version of the scoring system. What does that mean for AppSec practitioners?

Read More