DEV Community

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Why I Built an ML-Powered Secrets Detector Instead of Just Using Regex

Why I Built an ML-Powered Secrets Detector Instead of Just Using Regex

Comments
8 min read
What Building a SAST Tool Taught Me About AppSec That 13 Years of Software Engineering Didn't

What Building a SAST Tool Taught Me About AppSec That 13 Years of Software Engineering Didn't

Comments
8 min read
Your Private API is Currently Safe. One Developer Change Away From Unsafe.

Your Private API is Currently Safe. One Developer Change Away From Unsafe.

Comments
8 min read
False Positives in SAST — How I Built Suppression Into My Scanner and Why It Matters

False Positives in SAST — How I Built Suppression Into My Scanner and Why It Matters

Comments
9 min read
Writing Custom SAST Rules for Vulnerabilities Your Scanner Doesn't Cover

Writing Custom SAST Rules for Vulnerabilities Your Scanner Doesn't Cover

Comments
8 min read
How I Modelled the OWASP Top 10 Into a YAML Rule Engine

How I Modelled the OWASP Top 10 Into a YAML Rule Engine

Comments
8 min read
Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web

Introducing a OWASP Game for threat modeling Agentic AI, Cloud, Devops, Frontend, LLM, Automation, and Web

1
Comments 1
10 min read
Best Snyk Alternatives in 2026: Which AppSec Tool Should You Choose?

Best Snyk Alternatives in 2026: Which AppSec Tool Should You Choose?

2
Comments 1
12 min read
SnowFROC 2026: Secure Defaults, Real Trust, and a Better Layer on Top

SnowFROC 2026: Secure Defaults, Real Trust, and a Better Layer on Top

Comments
10 min read
From a Single IP to Exfiltrated Passwords in a PNG: My First Freelance Pentest Engagement

From a Single IP to Exfiltrated Passwords in a PNG: My First Freelance Pentest Engagement

Comments
13 min read
60–80% of your CVEs are unreachable. Here's how to prove it.

60–80% of your CVEs are unreachable. Here's how to prove it.

1
Comments
4 min read
What AppSec Engineers Actually Do (and Why It Matters)

What AppSec Engineers Actually Do (and Why It Matters)

Comments
7 min read
If Your Security Scanner Can't See Attack Chains, You're Flying Blind

If Your Security Scanner Can't See Attack Chains, You're Flying Blind

Comments
5 min read
Secure System Design -- 14 Challenges

Secure System Design -- 14 Challenges

Comments
31 min read
From LOW to CRITICAL: How a 5-Step Vulnerability Chain Goes Undetected by Flat Scanners

From LOW to CRITICAL: How a 5-Step Vulnerability Chain Goes Undetected by Flat Scanners

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.