Category: Code Security

The CWE Top 25

The CWE Top 25: What It Is and Why It’s Not the Same as the OWASP Top 10

One ranks weaknesses, the other ranks risks. What the CWE Top 25 measures, how it differs from OWASP Top 10, and when to use each.
10 min read
API Security Best Practices

API Security Best Practices: A Developer’s Checklist

API security best practices developers actually need: a practical checklist covering API protection and API management, before deployment.
10 min read
Code Quality Check vs. Code Security Check

Code Quality Check vs. Code Security Check: What’s the Difference?

Code quality checks and code security checks measure different things. See now what each catches, and how to run both from one platform.
8 min read
API Security

API Security Has Been a Runtime Problem. It Doesn’t Have to Be

Most API security tools catch risk after it's live. Static analysis mapped to the OWASP API Top 10 catches it in the pull request instead.
AI Attack Surface

The AI Attack Surface Nobody Is Taking into Account

Your AI attack surface grows with every agent-written line of code. See how slopsquatting & poisoned skills exploit it & how to close the gap
8 min read
code-quality-scanner-appsec

Code Quality and Code Security Have Been Living in Two Different Tools. They Don’t Have To.

Code smells & vulnerabilities live in the same codebase but get scanned by different tools. See how our Code Quality scanner closes that gap
7 min read
ReDoS

ReDoS Explained: What Regular Expression DoS Is and How to Prevent It

ReDoS attacks can crash your apps. Discover how vulnerable regex patterns work and how to detect and prevent them with modern AppSec practices.
9 min read
Autofix in AppSec

Autofix in AppSec: How to Remediate Vulnerabilities Without Breaking Builds

Autofix in AppSec helps remediate vulnerabilities automatically while avoiding breaking changes. Learn how to fix issues safely in DevSecOps.
15 min read
Mobile App Security

Mobile App Security with Swift and Kotlin SAST

Strengthen mobile app security with native Swift SAST and Kotlin SAST, optimized for OWASP Mobile Top 10 and CI/CD integration.
5 min read
Vibe Coding Security Risks

AI for Coding Explained: 10 Simple Answers Developers Need

Vibe coding, AI for coding y sus riesgos de seguridad: descubre cómo proteger tu código de los AI-generated code security risks.
6 min read
Agentic AI The Complete Guide

Agentic AI: The Complete Guide for Developers, AI Engineers, and AppSec Teams

Learn what agentic AI is and how AI agent platforms and AI coding agents work, including key risks and security practices for DevSecOps.
11 min read
task.run c# - async programming - parallel execution

Task.Run in C#: The Wrong Way to Parallelize Secure Code

Learn how misusing task.run c# breaks async programming and parallel execution, creating security and stability risks in our post!