⤷ Title: Packing/Unpacking in Malware Analysis and Scanners
════════════════════════
𐀪 Author: Chris Zhang
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 22:45:46 GMT
════════════════════════
⌗ Tags: #static_code_analysis #malware_analysis #computer_science #cybersecurity #malware
════════════════════════
𐀪 Author: Chris Zhang
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 22:45:46 GMT
════════════════════════
⌗ Tags: #static_code_analysis #malware_analysis #computer_science #cybersecurity #malware
Medium
Packing/Unpacking in Malware Analysis and Scanners
Malware authors are in a constant arms race with security researchers and antivirus scanners. To stay ahead, they often use packing — a…
⤷ Title: Exploiting Logic Flaws & Zip Slips: A Walkthrough of “Desires” on Hack The Box
════════════════════════
𐀪 Author: Muhammad Younas
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:08:08 GMT
════════════════════════
⌗ Tags: #penetration_testing #hackthebox_writeup #hackthebox #desire #static_code_analysis
════════════════════════
𐀪 Author: Muhammad Younas
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:08:08 GMT
════════════════════════
⌗ Tags: #penetration_testing #hackthebox_writeup #hackthebox #desire #static_code_analysis
Medium
Exploiting Logic Flaws & Zip Slips: A Walkthrough of “Desires” on Hack The Box
Category: Web | Difficulty: Easy (But I think it should be a Medium Difficulty :) )
⤷ Title: Statik Kod Analiz Metadolojisi ve Güvenlik Stratejileri
════════════════════════
𐀪 Author: suna ayaz
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 09:39:56 GMT
════════════════════════
⌗ Tags: #application_security #static_code_analysis
════════════════════════
𐀪 Author: suna ayaz
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 09:39:56 GMT
════════════════════════
⌗ Tags: #application_security #static_code_analysis
Medium
Statik Kod Analiz Metadolojisi ve Güvenlik Stratejileri
Yazılım geliştirme süreçlerinde ortaya çıkarılan uygulamalarının amaçlarına yönelik ve hatasız çalışabilmesi için bu uygulamanın…
⤷ Title: WP-Hunter: Smarter WordPress Recon with Heuristic Scoring + Semgrep SAST
════════════════════════
𐀪 Author: Ali Sünbül (xeloxa)
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 09:23:38 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #wordpress #cybersecurity #static_code_analysis #ai
════════════════════════
𐀪 Author: Ali Sünbül (xeloxa)
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 09:23:38 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #wordpress #cybersecurity #static_code_analysis #ai
Medium
WP-Hunter: Smarter WordPress Recon with Heuristic Scoring + Semgrep SAST
Github: https://github.com/xeloxa/wp-hunter
⤷ Title: Four Tools, Three Machines, One Question
════════════════════════
𐀪 Author: Andrew Kutuzov
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 16:31:00 GMT
════════════════════════
⌗ Tags: #ai #cursor #claude_code #application_security #static_code_analysis
════════════════════════
𐀪 Author: Andrew Kutuzov
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 16:31:00 GMT
════════════════════════
⌗ Tags: #ai #cursor #claude_code #application_security #static_code_analysis
Medium
Four Tools, Three Machines, One Question
There’s a lot of noise right now about AI replacing traditional SAST tools — and honestly, it’s hard to dismiss entirely. But it’s also…
⤷ Title: When Static Analysis Turns Dangerous: Command Injection in NASA’s Cobra Tool
════════════════════════
𐀪 Author: dark-haxor
════════════════════════
ⴵ Time: Sun, 05 Apr 2026 19:20:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #cobra #static_code_analyzer #penetration_testing #static_code_analysis
════════════════════════
𐀪 Author: dark-haxor
════════════════════════
ⴵ Time: Sun, 05 Apr 2026 19:20:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #cobra #static_code_analyzer #penetration_testing #static_code_analysis
Medium
🐍 When Static Analysis Turns Dangerous: Command Injection in NASA’s Cobra Tool
What is Cobra?
⤷ Title: How to Build a World-Class SAST Program from Scratch
════════════════════════
𐀪 Author: Vikrant Waghmode
════════════════════════
ⴵ Time: Wed, 06 May 2026 21:44:00 GMT
════════════════════════
⌗ Tags: #semgrep #application_security #cybersecurity #static_code_analysis
════════════════════════
𐀪 Author: Vikrant Waghmode
════════════════════════
ⴵ Time: Wed, 06 May 2026 21:44:00 GMT
════════════════════════
⌗ Tags: #semgrep #application_security #cybersecurity #static_code_analysis
Medium
How to Build a World-Class SAST Program from Scratch
A practitioner’s guide to transforming static analysis security testing — from creating the vision to selecting the right tools through…
⤷ Title: From Deep Link to Shell: Easy $3000 Android Crits.
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 23:19:13 GMT
════════════════════════
⌗ Tags: #android #hackerone #static_code_analysis #rce #deeplink
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 23:19:13 GMT
════════════════════════
⌗ Tags: #android #hackerone #static_code_analysis #rce #deeplink
Medium
From Deep Link to Shell: Easy $3000 Android Crits.
Akwaaba! gang, another part of my Static Android App Hacking series, today our focus is on exploiting Deep Links to achieve RCE. An easy…
⤷ Title: Day 26: Cross-Site Scripting (XSS) - Hacker Sidekick Certified Vibe Hacker CTF Walkthrough
════════════════════════
𐀪 Author: Sofia Batala
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 04:08:16 GMT
════════════════════════
⌗ Tags: #xss_attack #xss_vulnerability #hacker_sidekick #static_code_analysis #ctf
════════════════════════
𐀪 Author: Sofia Batala
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 04:08:16 GMT
════════════════════════
⌗ Tags: #xss_attack #xss_vulnerability #hacker_sidekick #static_code_analysis #ctf
Medium
Day 26: Cross-Site Scripting (XSS) - Hacker Sidekick Certified Vibe Hacker CTF Walkthrough
## Challenge: User-provided data is rendered in HTML templates without proper encoding, allowing JavaScript injection attacks. What…
⤷ Title: Build Self-Hosted SAST with pipeline DefectDojo
════════════════════════
𐀪 Author: Rizqi Ramadhan Andriono
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 13:41:47 GMT
════════════════════════
⌗ Tags: #defectdojo #static_code_analysis #security #penetration_testing #sonarqube
════════════════════════
𐀪 Author: Rizqi Ramadhan Andriono
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 13:41:47 GMT
════════════════════════
⌗ Tags: #defectdojo #static_code_analysis #security #penetration_testing #sonarqube
Medium
Build Self-Hosted SAST with pipeline DefectDojo
Static application security testing with DefectDojo as main dashboard using open source tools; SonarQube Community version, , OSV, Semgrep…