⤷ Title: Arbitrary File Write via Archive Extraction (Zip Slip)- OWASP Juiceshop #1
════════════════════════
𐀪 Author: DebianHat
════════════════════════
ⴵ Time: Mon, 31 Mar 2025 08:44:03 GMT
════════════════════════
⌗ Tags: #application_security #sast #vulnerability #secure_code_review #secure_coding
════════════════════════
𐀪 Author: DebianHat
════════════════════════
ⴵ Time: Mon, 31 Mar 2025 08:44:03 GMT
════════════════════════
⌗ Tags: #application_security #sast #vulnerability #secure_code_review #secure_coding
Medium
Arbitrary File Write via Archive Extraction (Zip Slip)- OWASP Juiceshop #1
Zip Slip is an another path traversal vulnerability that occurs when extracting ZIP (or other archive) files without properly validating…
⤷ Title: Gerçek Hayattan SDLC Süreci: Uçtan Uca Güvenlik Kültürü Nasıl İnşa Edilir?
════════════════════════
𐀪 Author: Melih Tuncc
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 13:11:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #sdlc #sast #devsecops
════════════════════════
𐀪 Author: Melih Tuncc
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 13:11:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #sdlc #sast #devsecops
Medium
Gerçek Hayattan SDLC Süreci: Uçtan Uca Güvenlik Kültürü Nasıl İnşa Edilir?
Güvenlik, yalnızca geliştirme sürecinin sonunda yapılan bir test değildir; yazılım geliştirme yaşam döngüsünün (SDLC) her aşamasına entegre…
⤷ Title: Fortify-Open Text SAST Detailed Installation Guide (Windows & Linux)
════════════════════════
𐀪 Author: Kerem
════════════════════════
ⴵ Time: Thu, 08 May 2025 13:25:00 GMT
════════════════════════
⌗ Tags: #application_security #code_analysis #devsecops #sast #cybersecurity
════════════════════════
𐀪 Author: Kerem
════════════════════════
ⴵ Time: Thu, 08 May 2025 13:25:00 GMT
════════════════════════
⌗ Tags: #application_security #code_analysis #devsecops #sast #cybersecurity
Medium
Fortify-Open Text SAST Detailed Installation Guide (Windows & Linux)
Contents
⤷ Title: Secure Coding Part 3 : Input Validation
════════════════════════
𐀪 Author: Siddiquimohammad
════════════════════════
ⴵ Time: Fri, 23 May 2025 21:21:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #sast #secure_coding #shift_left_testing
════════════════════════
𐀪 Author: Siddiquimohammad
════════════════════════
ⴵ Time: Fri, 23 May 2025 21:21:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #sast #secure_coding #shift_left_testing
Medium
Secure Coding Part 3 : Input Validation
Previous Part — Secure Coding Part 2 : OWASP CHECKLIST
⤷ Title: Boost Your GitHub Actions Security with sisakulint: Fast SAST for YAML
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 07 Jun 2025 00:17:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #blue team #CI/CD Security #cybersecurity #GitHub Actions #OWASP #SAST #security tool #sisakulint #Static Analysis #YAML
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 07 Jun 2025 00:17:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #blue team #CI/CD Security #cybersecurity #GitHub Actions #OWASP #SAST #security tool #sisakulint #Static Analysis #YAML
Penetration Testing Tools
Boost Your GitHub Actions Security with sisakulint: Fast SAST for YAML
Discover sisakulint, a fast SAST tool for GitHub Actions. It validates YAML files against security guidelines, prevents malicious code, and supports autofix.
⤷ Title: GitHub Actions: SAST / DAST scan
════════════════════════
𐀪 Author: Nejat Nebizade
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 14:16:18 GMT
════════════════════════
⌗ Tags: #application_security #sast #gh_actions #ci_cd_pipeline #dast
════════════════════════
𐀪 Author: Nejat Nebizade
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 14:16:18 GMT
════════════════════════
⌗ Tags: #application_security #sast #gh_actions #ci_cd_pipeline #dast
Medium
GitHub Actions: SAST / DAST scan
Bu məqalədə GitHub Actions vasitəsilə Snyk SAST skan və OWASP ZAP Baseline DAST scan-ın aparılmasından bəhs edilir.
⤷ Title: Secure Coding Part 5: Command Injection — Type
════════════════════════
𐀪 Author: Siddiquimohammad
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 13:30:54 GMT
════════════════════════
⌗ Tags: #command_injection #application_security #sast #secure_coding #code_security
════════════════════════
𐀪 Author: Siddiquimohammad
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 13:30:54 GMT
════════════════════════
⌗ Tags: #command_injection #application_security #sast #secure_coding #code_security
Medium
Secure Coding Part 5: Command Injection — Type
Previous Part — Secure Coding Part 4: Command Injection — Introduction
⤷ Title: SOURCE CODE REVIEW — HIVE AIRPORT
════════════════════════
𐀪 Author: Easpy
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 01:48:28 GMT
════════════════════════
⌗ Tags: #penetration_testing #source_code_review #web_penetration_testing #information_security #sast
════════════════════════
𐀪 Author: Easpy
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 01:48:28 GMT
════════════════════════
⌗ Tags: #penetration_testing #source_code_review #web_penetration_testing #information_security #sast
Medium
SOURCE CODE REVIEW — HIVE AIRPORT
Tulisan ini saya buat khususnya untuk saya pribadi dan umumnya untuk pembaca. Saya membuat tulisan ini dikarenakan saya ingin mempelajari…
⤷ Title: Choosing the Right SAST Tool: A Practical Guide for Developers
════════════════════════
𐀪 Author: Aamir Sk
════════════════════════
ⴵ Time: Sun, 24 Aug 2025 15:09:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #sast #application_security #devsecops
════════════════════════
𐀪 Author: Aamir Sk
════════════════════════
ⴵ Time: Sun, 24 Aug 2025 15:09:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #sast #application_security #devsecops
Medium
Choosing the Right SAST Tool: A Practical Guide for Developers
Static Application Security Testing (SAST) is one of the earliest and most effective defenses in the DevSecOps lifecycle. By scanning…
⤷ Title: Establishing DevSecOps for Small and Medium Organizations: Practical Controls, Challenges, and…
════════════════════════
𐀪 Author: Secnuo Consulting (OPC) Private Limited
════════════════════════
ⴵ Time: Thu, 28 Aug 2025 11:52:53 GMT
════════════════════════
⌗ Tags: #application_security #devsecops #cybersecurity #sast #dast
════════════════════════
𐀪 Author: Secnuo Consulting (OPC) Private Limited
════════════════════════
ⴵ Time: Thu, 28 Aug 2025 11:52:53 GMT
════════════════════════
⌗ Tags: #application_security #devsecops #cybersecurity #sast #dast
Medium
Establishing DevSecOps for Small and Medium Organizations: Practical Controls, Challenges, and Solutions
By Arvind Chauhan, Lead Consultant (Cyber Risk Services) at Secnuo.
⤷ Title: How Next‑Gen SAST & DAST Tools Are Unblocking DevOps — 8 Platforms That Actually Ship Secure…
════════════════════════
𐀪 Author: Iliya Garakh
════════════════════════
ⴵ Time: Thu, 04 Sep 2025 10:05:15 GMT
════════════════════════
⌗ Tags: #sast #devops #dast #application_security #api_security
════════════════════════
𐀪 Author: Iliya Garakh
════════════════════════
ⴵ Time: Thu, 04 Sep 2025 10:05:15 GMT
════════════════════════
⌗ Tags: #sast #devops #dast #application_security #api_security
Medium
How Next‑Gen SAST & DAST Tools Are Unblocking DevOps — 8 Platforms That Actually Ship Secure…
From eight‑hour scans to minute‑level feedback — developer-first security for modern microservices and CI/CD
⤷ Title: EXPLICATION SAST, SCA & CONTAINER SCAN
════════════════════════
𐀪 Author: dassimanuel000
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 13:36:18 GMT
════════════════════════
⌗ Tags: #sast #security #cybersecurity #devsecops #automation
════════════════════════
𐀪 Author: dassimanuel000
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 13:36:18 GMT
════════════════════════
⌗ Tags: #sast #security #cybersecurity #devsecops #automation
Medium
🔍 EXPLICATION SAST, SCA & CONTAINER SCAN
1. 🔍 SAST (Static Application Security Testing)
⤷ Title: Bypassing SSL/TLS Verification in GitGuardian’s GGShield: A Practical Security Analysis
════════════════════════
𐀪 Author: Tanish Saxena
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 07:56:18 GMT
════════════════════════
⌗ Tags: #sast #vulnerability_research #application_security #cybersecurity #devsecops
════════════════════════
𐀪 Author: Tanish Saxena
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 07:56:18 GMT
════════════════════════
⌗ Tags: #sast #vulnerability_research #application_security #cybersecurity #devsecops
Medium
🔓 Bypassing SSL/TLS Verification in GitGuardian’s GGShield: A Practical Security Analysis
By: Tanish Saxena Security Researcher — November 2025
⤷ Title: BugTrace-AI: The Comprehensive AI-Powered Suite for SAST, DAST, and Vulnerability Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:13:15 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BugTrace_AI #DAST #DOM XSS #Generative AI #JWT Auditor #Penetration Testing #SAST #Vulnerability Analysis #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:13:15 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BugTrace_AI #DAST #DOM XSS #Generative AI #JWT Auditor #Penetration Testing #SAST #Vulnerability Analysis #web security
Penetration Testing Tools
BugTrace-AI: The Comprehensive AI-Powered Suite for SAST, DAST, and Vulnerability Research
BugTrace-AI is an AI-powered vulnerability suite for developers and pentesters, offering SAST/DAST, DOM XSS pathfinding, and WAF-bypassing payload generation in one interface.
⤷ Title: How I Built a DevSecOps Pipeline That Catches Vulnerabilities Before They Hit Production
════════════════════════
𐀪 Author: Abed
════════════════════════
ⴵ Time: Sat, 21 Feb 2026 09:57:42 GMT
════════════════════════
⌗ Tags: #sast #gitlab #ci_cd_pipeline #devsecops #application_security
════════════════════════
𐀪 Author: Abed
════════════════════════
ⴵ Time: Sat, 21 Feb 2026 09:57:42 GMT
════════════════════════
⌗ Tags: #sast #gitlab #ci_cd_pipeline #devsecops #application_security
Medium
How I Built a DevSecOps Pipeline That Catches Vulnerabilities Before They Hit Production
A hands-on guide to secret scanning, SAST, SCA, and automated vulnerability management with real GitLab CI configs and the offensive…
⤷ Title: Why SAST is Broken!
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
ⴵ Time: Sun, 22 Feb 2026 09:54:56 GMT
════════════════════════
⌗ Tags: #sast #application_security #appsec #secure_coding
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
ⴵ Time: Sun, 22 Feb 2026 09:54:56 GMT
════════════════════════
⌗ Tags: #sast #application_security #appsec #secure_coding
Medium
Why SAST is Broken!
Why SAST is broken, and how it could be addressed
⤷ Title: SAST vs Claude Code Security: A Deep Dive
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 11:01:41 GMT
════════════════════════
⌗ Tags: #claude_code #sast #application_security
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 11:01:41 GMT
════════════════════════
⌗ Tags: #claude_code #sast #application_security
Medium
SAST vs Claude Code Security: A Deep Dive
In my previous post on Why SAST is Broken!, we explored some of the challenges and limitations of traditional static analysis tools. Now…
⤷ Title: Android Static Application Security Testing
════════════════════════
𐀪 Author: Tandelpruthvi
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 06:51:31 GMT
════════════════════════
⌗ Tags: #android_security_testing #android_apk_analysis #sast #penetration_testing #owasp_mobile_security
════════════════════════
𐀪 Author: Tandelpruthvi
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 06:51:31 GMT
════════════════════════
⌗ Tags: #android_security_testing #android_apk_analysis #sast #penetration_testing #owasp_mobile_security
Medium
Android Static Application Security Testing
Android applications are widely used for banking, social media, e-commerce, and many other services. These apps often handle sensitive…
⤷ Title: Control Drift: Why Your SOC 2 Compliance Can’t Keep Up With AI Written Code
════════════════════════
𐀪 Author: Jost Faganel
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 07:43:18 GMT
════════════════════════
⌗ Tags: #ai_generated_code #control_drift #application_security #sast #soc_2_compliance
════════════════════════
𐀪 Author: Jost Faganel
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 07:43:18 GMT
════════════════════════
⌗ Tags: #ai_generated_code #control_drift #application_security #sast #soc_2_compliance
Medium
Control Drift: Why Your SOC 2 Compliance Can’t Keep Up With AI Written Code
I’ve been thinking about compliance lately. A lot. Not in the way most people think about it — not the annual audit, not the checklist, not…
⤷ Title: TryHackMe SAST Walkthrough
════════════════════════
𐀪 Author: Rormsbee
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 21:24:04 GMT
════════════════════════
⌗ Tags: #code_review #sast #application_security #tryhackme_walkthrough #cybersecurity_training
════════════════════════
𐀪 Author: Rormsbee
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 21:24:04 GMT
════════════════════════
⌗ Tags: #code_review #sast #application_security #tryhackme_walkthrough #cybersecurity_training
Medium
TryHackMe SAST Walkthrough
Task 2: Code Review