⤷ Title: Arbitrary File Write via Archive Extraction (Zip Slip)- OWASP Juiceshop #1
════════════════════════
𐀪 Author: DebianHat
════════════════════════
ⴵ Time: Mon, 31 Mar 2025 08:44:03 GMT
════════════════════════
⌗ Tags: #application_security #sast #vulnerability #secure_code_review #secure_coding
════════════════════════
𐀪 Author: DebianHat
════════════════════════
ⴵ Time: Mon, 31 Mar 2025 08:44:03 GMT
════════════════════════
⌗ Tags: #application_security #sast #vulnerability #secure_code_review #secure_coding
Medium
Arbitrary File Write via Archive Extraction (Zip Slip)- OWASP Juiceshop #1
Zip Slip is an another path traversal vulnerability that occurs when extracting ZIP (or other archive) files without properly validating…
⤷ Title: ☕ How to Perform a Secure Code Review Without Losing Your Mind (or Developer Friends)
════════════════════════
𐀪 Author: UnpluggedSec
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 19:54:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #secure_code_review #appsec #devsecops #application_security
════════════════════════
𐀪 Author: UnpluggedSec
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 19:54:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #secure_code_review #appsec #devsecops #application_security
Medium
☕ How to Perform a Secure Code Review Without Losing Your Mind (or Developer Friends)
By Ayman Abdul Kareem | Security Architecture | Senior Application Security Engineer | DevSecOps Advocate | chai-driven defender of cloud…
⤷ Title: Secure Web Development in Go: Preventing SQL Injection, XSS, and CSRF Attacks
════════════════════════
𐀪 Author: Nova Novriansyah
════════════════════════
ⴵ Time: Wed, 28 May 2025 03:43:07 GMT
════════════════════════
⌗ Tags: #xs #csrf #go #secure_code #golang
════════════════════════
𐀪 Author: Nova Novriansyah
════════════════════════
ⴵ Time: Wed, 28 May 2025 03:43:07 GMT
════════════════════════
⌗ Tags: #xs #csrf #go #secure_code #golang
Medium
Secure Web Development in Go: Preventing SQL Injection, XSS, and CSRF Attacks
When building web applications, security must be treated as a core requirement, not an afterthought. Many developers unintentionally expose…
⤷ Title: RoadMap: Source Code Analysis — White Box
════════════════════════
𐀪 Author: Shwajsophia
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 21:03:30 GMT
════════════════════════
⌗ Tags: #secure_coding #penetration_testing #code_review #white_box_testing #secure_code_review
════════════════════════
𐀪 Author: Shwajsophia
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 21:03:30 GMT
════════════════════════
⌗ Tags: #secure_coding #penetration_testing #code_review #white_box_testing #secure_code_review
Medium
RoadMap: Source Code Analysis — White Box
Soooooo — here is a secure code analysis roadmap, it could be short, but probably is going to be long, so sorry not sorry :)
⤷ Title: Hackers don’t knock. They exploit.
════════════════════════
𐀪 Author: Prishusoft
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 08:35:33 GMT
════════════════════════
⌗ Tags: #web_security #angular_security #cybersecurity #angular #secure_code
════════════════════════
𐀪 Author: Prishusoft
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 08:35:33 GMT
════════════════════════
⌗ Tags: #web_security #angular_security #cybersecurity #angular #secure_code
Medium
Hackers don’t knock. They exploit.
Are your Angular apps REALLY secure?
From XSS to API abuse — even the tiniest gap can cost BIG.
From XSS to API abuse — even the tiniest gap can cost BIG.
⤷ Title: How can Windsurf/Cursor help you with your secure code review?
════════════════════════
𐀪 Author: Cristian
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 19:08:59 GMT
════════════════════════
⌗ Tags: #cursor #secure_code_review #ai_agent #application_security #windsurf
════════════════════════
𐀪 Author: Cristian
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 19:08:59 GMT
════════════════════════
⌗ Tags: #cursor #secure_code_review #ai_agent #application_security #windsurf
Medium
How can Windsurf/Cursor help you with your secure code review?
Hello everyone, in this blog I want to talk about how editors with integrated AI features such as Windsurf / Cursor can help you analyze…
⤷ Title: Manual Source Code Review in SAST – My Experience Uncovering Critical Vulnerabilities
════════════════════════
𐀪 Author: Saritamukkani
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 07:32:57 GMT
════════════════════════
⌗ Tags: #secure_code_review #secure_coding #application_security #cybersecurity
════════════════════════
𐀪 Author: Saritamukkani
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 07:32:57 GMT
════════════════════════
⌗ Tags: #secure_code_review #secure_coding #application_security #cybersecurity
Medium
Manual Source Code Review in SAST – My Experience Uncovering Critical Vulnerabilities
As a cybersecurity analyst specializing in Static Application Security Testing (SAST), I spend a lot of my time analyzing application source code for security weaknesses before the software is…
⤷ Title: Secure Code Review: Automated and Manual Analysis Techniques
════════════════════════
𐀪 Author: Andrei Ivan
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 10:26:52 GMT
════════════════════════
⌗ Tags: #software_development #cybersecurity #secure_code #secure_coding #application_security
════════════════════════
𐀪 Author: Andrei Ivan
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 10:26:52 GMT
════════════════════════
⌗ Tags: #software_development #cybersecurity #secure_code #secure_coding #application_security
Medium
Secure Code Review: Automated and Manual Analysis Techniques
How to combine SAST, DAST, and human expertise to catch vulnerabilities automated tools miss
⤷ Title: Building a secure AI tool with Lovable, Gemini API and Cloudflare Workers
════════════════════════
𐀪 Author: h@shtalk
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 14:58:51 GMT
════════════════════════
⌗ Tags: #vibe_coding #secure_code_review #vibe_hacking #cybersecurity #secure_code
════════════════════════
𐀪 Author: h@shtalk
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 14:58:51 GMT
════════════════════════
⌗ Tags: #vibe_coding #secure_code_review #vibe_hacking #cybersecurity #secure_code
Medium
Building a secure AI tool with Lovable, Gemini API and Cloudflare Workers
This might be the easiest secure way to deploy an app within a day.
⤷ Title: Vibe coding! How AI is creating unexpected coding problems as it solves others.
════════════════════════
𐀪 Author: Yann Barba
════════════════════════
ⴵ Time: Fri, 24 Oct 2025 19:41:05 GMT
════════════════════════
⌗ Tags: #secure_code #it_security #cybersecurity
════════════════════════
𐀪 Author: Yann Barba
════════════════════════
ⴵ Time: Fri, 24 Oct 2025 19:41:05 GMT
════════════════════════
⌗ Tags: #secure_code #it_security #cybersecurity
Medium
Vibe coding! How AI is creating unexpected coding problems as it solves others.
AI is the new standard, and has been for a while now. Just like Yahoo or Google changed the way we navigated through the web back in the…
⤷ Title: Pwning Vibecoded Apps
════════════════════════
𐀪 Author: Florian Walter
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 12:10:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #vibe_coding #application_security #secure_code_review
════════════════════════
𐀪 Author: Florian Walter
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 12:10:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #vibe_coding #application_security #secure_code_review
Medium
Pwning Vibecoded Apps
What to expect in this article: A case study showing how easy it often is to pwn vibecoded apps.
⤷ Title: From Token to Takeover: Exploiting Weak HS256 Secrets (POC)
════════════════════════
𐀪 Author: Satheesh
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 07:09:15 GMT
════════════════════════
⌗ Tags: #secure_code_review #application_security #cybersecurity #jwt_exploitation #jwt_authentication
════════════════════════
𐀪 Author: Satheesh
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 07:09:15 GMT
════════════════════════
⌗ Tags: #secure_code_review #application_security #cybersecurity #jwt_exploitation #jwt_authentication
Medium
From Token to Takeover: Exploiting Weak HS256 Secrets (POC)
🔓 Cracking a Weak HS256 JWT: How I Forged a Token and Retrieved the Masterkey
⤷ Title: Security-First Development: Prompting for Secure Code (Before It’s Hacked)
════════════════════════
𐀪 Author: Kawaldeep Singh
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 12:32:18 GMT
════════════════════════
⌗ Tags: #security_first #secure_code #cybersecurity #best_practices #application_security
════════════════════════
𐀪 Author: Kawaldeep Singh
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 12:32:18 GMT
════════════════════════
⌗ Tags: #security_first #secure_code #cybersecurity #best_practices #application_security
Medium
Security-First Development: Prompting for Secure Code (Before It’s Hacked)
Your app launches. Users sign up. Everything works.
⤷ Title: Why Most Developers Accidentally Create Security Holes
════════════════════════
𐀪 Author: Hania Khan
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:12:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #secure_code #cyber_security_awareness #infosec #technology
════════════════════════
𐀪 Author: Hania Khan
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:12:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #secure_code #cyber_security_awareness #infosec #technology
Medium
Why Most Developers Accidentally Create Security Holes
I pushed a secret API key to GitHub. 3,000 people downloaded it before I noticed.
⤷ Title: CVE Hunting via Github Dorking
════════════════════════
𐀪 Author: Abhirup Konwar
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 13:55:42 GMT
════════════════════════
⌗ Tags: #cve #ethical_hacking #php_security #secure_code_review #programming
════════════════════════
𐀪 Author: Abhirup Konwar
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 13:55:42 GMT
════════════════════════
⌗ Tags: #cve #ethical_hacking #php_security #secure_code_review #programming
Medium
CVE Hunting via Github Dorking
Finding 0 days in PHP Open Source Code
⤷ Title: Building a Real Python Security Project with Bandit (macOS Terminal Walkthrough)
════════════════════════
𐀪 Author: Priyanshu Manash
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 13:59:28 GMT
════════════════════════
⌗ Tags: #xss_attack #sql_injection #vulnerability #secure_code_review #bandit
════════════════════════
𐀪 Author: Priyanshu Manash
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 13:59:28 GMT
════════════════════════
⌗ Tags: #xss_attack #sql_injection #vulnerability #secure_code_review #bandit
Medium
Building a Real Python Security Project with Bandit (macOS Terminal Walkthrough)
Static Application Security Testing (SAST) isn’t just theory. In this article, I’ll walk through building a real, hands-on Python security…
⤷ Title: Finding 0 days using Codex
════════════════════════
𐀪 Author: Abhirup Konwar
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 03:54:22 GMT
════════════════════════
⌗ Tags: #xcode #openai_codex #chatgpt #hacking #secure_code_review
════════════════════════
𐀪 Author: Abhirup Konwar
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 03:54:22 GMT
════════════════════════
⌗ Tags: #xcode #openai_codex #chatgpt #hacking #secure_code_review
Medium
Finding 0 days using Codex
Can codex help you in secure code review ?
⤷ Title: How to Find Real Vulnerabilities Using Source -> Flow -> Sink
════════════════════════
𐀪 Author: Suraj Vishwakarma
════════════════════════
ⴵ Time: Sat, 25 Apr 2026 10:10:51 GMT
════════════════════════
⌗ Tags: #application_security #attack_chain #red_team #secure_code_review #sast
════════════════════════
𐀪 Author: Suraj Vishwakarma
════════════════════════
ⴵ Time: Sat, 25 Apr 2026 10:10:51 GMT
════════════════════════
⌗ Tags: #application_security #attack_chain #red_team #secure_code_review #sast
Medium
How to Find Real Vulnerabilities Using Source -> Flow -> Sink
There are several mental models worth building as a security engineer. This is one of the more practical ones — and one that’s often…
⤷ Title: Remote Code Execution (RCE) from a Secure Code Review Perspective
════════════════════════
𐀪 Author: Aryah
════════════════════════
ⴵ Time: Sun, 17 May 2026 12:03:55 GMT
════════════════════════
⌗ Tags: #appsec #vulnerability #secure_code_review #rce
════════════════════════
𐀪 Author: Aryah
════════════════════════
ⴵ Time: Sun, 17 May 2026 12:03:55 GMT
════════════════════════
⌗ Tags: #appsec #vulnerability #secure_code_review #rce
Medium
Remote Code Execution (RCE) from a Secure Code Review Perspective
I know It’s been a long time since I published anything related to secure code review.After taking a break, everything felt new again. Busy…
⤷ Title: Can AI write secure code? I audited 50 AI-Generated snippets
════════════════════════
𐀪 Author: h@shtalk
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 10:41:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #secure_code_review #ai #infosec
════════════════════════
𐀪 Author: h@shtalk
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 10:41:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #secure_code_review #ai #infosec
Medium
Can AI write secure code? I audited 50 AI-Generated snippets
A real, hands-on audit — methodology, sources, and the actual code, broken down line by line.