Security Learning Center

Your comprehensive guide to AI coding security, ACSM, and modern application security concepts.

Traditional Security

Application Security (AppSec) Fundamentals

Application security focuses on finding, fixing, and preventing security vulnerabilities in software applications throughout their lifecycle.

AppSecapplication securitysoftware security

Cross-Site Scripting (XSS)

Cross-site scripting allows attackers to inject malicious scripts into web pages viewed by other users. Learn about the different types and how to prevent them.

XSScross-site scriptingweb security

DevSecOps: Integrating Security into CI/CD

DevSecOps integrates security practices into the software development lifecycle, automating security testing and making it part of the development workflow.

DevSecOpsCI/CD securityshift left

Infrastructure Scanning and Configuration Security

Infrastructure scanning tools analyze configuration files for security misconfigurations in cloud resources, containers, and infrastructure-as-code templates.

infrastructure scanningIaC securitycloud security

Secrets Detection: Preventing Credential Leaks

Secrets detection tools scan code and commits for accidentally exposed credentials, API keys, and other sensitive data before they reach version control.

secrets detectioncredential scanningAPI key security

Software Supply Chain Security

Supply chain attacks target the dependencies and build processes that software relies on. Learn about the risks and how to protect your projects.

supply chain securitydependency securitynpm security

SQL Injection Prevention

SQL injection occurs when user input is improperly included in database queries, allowing attackers to manipulate or extract data. Learn how it works and how to prevent it.

SQL injectionSQLidatabase security

Vulnerability Management Best Practices

Vulnerability management is the process of identifying, evaluating, and addressing security vulnerabilities in software and systems.

vulnerability managementsecurity operationsrisk management

What is Common Weakness Enumeration (CWE)?

CWE is a community-developed list of software and hardware weakness types, providing a common language for describing security vulnerabilities.

CWECommon Weakness Enumerationvulnerability types

What is Dynamic Application Security Testing (DAST)?

DAST tests running applications by simulating attacks to find runtime vulnerabilities like authentication issues and server misconfigurations.

DASTdynamic testingruntime security

What is Interactive Application Security Testing (IAST)?

IAST combines aspects of static and dynamic testing, analyzing applications from within during runtime to identify vulnerabilities with higher accuracy.

IASTinteractive testingruntime analysis

What is Software Composition Analysis (SCA)?

Software Composition Analysis identifies vulnerabilities and license issues in open source dependencies, helping teams manage the risks of third-party code.

SCAsoftware composition analysisdependency scanning

What is Static Application Security Testing (SAST)?

SAST analyzes source code to identify security vulnerabilities without executing the program, helping teams find issues early in development.

SASTstatic analysiscode scanning

What is the OWASP Top 10?

The OWASP Top 10 is a regularly updated list of the most critical web application security risks, serving as a standard awareness document for developers.

OWASPOWASP Top 10web security