Visit HackEDU

HackEDU Blog

Stay up to date

Topic: Application Security

Application Security PCI Compliance

How to Go Beyond PCI Compliance to Secure Your Organization: Introduction

Introduction In 2000, the number of websites skyrocketed to 17 million, with more than 400 million internet users. Shortly after, a quickly increasing number of online stores came online....

Continue Reading

software security Application Security DevSecOps

Same-Origin Policy And Cross-Origin Resource Sharing (CORS)

Introduction Modern web browsers provide many built-in security mechanisms to defend against attackers. Same-origin policy, Cookie Policy, Content Security Policy, browser sandbox, and XSS...

Continue Reading

Secure Coding Training software security Application Security

What is a Secure Software Development Lifecycle & how do you build an appsec program?

And how do you build an application security program? Software development follows what is called a Software Development Lifecycle, or S D L C. It is a process used for developing software....

Continue Reading

Secure Coding Training Secure Development Training Application Security

Why You Need a Vulnerability Disclosure Response Plan & How to Develop One

Background Most companies have an Incident Response Plan these days. With an increasing number of data breaches, having a plan in place is important so that all stakeholders (Security,...

Continue Reading

Secure Coding Training software security Application Security

Common Federated Identity Protocols: OpenID Connect vs OAuth vs SAML 2

Introduction When it comes to federated identity there are three major protocols used by companies: OAuth 2, OpenID Connect, and SAML. In this article we will examine their security...

Continue Reading

Application Security DevSecOps

DevSecOps Best Practices

You’ve decided to integrate DevSecOps into your software development operations. That’s an important first step to improving your product’s overall security by including it into the...

Continue Reading

Application Security DevSecOps

What Is DevSecOps?

DevOps, that combination of software development and IT operations, is designed to improve the development life cycle, getting software to market quicker and improve overall deployment. But...

Continue Reading

Application Security Security Champion

What Are Security Champion Responsibilities?

Your company has decided to add security champions to improve your overall security postures, and you’ve chosen great candidates to take on this role. The next step is to define the...

Continue Reading

Secure Coding Training Secure Development Training Application Security

Apache Struts 2 Namespace (CVE-2018-11776) Vulnerability

Click here to try hacking the Struts 2 Vulnerability and learn more with HackEDU's hands-on Struts 2 application. Introduction On 22 August 2018, a Semmle security researcher disclosed a...

Continue Reading

Application Security Security Champion

How Do You Select Security Champions?

Security champions should be an integral part of your security team. When this position was first introduced five or so years ago as part of the cybersecurity structure, the security...

Continue Reading

Stay up to date