Appsec Village

How to Prioritize Firmware Vulnerabilities for CRA Compliance

How to Prioritize Firmware Vulnerabilities for ...

Firmware scanners can return tens of thousands of CVEs, but the EU Cyber Resilience Act (CRA) expects remediation decisions to be risk-based, proportionate, and documented. How do you find the...

How to Prioritize Firmware Vulnerabilities for ...

Firmware scanners can return tens of thousands of CVEs, but the EU Cyber Resilience Act (CRA) expects remediation decisions to be risk-based, proportionate, and documented. How do you find the...

Claude x Security Engineering: From POC to Production

Claude x Security Engineering: From POC to Prod...

You can't just drop Claude into your security workflow. So how do you harness it to truly scale security and go beyond the hype? Tristan Kalos (Co-Founder and CEO, Escape)...

Claude x Security Engineering: From POC to Prod...

You can't just drop Claude into your security workflow. So how do you harness it to truly scale security and go beyond the hype? Tristan Kalos (Co-Founder and CEO, Escape)...

Cloud Application Detection and Response (CADR) For Dummies

Cloud Application Detection and Response (CADR)...

Firewalls. EDR. CWPP. CNAPP. Each solved a piece of the puzzle, but attackers keep finding the gaps. The new "CADR For Dummies" guide breaks down why runtime visibility is the...

Cloud Application Detection and Response (CADR)...

Firewalls. EDR. CWPP. CNAPP. Each solved a piece of the puzzle, but attackers keep finding the gaps. The new "CADR For Dummies" guide breaks down why runtime visibility is the...

State of AI in Pentesting 2026

State of AI in Pentesting 2026

The average pentest validates a system that stopped existing weeks ago, because the code kept shipping after the testers went home. Our sponsor, @Aikido Security, asked 400 security and engineering...

State of AI in Pentesting 2026

The average pentest validates a system that stopped existing weeks ago, because the code kept shipping after the testers went home. Our sponsor, @Aikido Security, asked 400 security and engineering...

10 AI Supply Chain Risks Hiding in Your Codebase, and How to Get Ahead of Them

10 AI Supply Chain Risks Hiding in Your Codebas...

As organizations rapidly adopt AI, new components, including models, agents, MCP servers, prompts, datasets, and hosted AI services, are becoming part of the software supply chain. Many of them exist...

10 AI Supply Chain Risks Hiding in Your Codebas...

As organizations rapidly adopt AI, new components, including models, agents, MCP servers, prompts, datasets, and hosted AI services, are becoming part of the software supply chain. Many of them exist...

The malware dating guide: Understanding the types of malware on NPM

The malware dating guide: Understanding the typ...

You’ve heard of red flags in dating… but what about in your npm install? Our friends at Aikido Security just dropped the Malware Dating Guide. A brilliant (and hilarious) breakdown...

The malware dating guide: Understanding the typ...

You’ve heard of red flags in dating… but what about in your npm install? Our friends at Aikido Security just dropped the Malware Dating Guide. A brilliant (and hilarious) breakdown...