Appsec Village

Cloud Application Detection and Response (CADR) For Dummies

Cloud Application Detection and Response (CADR)...

Firewalls. EDR. CWPP. CNAPP. Each solved a piece of the puzzle, but attackers keep finding the gaps. The new "CADR For Dummies" guide breaks down why runtime visibility is the...

Cloud Application Detection and Response (CADR)...

Firewalls. EDR. CWPP. CNAPP. Each solved a piece of the puzzle, but attackers keep finding the gaps. The new "CADR For Dummies" guide breaks down why runtime visibility is the...

State of AI in Pentesting 2026

State of AI in Pentesting 2026

The average pentest validates a system that stopped existing weeks ago, because the code kept shipping after the testers went home. Our sponsor, @Aikido Security, asked 400 security and engineering...

State of AI in Pentesting 2026

The average pentest validates a system that stopped existing weeks ago, because the code kept shipping after the testers went home. Our sponsor, @Aikido Security, asked 400 security and engineering...

10 AI Supply Chain Risks Hiding in Your Codebase, and How to Get Ahead of Them

10 AI Supply Chain Risks Hiding in Your Codebas...

As organizations rapidly adopt AI, new components, including models, agents, MCP servers, prompts, datasets, and hosted AI services, are becoming part of the software supply chain. Many of them exist...

10 AI Supply Chain Risks Hiding in Your Codebas...

As organizations rapidly adopt AI, new components, including models, agents, MCP servers, prompts, datasets, and hosted AI services, are becoming part of the software supply chain. Many of them exist...

The malware dating guide: Understanding the types of malware on NPM

The malware dating guide: Understanding the typ...

You’ve heard of red flags in dating… but what about in your npm install? Our friends at Aikido Security just dropped the Malware Dating Guide. A brilliant (and hilarious) breakdown...

The malware dating guide: Understanding the typ...

You’ve heard of red flags in dating… but what about in your npm install? Our friends at Aikido Security just dropped the Malware Dating Guide. A brilliant (and hilarious) breakdown...

What’s Broken in Cybersecurity - and How Developer-First Security Can Fix It

What’s Broken in Cybersecurity - and How Develo...

What Does “Developer-First Security” Actually Look Like in Practice? This article cuts through the buzzwords to unpack what developer-first security really means—and why most current approaches fall short. It’s not...

What’s Broken in Cybersecurity - and How Develo...

What Does “Developer-First Security” Actually Look Like in Practice? This article cuts through the buzzwords to unpack what developer-first security really means—and why most current approaches fall short. It’s not...

Proven Strategies to Unlock Developer Adoption of AppSec

Proven Strategies to Unlock Developer Adoption ...

Strong developer buy-in is one of the most crucial ways AppSec managers can effectively fix vulnerabilities. But how can you get your dev teams to adopt a security minded approach?...

Proven Strategies to Unlock Developer Adoption ...

Strong developer buy-in is one of the most crucial ways AppSec managers can effectively fix vulnerabilities. But how can you get your dev teams to adopt a security minded approach?...