AppSec Insights

Practical articles on application security, secure coding, penetration testing, API and mobile hardening, threat modeling, and cloud security — written by the AppSecWarrior team for developers, security engineers, and leaders who want to ship safer software. New posts from our Medium publication appear here automatically, so you always see our latest guides, research, and field notes without refreshing the page.

securitySep 5, 2026

Breaking In: Pentester’s Voice — Episode #3

About Today’s Guest — Pentester Conversations: Superwoman in Cybersecurity - Pallavi’s journeyHackers and Security Enthusiasts, today we’re thrilled to welcome Pallavi Deshmukh — a dashing, dynamic woman in cybersecurit…

Read on Medium
pentestingAug 31, 2026

AI-powered scanner vulnerabilities

How autonomous, LLM-driven security scanners introduce a new class of attack surface — and how to defend against itArtificial Intelligence has quickly become the shiny new tool in the security world. AI-powered scanners…

Read on Medium
penetration testingAug 19, 2026

Breaking In: Pentester’s Voice — Episode #2

Cybersecurity is constantly evolving, but the most valuable lessons often come straight from those on the front lines. With this series, our goal is to bridge technical expertise and accessible storytelling by sharing e…

Read on Medium
hackingJul 5, 2026

Breaking In: Pentester’s Voice

Shradha’s JourneyIn the ever‑evolving world of cybersecurity, the voices of practitioners often carry the most valuable lessons. With this new series, I aim to bridge the gap between technical expertise and accessible s…

Read on Medium
threat modelingMay 11, 2026

Threat Modeling for AI Application

As we move from static chatbots to autonomus AI agents the security landscape has shifted from “What the AI says” to “What the AI can do”. Traditional threat modeling is no longer enough. when an agent has the power to…

Read on Medium
zero click attackMar 22, 2026

Zero-Click Exploit Attack

In a recent interview session, we asked candidates about zero‑click exploits to evaluate whether they understand modern, advanced attack vectors that go beyond the typical ‘click a malicious link’ scenarios. Here is Sam…

Read on Medium
penetration testingNov 1, 2025

HTTP Host Header Vulnerability

IntroductionThe HTTP Host header is a fundamental component of the HTTP/1.1 protocol, specifying the domain name of the server (for example, www.appsecwarrior.org) and optionally the port number, to which the request is…

Read on Medium

View all articles on Medium →