Please download one of these browsers:
Keep your browser version up-to-date for a fast, secure, web experience.
An application security engineer is a specialist in the field of information technology (IT), whose primary focus is to safeguard software applications from potential threats and breaches. They are the bridge between security and development, ensuring that applications are designed, developed, and deployed in a secure manner.
Tal Kollender highlights how human errors and default settings lead to 80% of ransomware attacks. Discover the risks of manual remediation and how automation can reduce misconfigurations, shrinking the attack surface and enhancing network protection.
This course is designed for those looking to gain skills related to penetration testing web applications.
PenTest+ assesses the most up-to-date penetration testing, and vulnerability assessment and management skills necessary to determine the resiliency of the network against attacks.
Version control is a cryptic yet essential part of a software development team. Git is a distributed version control system that allows collaboration and management of large scale software products (as well as other types of projects)
Apple Certified Support Professional (ACSP) certification confirms the candidate's understanding of macOS's core functionality as well as having the ability to configure key services, perform basic troubleshooting, and support multiple users with essential macOS capabilities.
This course is designed to teach you about the 2021 version of the OWASP Top 10 Web Application Vulnerabilities. The OWASP Top 10 is a list of the most critical security risks to web applications, and it is widely used by organizations to improve their web application security.
James Kettle of PortSwigger reveals sophisticated web race condition exploits, demonstrating how attackers can manipulate state machines and create backdoors through precise timing attacks.
Dive into the world of MinIO security as we uncover and exploit an information disclosure vulnerability, gaining access to sensitive data.
Master container security in our Vulnerable Erlang course! Exploit CVE-2025-32433, deploy vulnerable Docker containers, detect threats with Sysdig Falco, and secure systems. Ideal for security professionals, DevSecOps, and pentesters.
Learn about types of vulnerabilities, the exploits that can occur from those vulnerabilities, and the programming practices that will help prevent exploitation in an application!
Trend Micro's senior threat researcher Nitesh Surana reveals critical vulnerabilities in Azure Machine Learning services, demonstrating how attackers can compromise ML workspaces.
Security researcher Nemo examines UPI's security architecture, revealing critical vulnerabilities in mobile number verification and offering recommendations to strengthen India's digital payment ecosystem.
Industry leaders Matanda Doss, Susan Koski, William Beer and Paul Leonhirth discuss cloud adoption challenges, API security and AI-powered fraud detection in financial services cybersecurity.
Fred Harris, Matanda Doss and Patrice Boffa examine emerging attack patterns targeting financial services' revenue-generating digital assets.
Veracode CISO Sohail Iqbal provides guidance on prioritizing software security and effectively communicating metrics to board members.
Colin Bell of HCLSoftware examines evolving application security trends, focusing on AI's role in vulnerability detection, API security's growing importance, and how these technologies are reshaping DevOps practices.
Learn from Christophe Barel about securing supply chains, adopting shift-left strategies, and managing open-source risks. Explore frameworks for secure coding, automated security-by-design, and faster detection and remediation of supply chain attacks.
Aurélien Svevi explains how application detection and response cuts through security noise by analyzing applications in production to connect attacks with exploitable vulnerabilities.
Sean Mack shares how DevSecOps transforms security from obstacle to competitive advantage by embedding protection into development workflows, enabling teams to move faster while reducing risk through proper road maps and guardrails.
Bryan Rosensteel of Wiz explains how AI has collapsed the time to exploit, why siloed security fails in the cloud, and how visibility and context let defenders prioritize true risk.
Don Codling and Craig Darling examine security-by-design principles for AI, cloud and enterprise architecture, covering governance, compliance, identity security, threat modeling and strategies for building resilient technology environments.
Chip Witt of Radware examines how AI is expanding the healthcare attack surface, accelerating cyberattacks and introducing prompt injection risks, while outlining practical strategies to secure APIs and AI-powered applications.
Ivan Tsarynny of Feroot Security examines how third-party tracking technologies expose patient data, why continuous evidence collection matters for compliance, and how AI agents automate security testing, monitoring, and risk remediation.
Allan Tay of Singapore Pools makes the case for security-by-design as a leadership mandate, showing how governance, cloud accountability and responsible AI adoption protect enterprises from costly breaches.
Sébastien Dudek of Penthertz walks through real 5G security assessments at every layer - from radio encryption failures and null cipher abuse to 5G core API exploitation and CAMARA endpoint vulnerabilities enabling surveillance and fraud.
Visagan Subburayalu, Dr. Vishal Saraswat and Amol Naik debate who owns AI-generated code security and how organizations can balance developer velocity with accountability, guardrails and human-in-the-loop controls.
Sonya Moisset of Snyk breaks down the security risks of AI-assisted engineering - from slopsquatting to weaponized agents - and shares a five-layer playbook to secure your AI-powered software development life cycle.
Christoph Nagy of SecurityBridge examines how SAP vulnerabilities create direct paths to OT disruption and what a holistic SAP security program must cover to protect operational continuity.
Denis Maligin of Chainguard examines how open-source supply chain attacks reach production environments and how zero-CVE images and software bills of materials address the Cyber Resilience Act.
Intuitive's David Scott explores how secure-by-design practices, governance, supply chain assurance and incident readiness help build trust, resilience and safer outcomes.
Daniella Drori traces AppSec's evolution from siloed, alert-heavy scanners to context-aware security, showing how cross-scanner correlation and AI-aware tooling close the gap between what gets detected and what actually gets fixed.
Thejes Sree Satheesh Kumar and Srinivasan Sekar examine how AI agents using protocols like MCP create unmonitored toolchain attack surfaces and why traditional security models are unequipped to defend them.
Adobe's Kamalpreet Khurana exposes how legacy SOAP systems still fuel critical vulnerabilities in 2026, walking through a real zero-day XXE discovery and offering practical mitigations for teams that can't retire their SOAP infrastructure.
Rishav Raj and Rajkumar Rathod of FIS demo VISTA, an open-source Burp Suite extension that integrates LLM reasoning into penetration testing workflows without replacing human judgment.
Ashish Kataria of Synacor examines how modern sanitization pipelines can inadvertently introduce XSS vulnerabilities through structural mutations, namespace confusion and multi-stage parser mismatches.
SoYeon Kim, Hea-Eun Moon and Sang-tae Woo of NSHC share lessons from organizing ACDC 2025, Korea's first AI security CTF, covering challenge design, unintended AI-powered solutions and format pitfalls.
Join Shobha Jagatpal in a discussion of the cloud, security, network operations, threat detection and response.
Dr. N Rajendran of MCX, Kiran Belsekar of Aegon, Rajat Sen of FS-ISAC and Apurva Dalal of Adani discuss API security challenges and risk management strategies.
Venkatesh Vanjaku of CloudSEK discusses proactive measures for identifying and mitigating software supply chain risks in the modern digital ecosystem.
The transition from DevOps and CI/CD to cloud-native technologies, microservices architecture, security, and governance, and ultimately automation and artificial intelligence, necessitates a modern approach to software supply chain management.
David Dechaux of Technip and Anthony Chiapello of Snyk share insights on implementing AppSec in a non-software company, addressing challenges across distributed teams, multiple languages and varying expertise levels.
Join Brian Shea of Salesforce and Vinit Tople of Amazon in an exploration of security implications of open platforms versus open-source LLMs, focusing on implementation and regulation.
Dillon Franke of Mandiant/Google demonstrates advanced techniques for identifying IPC vulnerabilities in macOS, covering sandbox-allowed communications and mutation-based fuzzing methodologies.
Agarri Founder Nicolas Grégoire shares 25 years of industry insights, tracing the evolution of vulnerability research, security tools and bug bounty programs from 1999 to 2024.
Snyk's Shilpa Raghunathan explores effective ways to identify malicious code and secure first-party code in supply chains using security-by-design principles.
Synopsys's Girish Nanappa explores application security posture management for securing enterprise applications at scale in AI-fueled environments.
Richard Meeus of Akamai shares how comprehensive visibility across IT infrastructure, data streams and applications strengthens organizational defenses and ensures robust operational resilience.
Deval Mazmudar, Pawan Chawla, Abhishek Jha, and Sandesh Jadhav discuss API security challenges, breach prevention, and risk management. Learn how CISOs can balance API security with innovation in digital enterprises.
Industry experts Ramesh Gurram, Sanjeev Kaushik and Mitish Chitnavis discuss API security standards, authentication mechanisms, and access control configurations.
1 2 Next