Evan OslickJan 173 minAPPSEC ADVICEGet the Easy Wins. Stop Hiding from the Hard Ones.Balancing priorities between fixing security findings and product impact is a difficult exercise.
Brian PavicicDec 8, 20225 minNEWSThe Next Evolution of Browser-Based Penetration Testing Kits: OWASP PTK There are far too many competing tools in application security and not enough that are great. One tool aims to rise above them all and has p
Brian PavicicNov 29, 20225 minAPPSEC ADVICEHow to Avoid the AppSec Staffing Crisis in 2023Routes to real progress and success exist beyond outdated and painful hiring practices.
Brian PavicicOct 3, 20223 minAPPSEC VAR SOLUTIONSModern AppSec Means Doing More with LessGet tips for stretching your security budget without letting vulnerabilities go unnoticed The Government is Stepping Up Security...
Brian PavicicSep 7, 20221 minNEWSWe have exciting news for the AppSec community!True Positives unveils enterprise quality AppSec scanning on demand --- starting at FREE. Meet our new AppSec product/service hybrid,...
Evan OslickJul 11, 20224 minAPPSEC ADVICEHow to Navigate the Maze of AppSec Tools in 2023The number of tools for performing various application security tests is increasing at a very rapid rate. We’ve gone from the big...
Clayton DewberryJun 29, 20223 minAPPSEC ADVICEDon't Wade in Alone! AppSec Waters are Perilous!I enjoy fly fishing, but I’m not that good at it. It’s not my full-time sport, nor my day job, so when I go out for some “fun” it can be...
Brian PavicicJun 23, 20223 minAPPSEC ADVICEThe Secret to AppSec ShortcutsSecurity scanners are great but only when used properly with a company that truly assesses their own security. Shortcuts can be risky. Read
Brook S.E. SchoenfieldJun 17, 20224 minAPPSEC ADVICEA Better Vulnerability MousetrapEPSS won’t save you from building defenses. But it will help to manage large unpatched vulnerability queues so that the probably dangerous i
Brian PavicicMay 11, 20225 minAPPSEC ADVICEModern AppSec Survival Guide: 5 Tips for Program SuccessThere’s no easy path to success for a modern AppSec program. You’ll absolutely fail if you don’t come prepared and have the right tools...