Skip to content
AppSec Labs logo
  • Penetration Testing Services
    • Web Applications
    • SaaS & Multi-Tenant
    • APIs
    • Mobile Apps
    • AI & LLM
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • About
    • Alumni
    • The Book
  • Careers
  • Blog
  • Contact
  • עברית

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

    Application Security

    • Home
    • Blog
    • Application Security
    Application Security

    The Most Expensive Vulnerability Is a Token Nobody Rotated

    July 8, 2026 No comments yet

    No sophisticated SQL injection. No state actor with three APT teams. A developer pushed code with a secret in it, and a drug worth billions walked out.

    Application Security

    Securing the Lifeline: A Guide to Medical Device Penetration Testing

    February 15, 2026 AppSec Labs No comments yet

    Medical devices now sit at the center of hospital networks, cloud platforms, and mobile apps, which makes them attractive targets for cyber attackers. A successful attack can expose sensitive medical data, disrupt life critical treatments, and put healthcare providers at risk of regulatory penalties. This article explains why medical device penetration testing is vital, what […]

    Application Security

    What Is Real-Time Penetration Testing And Why It Matters

    January 25, 2026 Lior Gershon No comments yet

    One quiet vulnerability can be tomorrow’s headline, and the clock is always in the attackers’ favor. IBM’s 2025 Cost of a Data Breach Report just discovered the average global breach cost, not surprisingly, is $4.44 million, which obviously highlights how expensive “later” can be. Penetration testing mitigates that risk by imitating actual attacks so that exploitable holes crop […]

    Application Security

    A Medical Device on End-of-Life Linux: What You Do When You Cannot Patch

    January 10, 2026 No comments yet

    Hundreds of thousands of devices in hospitals, an unsupported Linux, and no vendor patches. Removing packages that were never used cut roughly half the problem before we touched the critical ones.

    Application Security

    Almost Every Real Penetration Test Starts by Hunting for Secrets

    August 19, 2025 No comments yet

    An API key left in git. A token embedded in an image or a PDF. A config.old.js somebody forgot to delete. Google open-sourced a secret scanner, and it is worth your attention.

    Software Security Testing
    Application Security

    The Ultimate Guide to Securing Applications Through Software Security Testing

    June 8, 2025 AppSec Labs No comments yet

    Software application security testing is essential in safeguarding applications against vulnerabilities and potential cyber-attacks. With increasing threats, ensuring the security of applications through thorough testing is crucial for protecting sensitive data and maintaining user trust. Common Types of Software Security Hacks and Vulnerabilities 1. Injection Attacks Injection attacks involve inserting malicious code into applications, often […]

    Application Security

    The Same Flaws Keep Entering at the Code Stage. Here Is What We Put in the Way.

    April 20, 2025 No comments yet

    Across the assessments and code reviews we run, the same security problems enter systems at the code stage – sometimes without the developers being aware of it at all.

    PHP Security Code Review Cheat Sheet
    Application Security

    PHP Security Code Review Cheat Sheet

    February 10, 2025 Michael Yermakov No comments yet

    In today’s development landscape among our customers, it’s rare to encounter production PHP code. However, when we do, the story is always the same. Typically, such code is riddled with numerous high and critical-level vulnerabilities. Reviewing and testing this kind of code feels like being transported back in time about 20 years when all the […]

    Application Security

    ReDoS

    December 29, 2024 Nathan Touati No comments yet

    How a Simple Test Brought Down a Server You sanitized your input fields for XSS? You might have opened a new door for attackers… Imagine this: You’re a developer at your company. After a penetration test, several issues were found in your app, some input fields have no limits on length or content. This leaves […]

    Application Security

    Cryptography as a Solution – Using Advanced Techniques for Data Protection

    December 24, 2024 AppSec Labs No comments yet

    Introduction to Data Protection In the world of information security it is highly advised to implement security solutions in layers. Solutions such as authentication, authorization, input validation and others help us maintain order and security when dealing with access to data. It is important to note that these techniques do not help with the data […]

    Posts pagination

    1 2 Next

    Search

    Categories

    • AI and LLM Security (26)
    • API Security (7)
    • Application Security (18)
    • Authorization and Access Control (11)
    • Black Box Testing (3)
    • Brute Force (1)
    • Cloud Security (13)
    • Engagements and Process (10)
    • Hacking (4)
    • Mobile Security (4)
    • Supply Chain (15)
    • White Box Testing (1)

    Recent posts

    • Somebody Wired the Darknet Into Your AI. What Could Go Wrong?
    • Configured Is Not Enforced
    • Every Week Someone Asks Me When AI Will Replace Pentesters
    AppSec Labs logo

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • info@appsec-labs.com
    • +972 52-433-9393

    © AppSec Labs 2026. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy