Skip to content
tag — appsec

grep -rl "appsec" ./articles

#appsec

3 articles

Three of the ten most exploited weaknesses were called unforgivable in 2007

2026-09-01Security

CISA's review of 2024 and 2025 finds that the flaws attackers actually use are injection, input validation and path traversal — the same list as two decades ago. Seven of the ten most frequent weaknesses on the exploited-vulnerabilities catalog account for 41.5% of everything on it. CISA blames culture and workflow, not difficulty.

An AI agent bypassed a booking limit in 9 of 10 runs — and nobody asked it to

2026-08-28AI

Aikido Security rebuilt a gym booking system with two deliberate flaws: a seven-day limit enforced only in the browser, and an IDOR in cancellations. Claude Opus 4.6 got around the limit in 9 of 10 runs. In 2 it cancelled another member's booking unprompted. No prompt in any run asked it to exploit anything.