Web · API · Cloud · IAM · AI/LLM Security

AppSec Engineering Build secure. Stay secure. Web · API · Cloud · IAM · AI/LLM · Offensive Security Programme

Application security research bridging offensive knowledge and defensive engineering — covering web application vulnerabilities, API security, cloud security posture, identity management, and AI/LLM threat surfaces. United States, United Kingdom, and European Union focus.

Appsec Engineering active
CRITICAL

OWASP API Security Top 10 — Broken Object Level Authorization

API Security · 2026

HIGH

Prompt injection in production LLM applications — enterprise risk

AI/LLM Security · 2026

HIGH

Cloud misconfiguration — S3 exposure patterns Q2 2026

Cloud Security · 2026

MEDIUM

OAuth 2.0 implementation flaws in enterprise SaaS

IAM · Authentication · 2026

OWASP

OWASP Top 10 2025 — updated rankings and new entries

Web Application Security

What This Repo Covers

Six engineering disciplines — all research grounded in official frameworks, real vulnerability data, and defensive application.

01 // WEB APPLICATION

Web Application Security

OWASP Top 10, injection vulnerabilities, authentication flaws, and secure development practices for modern web applications.

OWASP Top 10SQLiXSSCSRF

02 // API SECURITY

API Security

OWASP API Security Top 10, REST and GraphQL vulnerabilities, authentication bypass, and mass assignment attacks in modern API design.

OWASP API Top 10BOLAGraphQLREST

03 // CLOUD SECURITY

Cloud Security

Cloud-native attack surfaces, misconfiguration risks across AWS, Azure, and GCP, shared responsibility model, and zero-trust architecture.

AWSAzureGCPCSPM

04 // IAM & AUTHENTICATION

Identity & Access Management

OAuth 2.0 and OIDC implementation flaws, MFA bypass techniques, privilege escalation, and zero-trust identity architecture.

OAuth 2.0OIDCMFAZero Trust

05 // AI/LLM SECURITY

AI & LLM Security

Prompt injection, data leakage from AI systems, adversarial inputs, and security assessment of AI-powered applications in production.

Prompt InjectionLLMOWASP LLM Top 10

06 // SECURITY PROGRAMME

Offensive Security Programme Management

Building and managing security testing programmes — vulnerability disclosure, bug bounty programme design, and security engineering culture.

VDPBug BountySec Engineering

Latest Articles

Every article cites official sources — OWASP, NIST, CISA, CVE database, and primary vendor advisories.