# contentlab

Published articles for contentlab.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## JPMorgan Just Published a Cyber To-Do List and Snyk Covers 8 of the 10 Items. How do you stack up?

DevFeed: [JPMorgan Just Published a Cyber To-Do List and Snyk Covers 8 of the 10 Items. How do you stack up?](<https://devfeed.tech/articles/jpmorgan-just-published-a-cyber-to-do-list-and-snyk-covers-8-of-the-10-items-how-do-you-stack-up-8122.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-covers-jpmorgan-cyber-list/>)

Author: John Carione

Published: 2026-04-23T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Resilience](<https://devfeed.tech/topics/resilience.md>), [Security](<https://devfeed.tech/topics/security.md>), [snyk-iac](<https://devfeed.tech/topics/snyk-iac.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [releases](<https://devfeed.tech/topics/releases.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code](<https://devfeed.tech/tags/code.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [interest](<https://devfeed.tech/tags/interest.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [releases](<https://devfeed.tech/tags/releases.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-cloud](<https://devfeed.tech/tags/snyk-cloud.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

JPMorganChase's 10-point cyber resilience checklist addresses enterprise security priorities spanning software versions, open-source dependencies, SBOMs, build pipelines, secrets, infrastructure as code, and AI development. The article explains how Snyk covers eight of the ten actions through developer workflows and its security platform.

### Source excerpt

JPMorganChase published a 10-point cyber resilience checklist. See how Snyk covers 8 of the 10 actions and where it fits in your security stack.

## A commitment to future generations: Snyk's 2024 Student Edition Capture The Flag Recap

DevFeed: [A commitment to future generations: Snyk's 2024 Student Edition Capture The Flag Recap](<https://devfeed.tech/articles/a-commitment-to-future-generations-snyk-s-2024-student-edition-capture-the-flag-recap-8144.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-learn-commitment-to-future/>)

Author: Michael Biocchi

Published: 2024-11-21T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [ctf](<https://devfeed.tech/topics/ctf.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk-learn](<https://devfeed.tech/topics/snyk-learn.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [free](<https://devfeed.tech/tags/free.md>), [learn](<https://devfeed.tech/tags/learn.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [training](<https://devfeed.tech/tags/training.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk recaps its 2024 student Capture The Flag 101 Workshop, which brought together students from more than 100 schools for hands-on cybersecurity training. The article describes CTFs as practical exercises covering application security, network vulnerabilities, cryptography, and related skills, and outlines Snyk Learn's commitment to providing free training and additional student opportunities in 2025.

### Source excerpt

Looking to boost your cybersecurity skills? Snyk's CTF 101 Workshop offers a hands-on introduction to Capture the Flag competitions, empowering students to tackle real-world security challenges. Learn about application security, network vulnerabilities, and more through free, engaging training.

## Symmetric vs. asymmetric encryption: Practical Python examples

DevFeed: [Symmetric vs. asymmetric encryption: Practical Python examples](<https://devfeed.tech/articles/symmetric-vs-asymmetric-encryption-practical-python-examples-8202.md>)

Original publisher: [Read original article](<https://snyk.io/blog/symmetric-vs-asymmetric-encryption-python/>)

Author: Josh Amata

Published: 2024-05-15T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Encryption](<https://devfeed.tech/topics/encryption.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Python](<https://devfeed.tech/topics/python.md>), [SSL](<https://devfeed.tech/topics/ssl.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [data-transmission](<https://devfeed.tech/tags/data-transmission.md>), [developer](<https://devfeed.tech/tags/developer.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [examples](<https://devfeed.tech/tags/examples.md>), [guide](<https://devfeed.tech/tags/guide.md>), [implement](<https://devfeed.tech/tags/implement.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

This tutorial explains symmetric and asymmetric encryption, including how each uses cryptographic keys to protect sensitive data. It provides practical Python examples and discusses applications in secure transmission, storage, messaging, and TLS/SSL handshakes.

### Source excerpt

In this guide, we'll discuss symmetric and asymmetric encryption, implement them in Python, and explore their best practices.

## File encryption in Python: An in-depth exploration of symmetric and asymmetric techniques

DevFeed: [File encryption in Python: An in-depth exploration of symmetric and asymmetric techniques](<https://devfeed.tech/articles/file-encryption-in-python-an-in-depth-exploration-of-symmetric-and-asymmetric-techniques-8200.md>)

Original publisher: [Read original article](<https://snyk.io/blog/symmetric-asymmetric-file-encryption-in-python/>)

Author: Keshav Malik

Published: 2023-11-22T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Encryption](<https://devfeed.tech/topics/encryption.md>), [Python](<https://devfeed.tech/topics/python.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [amazon-web-services](<https://devfeed.tech/tags/amazon-web-services.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [developer](<https://devfeed.tech/tags/developer.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kms](<https://devfeed.tech/tags/kms.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

This tutorial explains symmetric and asymmetric file encryption in Python. It covers symmetric encryption with Amazon KMS and PyNaCl SecretBox, then introduces asymmetric encryption with PyNaCl's public/private box, including the prerequisites and packages needed to follow along.

### Source excerpt

This article dives into the world of encryption in Python. For symmetric encryption, we'll focus on Amazon's Key Management Service (KMS) and PyNaCl SecretBox. Then, we'll look at asymmetric encryption and PyNaCl's public/private box.

## Getting started with query parameterization

DevFeed: [Getting started with query parameterization](<https://devfeed.tech/articles/getting-started-with-query-parameterization-7940.md>)

Original publisher: [Read original article](<https://snyk.io/blog/getting-started-query-parameterization/>)

Author: Mary Gathoni

Published: 2023-10-24T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [SQL](<https://devfeed.tech/topics/sql.md>), [Security](<https://devfeed.tech/topics/security.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [sql](<https://devfeed.tech/tags/sql.md>)

### AI overview

A hands-on article explaining SQL query parameterization as a defense against SQL injection in web applications. It describes using placeholders, prepared statements, and parameterized stored procedures so user input is treated as data rather than executable SQL, while also discussing permissions and potential performance benefits.

### Source excerpt

In this hands-on article, we'll review how to leverage SQL query parameterization and stored procedures to prevent injection attacks, as well as some additional security measures that help keep our code safe.

## How to protect Node.js apps from CSRF attacks

DevFeed: [How to protect Node.js apps from CSRF attacks](<https://devfeed.tech/articles/how-to-protect-node-js-apps-from-csrf-attacks-7961.md>)

Original publisher: [Read original article](<https://snyk.io/blog/how-to-protect-node-js-apps-from-csrf-attacks/>)

Author: Victor Ikechukwu

Published: 2023-10-17T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [browser](<https://devfeed.tech/topics/browser.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [cookies](<https://devfeed.tech/tags/cookies.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node](<https://devfeed.tech/tags/node.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

This tutorial explains cross-site request forgery (CSRF) attacks against Node.js applications. It describes how attackers exploit trust in authenticated browser sessions, session IDs, and cookies to trigger unauthorized actions, then introduces practical protection methods, testing approaches, code examples, and security best practices.

### Source excerpt

Victor Ikechukwu October 17, 2023 A cross-site request forgery attack (CSRF) attack is a security vulnerability capitalizing on trust between a web browser and a legitimate website. Crafty attackers manipulate browsers into executing malicious actions on websites where users authenticate themselves and log in. Often, these attacks start when users click a link attached to a deceptive email or land on a compromised website, unaware of the logic executing in the background.

## Installing and managing Java on macOS

DevFeed: [Installing and managing Java on macOS](<https://devfeed.tech/articles/installing-and-managing-java-on-macos-7978.md>)

Original publisher: [Read original article](<https://snyk.io/blog/installing-and-managing-java-on-macos/>)

Author: Keshav Malik

Published: 2023-10-12T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [macOS](<https://devfeed.tech/topics/macos.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [installation](<https://devfeed.tech/tags/installation.md>), [java](<https://devfeed.tech/tags/java.md>), [jdk](<https://devfeed.tech/tags/jdk.md>), [macos](<https://devfeed.tech/tags/macos.md>), [reviews](<https://devfeed.tech/tags/reviews.md>)

### AI overview

A guide to installing and managing multiple Java versions on macOS, including manual installation, distribution choices, compatibility testing, and configuring environment variables such as JAVA_HOME.

### Source excerpt

This article reviews how to install and manage different versions of Java on your macOS system to help you simplify this process.

## Security implications of cross-origin resource sharing (CORS) in Node.js

DevFeed: [Security implications of cross-origin resource sharing (CORS) in Node.js](<https://devfeed.tech/articles/security-implications-of-cross-origin-resource-sharing-cors-in-node-js-8089.md>)

Original publisher: [Read original article](<https://snyk.io/blog/security-implications-cors-node-js/>)

Author: Victor Ikechukwu

Published: 2023-09-13T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [data-breaches](<https://devfeed.tech/tags/data-breaches.md>), [developer](<https://devfeed.tech/tags/developer.md>), [http](<https://devfeed.tech/tags/http.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

This article explains how cross-origin resource sharing (CORS) enables web applications to communicate across origins while working around same-origin policy restrictions. It uses a Node.js code sample to discuss CORS implementation, security risks such as data breaches and unauthorized access, best practices, and security testing.

### Source excerpt

This article will cover what CORS is and some of its use cases, as well as best practices for using CORS and testing the security of your code.

## How to avoid web cache poisoning attacks

DevFeed: [How to avoid web cache poisoning attacks](<https://devfeed.tech/articles/how-to-avoid-web-cache-poisoning-attacks-7955.md>)

Original publisher: [Read original article](<https://snyk.io/blog/how-to-avoid-web-cache-poisoning-attacks/>)

Author: Najia Gul

Published: 2023-09-11T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Caching](<https://devfeed.tech/topics/caching.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cache](<https://devfeed.tech/tags/cache.md>), [caching](<https://devfeed.tech/tags/caching.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [security](<https://devfeed.tech/tags/security.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

An article explaining web cache poisoning attacks, how caching works across browsers, servers, and CDNs, and how improper cache management can create security risks for web applications.

### Source excerpt

In this article, we'll comprehensively explore web cache poisoning attacks and how they work. We'll also discuss the most effective mitigation strategies to help safeguard our web applications.

## How to implement SSL/TLS pinning in Node.js

DevFeed: [How to implement SSL/TLS pinning in Node.js](<https://devfeed.tech/articles/how-to-implement-ssl-tls-pinning-in-node-js-8190.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ssl-tls-pinning-node-js/>)

Author: Nwani Victory

Published: 2023-08-29T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A tutorial on implementing SSL/TLS certificate pinning in Node.js to help defend connections against MITM and certificate-related attacks.

### Source excerpt

This article explains certificate pinning, highlighting its benefits and use cases in Node.js applications.

## Top 5 VS Code extensions for security

DevFeed: [Top 5 VS Code extensions for security](<https://devfeed.tech/articles/top-5-vs-code-extensions-for-security-8217.md>)

Original publisher: [Read original article](<https://snyk.io/blog/top-5-vs-code-extensions-security/>)

Author: Brian Clark

Published: 2023-08-24T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [extensions](<https://devfeed.tech/tags/extensions.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>)

### AI overview

The article presents VS Code extensions for improving application security and security practices. Its shown section covers the 1Password extension, which helps developers store, detect, and retrieve passwords and secrets without leaving the editor.

### Source excerpt

This article highlights the top five VS Code extensions to help us write more secure code and maintain security best practices.

## Does GitOps enhance application security?

DevFeed: [Does GitOps enhance application security?](<https://devfeed.tech/articles/does-gitops-enhance-application-security-7942.md>)

Original publisher: [Read original article](<https://snyk.io/blog/gitops-application-security/>)

Author: Vandana Verma Sehgal

Published: 2023-08-21T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [ci](<https://devfeed.tech/topics/ci.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [git](<https://devfeed.tech/tags/git.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains GitOps principles and their role in application security. It describes declarative configuration, Git-based version control, automated change approvals, and continuous reconciliation for CI/CD and infrastructure delivery.

### Source excerpt

In this post, we'll explore GitOps' core principles, how they enhance application security, and how GitOps' rapid-change deployment process helps increase efficiency.

## Mitigating DOM clobbering attacks in JavaScript

DevFeed: [Mitigating DOM clobbering attacks in JavaScript](<https://devfeed.tech/articles/mitigating-dom-clobbering-attacks-in-javascript-8017.md>)

Original publisher: [Read original article](<https://snyk.io/blog/mitigating-dom-clobbering-attacks-javascript/>)

Author: Keshav Malik

Published: 2023-08-07T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Document Object Model (DOM)](<https://devfeed.tech/topics/dom.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [HTML](<https://devfeed.tech/topics/html.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [browser](<https://devfeed.tech/tags/browser.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [html](<https://devfeed.tech/tags/html.md>), [html-elements](<https://devfeed.tech/tags/html-elements.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [time](<https://devfeed.tech/tags/time.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This article explains DOM clobbering, a condition in which HTML element IDs or name attributes conflict with global JavaScript variables or functions. It describes how browsers create global variables from these attributes, how conflicts can overwrite existing functions, and how attackers may exploit the behavior to cause unpredictable behavior or security vulnerabilities such as cross-site scripting (XSS).

### Source excerpt

This article explores the concept of DOM clobbering and provides strategies for building more secure and robust web applications.

## WebAssembly Security Concerns and Risk Mitigation

DevFeed: [WebAssembly Security Concerns and Risk Mitigation](<https://devfeed.tech/articles/how-secure-is-webassembly-5-security-concerns-unique-to-webassembly-8233.md>)

Original publisher: [Read original article](<https://snyk.io/blog/webassembly-security-concerns/>)

Author: Marcelo Oliveira

Published: 2023-07-28T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [WebAssembly](<https://devfeed.tech/topics/web-assembly.md>), [Security](<https://devfeed.tech/topics/security.md>), [Blazor](<https://devfeed.tech/topics/blazor.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>)

### AI overview

This tutorial introduces WebAssembly security considerations and uses a sample Blazor application to examine WebAssembly-specific security issues. It explains setup with Visual Studio or VS Code and a Snyk extension for security analysis.

### Source excerpt

Developers are embracing WebAssembly for its ability to accelerate complex algorithms, enable gaming and multimedia applications, and provide a secure sandbox. But before adopting WebAssembly, it's crucial to consider its security implications and how to mitigate the risks.

## Finding and fixing insecure direct object references in Python

DevFeed: [Finding and fixing insecure direct object references in Python](<https://devfeed.tech/articles/finding-and-fixing-insecure-direct-object-references-in-python-7975.md>)

Original publisher: [Read original article](<https://snyk.io/blog/insecure-direct-object-references-python/>)

Author: Keshav Malik

Published: 2023-07-19T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Security](<https://devfeed.tech/topics/security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [acquisition](<https://devfeed.tech/tags/acquisition.md>), [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

This article explains insecure direct object references (IDOR) in Python applications. It describes how missing authorization checks can let attackers access or modify sensitive objects, files, or user data, and outlines common IDOR patterns, including blind IDORs and guessable identifiers.

### Source excerpt

In this post, we'll review common patterns and types of IDOR vulnerabilities and how to protect against them.

## Best practices for effective attack surface analysis

DevFeed: [Best practices for effective attack surface analysis](<https://devfeed.tech/articles/best-practices-for-effective-attack-surface-analysis-7841.md>)

Original publisher: [Read original article](<https://snyk.io/blog/best-practices-attack-surface-analysis/>)

Author: Benson Kuria Macharia

Published: 2023-07-18T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Microservice](<https://devfeed.tech/topics/microservice.md>), [Microservices](<https://devfeed.tech/topics/microservices.md>), [Network](<https://devfeed.tech/topics/network.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [article](<https://devfeed.tech/tags/article.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains attack surface analysis as the process of identifying and assessing vulnerabilities and risks across an application or network. It presents a two-step approach: map attack surfaces and rank the severity of potential breaches, while considering interfaces, communication paths, attack vectors, authentication, microservices, open-source and third-party components, continuous monitoring, license compliance, and supply-chain security.

### Source excerpt

This article reviews several best practices we can implement to make an attack surface analysis more effective.

## XS leaks: What they are and how to avoid them

DevFeed: [XS leaks: What they are and how to avoid them](<https://devfeed.tech/articles/xs-leaks-what-they-are-and-how-to-avoid-them-8258.md>)

Original publisher: [Read original article](<https://snyk.io/blog/xs-leaks/>)

Author: Gino Diño

Published: 2023-07-17T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [browser](<https://devfeed.tech/tags/browser.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>)

### AI overview

The article explains cross-site leaks (XS leaks), web security vulnerabilities that can expose sensitive data from a user's activity on other websites. It describes how browser and web features can be exploited, including timing attacks involving cross-origin requests, and introduces prevention examples.

### Source excerpt

In this article, we'll dive deeper into what XS leaks are and how they occur. Then, we'll review some hands-on examples of how to prevent them.