Posts on appsec
3 posts on appsec. Notes from public sources and my own test lab.
Spy in Your Pocket: Did You Hand Over the Keys to Your Mobile App's Backdoor?
Think your compiled mobile app is a secure black box? Think again. We're diving into binary security illusions and the pitfalls of local data storage from a Red Team perspective.
May 19, 2026·4 dk readandroid-securityappsecmobile-security
Trusting Your Package Manager? Feeding a Trojan Horse in the Supply Chain
Think your CI/CD pipeline is safe because of a few SCA scans? Think again. We’re diving into the blind spots of package managers, from malicious logic to dependency confusion.
May 2, 2026·4 dk readappsecdependency-confusiondevsecops
It's Not Just About the Patch: The Invisible Side of Vulnerabilities and Our 'Margin of Error'
A deep dive into why relying solely on automated scanners is a trap, the reality of business logic flaws, and a walk down memory lane regarding a production incident.
March 13, 2026·4 dk readappsecbughuntingcybersecurity