Application Security Archives - 7ASecurity Blog https://7asecurity.com/blog/ 7ASecurity Blog With Cybersecurity Tips and Tools Fri, 17 Jul 2026 07:18:32 +0000 en-US hourly 1 https://7asecurity.com/blog/contents/uploads/2019/06/favicon.ico Application Security Archives - 7ASecurity Blog https://7asecurity.com/blog/ 32 32 Don't Let jQuery 3.5.1 Vulnerabilities Panic Your Risk Team https://7asecurity.com/blog/2026/07/jquery-3-5-1-vulnerabilities/ Fri, 17 Jul 2026 07:18:30 +0000 Searches for jQuery 3.5.1 vulnerabilities often mix up older jQuery XSS issues with scanner noise. The major 2020 DOM manipulation flaws, CVE-2020-11022 and CVE-2020-11023, affected versions before 3.5.0. jQuery 3.5.1 followed 3.5.0 and kept those fixes while addressing a regression. Teams should still check loaded versions, old bundled copies, plugins, unsafe DOM insertion, and output …

The post Don't Let jQuery 3.5.1 Vulnerabilities Panic Your Risk Team appeared first on 7ASecurity Blog.

]]>
Don't Let a Misconfigured Cache DB Ruin Your Application https://7asecurity.com/blog/2026/07/misconfigured-cache-database/ Fri, 10 Jul 2026 09:56:06 +0000 A cache DB is a common search term for a cache layer, cache store, or in-memory data store. It keeps frequently used data close to the application to reduce latency and load. The security risk is simple: cached data still counts. Sessions, tokens, user records, API responses, authorisation state, browser cache files, and mobile cache …

The post Don't Let a Misconfigured Cache DB Ruin Your Application appeared first on 7ASecurity Blog.

]]>
P2PE vs E2EE: Stop Guessing and Start Securing Your App https://7asecurity.com/blog/2026/07/p2pe-vs-e2ee-encryption-comparison/ Fri, 03 Jul 2026 07:53:16 +0000 P2PE vs E2EE compares two different encryption models. P2PE protects payment card data from the point of interaction to a secure decryption environment. E2EE protects content between communicating endpoints so intermediaries mustn’t read the plaintext. One isn’t universally better. The right model depends on the data flow, endpoint trust, key handling, compliance context, and where …

The post P2PE vs E2EE: Stop Guessing and Start Securing Your App appeared first on 7ASecurity Blog.

]]>
Iframe XSS: postMessage, CSP, Sandboxing, & Clickjacking https://7asecurity.com/blog/2026/06/iframe-xss-security/ Fri, 19 Jun 2026 08:18:21 +0000 Iframe XSS Explained: Trust Boundaries, Messages, and Embedded Content Iframe XSS isn’t one single bug class. It can refer to XSS inside framed content, unsafe srcdoc, user-controlled iframe sources, weak postMessage handling, over-trusted widgets, or parent pages that trust child frames too much. The fix starts with trust boundaries: control iframe sources, sandbox untrusted content, …

The post Iframe XSS: postMessage, CSP, Sandboxing, & Clickjacking appeared first on 7ASecurity Blog.

]]>
How 7ASecurity Audits Work: Interim Findings, Manual Testing, and Free Fix Verification https://7asecurity.com/blog/2026/02/how-7asecurity-audits-work/ Fri, 06 Feb 2026 06:24:49 +0000 A clear, practical walkthrough of the 7ASecurity audit process: threat-model driven scoping, a dedicated communication channel with interim findings, and free fix verification—so issues are fixed, not just reported.

The post How 7ASecurity Audits Work: Interim Findings, Manual Testing, and Free Fix Verification appeared first on 7ASecurity Blog.

]]>
Interview with OWASP Executive Director on Quality Pentests https://7asecurity.com/blog/2026/01/owasp-executive-director-interview-7asecurity/ Fri, 23 Jan 2026 06:41:47 +0000 OWASP Executive Director Andrew van der Stock interviews 7ASecurity CEO Abraham Aranguren on what “quality pentesting” really means: threat-model driven scoping, researcher-led testing, interim findings, and free fix verification.

The post Interview with OWASP Executive Director on Quality Pentests appeared first on 7ASecurity Blog.

]]>
What's the Real Web Application Penetration Testing Cost? https://7asecurity.com/blog/2025/11/web-app-pen-test-cost/ Wed, 12 Nov 2025 13:25:52 +0000 The Real Value Behind the Price Tag When it comes to web application penetration testing costs, the price is more than a figure to pay. While the number matters, it pales in comparison to the average cost of a single data breach. For small and medium-sized businesses, the financial fallout can be devastating. The UK …

The post What's the Real Web Application Penetration Testing Cost? appeared first on 7ASecurity Blog.

]]>
Unleash Your Inner Mobile App Hacker: 3-Day Intensive at OWASP Lisbon! https://7asecurity.com/blog/2024/05/unleash-your-inner-mobile-app-hacker-3-day-intensive-at-owasp-lisbon/ Thu, 23 May 2024 10:25:34 +0000 Become a mobile app security pro with our "Hacking Android, iOS, and IoT apps by Example" training at OWASP Global AppSec Lisbon. This action-packed 3-day program offers: Hands-on Labs: Master the art of finding vulnerabilities with real-world scenarios. Expert-Led Instruction: Learn from industry veterans and gain practical insights. Flexible Learning Options: Choose between in-person immersion …

The post Unleash Your Inner Mobile App Hacker: 3-Day Intensive at OWASP Lisbon! appeared first on 7ASecurity Blog.

]]>