appsec.fyi

Newsletter Preview

Weekly digest — Apr 01 – Apr 08, 2026

AppSec Weekly

335 new resources across 22 topics — Apr 01 – Apr 08, 2026

Term of the Week
Prototype Pollution
A JavaScript-specific vulnerability where an attacker modifies Object.prototype, affecting every object in the application. Commonly found through recursive merge functions that don't filter __proto__ or constructor.prototype. Impact ranges from denial of service to RCE depending on what the application does with polluted properties downstream.
Browse full glossary →

AuthZ +21

SSRF +16

Supply Chain +16

Mobile +16

API Security +16

CSRF +16

XSS +16

Deserialization +15

Secrets +15

AI +15

Recon +15

Bug Bounty +15

RCE +15

Python +15

OSINT +15

SQLi +15

GraphQL +14

Fuzzing +14

Talks +14

XXE +14

IDOR +14

Burp Suite +13