Latest articles
Application security blog
CVE explainers, code review patterns and practical guidance for people who build and own software.
After React2Shell: three security boundaries every server component review needs
A technical review method for React2Shell and CVE-2026-23864: separate safe decoding, permission checks and bounded work, then verify the deployed build.
Read articleThe 2026 Axios attack: why a clean dependency tree cannot clear a build runner
An evidence-led analysis of the Axios supply-chain compromise: trace package installation, code execution and credential reach before declaring recovery complete.
Read articleCVE-2024-26855: when a missing attribute becomes a NULL dereference
A Linux ice driver fix illustrates a common review mistake: treating a parser’s optional result as a guaranteed object.
Read articleCVE-2025-37858: a 64-bit destination cannot fix a narrow shift
A JFS allocation-group calculation demonstrates why code review must inspect the width of an operation before its result is assigned.
Read articleSecurity code review or penetration testing: what should you buy?
Choose the engagement from the question your product team needs answered, the access available and the change you need to make.
Read article