Results for "Static analysis"
- Article
What Is Static Code Analysis? A Complete Guide
Learn what static code analysis is, how it works, and why it catches vulnerabilities before deployment. A complete guide with best practices.
- Article
Why Static Analysis Struggles with Business Logic Vulnerabilities
The gap between tracking where data flows and reasoning about whether the logic is correct.
- Article
SAST vs DAST: Complete Guide to Application Security Testing
SAST vs DAST, compared for application security testing. Learn static and runtime testing methods, key differences, and coverage gaps.
- Article
n8n Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
Authorization bypass in n8n’s dynamic-credentials OAuth endpoints allows any authenticated user to operate on another user’s OAuth credential by supplying its I…
- Article
API Scanning: Complete Guide to Automated Security Testing
Learn API scanning for automated security testing. Find vulnerabilities from broken authentication to business logic flaws in your endpoints.
- Article
Gecko Security vs ZeroPath: Which Is Better?
Gecko Security vs ZeroPath, compared. See which SAST tool finds authorization bugs, handles microservices, and reduces false positives better.
- Article
Claude Code Review: What Code Scanners Cannot Tell You About Real Risk
Claude Code Review brought five parallel agents and sub-1% false positives, changing how AI development teams ship production code.
- Article
Why Gecko Isn’t an IaC Scanner, and What It Actually Does
Learn why Gecko Security isn’t an IaC scanning tool and what it actually does. Compare IaC scanners with application security testing.
- Article
RCE in Your Test Suite: AI Agent Skills and the Attack Vector Skill Scanners Miss
When a developer runs npx skills add, the installer copies the entire skill directory into the repo. If a malicious skill includes a *.test.ts file, it runs dur…
- Article
How Broken Access Controls in Cal.com Leaked Millions of Bookings and Enabled Complete Account Takeover
Gecko’s AI security engineer discovered critical chained vulnerabilities in Cal.com Cloud that allowed complete account takeover and exposed all booking data.
Showing 1 - 10 of 20 results