Application Security
Rietta's application security posts cover secure API tokens, breach prevention talks, and prioritizing appsec work as companies grow.
Subscribe to Application Security posts via RSS
09/16/2026
Non-Repudiation in Cybersecurity
by Frank Rietta
Non-repudiation is a foundational security property among the five pillars of Information Assurance. It is at natural odds with Privacy and must be balanced.
09/14/2026
RubyGems Open Source Supply Chain Security and OpenAI
by Frank Rietta
OpenAI agents attacked RubyGems in May 2026. Why automated attackers have collapsed the window to patch a critical CVE from weeks to hours.
07/25/2026
The Five Pillars of Information Security (And Why We Audit Accessibility)
by Frank Rietta
The Five Pillars of Information Security, why accessibility failures are availability failures, and the reason a cybersecurity firm audits ADA/WCAG compliance.
05/14/2024
UUID as a secure API token for API RESTful endpoints? (Video)
by Frank Rietta
Video excerpt about the role of UUIDs as a security identifier for REST API and how to use them more securely if you must.
11/28/2023
An Honest Conversation About Cyber Security (Video)
by Frank Rietta
I recently sat down with Jeremy Duvall of 7Factor Software to discuss Cyber Security and application developers. Enjoy this video!
09/27/2023
Prioritizing cybersecurity (Pluralsight)
by Frank Rietta
The structure and siloing of a large enterprise organization can thwart security efforts. Here is a tip on how to overcome.
04/04/2023
How to win the race with hackers when new vulnerabilities are publicly disclosed!
by Frank Rietta
Keeping deployed web applications up-to-date is imperative to prevent data breaches. Here's how to use automated testing of custom web application software to patch quickly after a support chain vulnerability is publicly disclosed.
04/01/2020
Snowfroc 2020 - Application Security and Development
by Chris Davis
Application security is important to an entire company, but what practical steps can we take on a development team to keep applications secure?