Web applications
How web applications and APIs get attacked is written down in the OWASP Top 10 and its counterpart for APIs. Dynamic tests find the gaps in production; secure development avoids many of them from the start.
All articles and events are in German.
Articles
Schwachstellen in APIs aufspüreniX 7/2022 · API-Sicherheit 2/2
Drei Fragen und Antworten: Warum sind APIs so ein Sicherheitsrisiko?heise online · 2022-06-22
APIs sicher entwickelniX 7/2022 · API-Sicherheit 1/2
Beyond OWASP Top 10Java aktuell 1/2020
Talks and panels
Upcoming
MCP und RAG absichernTalk · heise devSec · next date 2026-09-23
Archive
Sich selbst hacken bevor es Angreifer tunTalk · IT-Tage · 2024-06-13
OWASP API Security Top 10 2023Talk · IT-Tage · 2023-12-13
Wie APIs angegriffen werden und wie Entwickler sicher entwickelnTalk · c't <webdev> · 2023-11-15
OWASP API Security Top 10Talk · betterCode() · 2021-04-22
OWASP API Security Top 10Talk · IT-Tage · 2020-12-09
OWASP API Security Top 10Talk · heise devSec · 2020-10-22
OWASP API Security Top 10Talk · IT-Sicherheitskonferenz · 2020-09-22
OWASP API Security Top 10 – How APIs are HackedTalk · BSides Munich · 2020-08-23
OWASP Top 10Talk · German Testing Day · 2020-05-06
Beyond OWASP Top 10Talk · c't <webdev> · 2020-02-05
Beyond OWASP Top 10: Angriffe auf Webanwendungen und Schnittstellen trotz AbsicherungTalk · IT-Tage · 2019-12-10
Workshops and webinars
Upcoming
Ethical Hacking für Admins – Pentesting für eine sichere ITWebinar series · heise academy · next date 2026-09-17
Archive
Fortgeschrittenes Ethical Hacking – Deep Dive ins Pentesting für AdminsWebinar series · heise academy · 2026-07-07
Die Log4j-Lücke – der Praxis-Ratgeber für AdminsWebinar · heise security · 2021-12-20