Web applications

How web applications and APIs get attacked is written down in the OWASP Top 10 and its counterpart for APIs. Dynamic tests find the gaps in production; secure development avoids many of them from the start.

All articles and events are in German.

Articles

Schwachstellen in APIs aufspüreniX 7/2022 · API-Sicherheit 2/2
APIs sicher entwickelniX 7/2022 · API-Sicherheit 1/2
Beyond OWASP Top 10Java aktuell 1/2020

Talks and panels

Upcoming

MCP und RAG absichernTalk · heise devSec · next date 2026⁠-⁠09⁠-⁠23

Archive

Sich selbst hacken bevor es Angreifer tunTalk · IT-Tage · 2024⁠-⁠06⁠-⁠13
OWASP API Security Top 10 2023Talk · IT-Tage · 2023⁠-⁠12⁠-⁠13
Wie APIs angegriffen werden und wie Entwickler sicher entwickelnTalk · c't <webdev> · 2023⁠-⁠11⁠-⁠15
OWASP API Security Top 10Talk · betterCode() · 2021⁠-⁠04⁠-⁠22
OWASP API Security Top 10Talk · IT-Tage · 2020⁠-⁠12⁠-⁠09
OWASP API Security Top 10Talk · heise devSec · 2020⁠-⁠10⁠-⁠22
OWASP API Security Top 10Talk · IT-Sicherheitskonferenz · 2020⁠-⁠09⁠-⁠22
OWASP API Security Top 10 – How APIs are HackedTalk · BSides Munich · 2020⁠-⁠08⁠-⁠23
OWASP Top 10Talk · German Testing Day · 2020⁠-⁠05⁠-⁠06
Beyond OWASP Top 10Talk · c't <webdev> · 2020⁠-⁠02⁠-⁠05

Workshops and webinars

Upcoming

Ethical Hacking für Admins – Pentesting für eine sichere ITWebinar series · heise academy · next date 2026⁠-⁠09⁠-⁠17

Archive

Fortgeschrittenes Ethical Hacking – Deep Dive ins Pentesting für AdminsWebinar series · heise academy · 2026⁠-⁠07⁠-⁠07
Die Log4j-Lücke – der Praxis-Ratgeber für AdminsWebinar · heise security · 2021⁠-⁠12⁠-⁠20