Security Testing
Curated Security Testing articles inside the Manual Testing hub — tutorials, real-world patterns, and interview-ready Q&A written by working QA engineers. 7 guides and counting.
Latest Security Testing articles
Security Testing for QA Engineers: Complete 2026 Guide (OWASP, Burp Suite, ZAP)
The 2026 complete security testing guide for QA engineers — OWASP Top 10, OWASP API Security Top 10, SQL injection, XSS, BOLA, authentication and authorization testing, Burp Suite, OWASP ZAP, and security in CI/CD.
Read articleAccessibility Testing WCAG Guide: Complete Handbook
Complete WCAG accessibility testing guide. WCAG 2.2 levels, POUR principles, axe-core, screen reader testing, keyboard navigation, CI/CD integration, and legal compliance.
Read articleOWASP Security Testing Checklist: Complete 2026 Guide
Complete 2026 OWASP security testing checklist. OWASP Top 10 for web and API, hands-on test cases for SQL injection, XSS, BOLA, and security automation in CI/CD.
Read articleGDPR-Safe Test Data Strategies for QA Teams
How to run realistic QA without breaching GDPR: masking, synthesis, anonymisation, and the legal red-lines every tester must know.
Read articleTop 10 JWT Security Vulnerabilities Every QA Should Test in 2026
The 10 JWT attacks QA teams miss: alg=none, key confusion, jku/kid injection, weak secrets, algorithm downgrade, and more — with test payloads and how to detect each one.
Read articleSecurity Testing Complete Guide 2026 — Web, API & Mobile for QA Engineers
The 2026 security testing guide for QA engineers — OWASP Top 10, API Security Top 10, DAST vs SAST, ZAP & Burp basics, authentication & authorization tests, and a shift-left workflow.
Read articleRBAC Security Testing — 20-Point Checklist for QA (2026)
Role-based access control bugs are the #2 OWASP category (Broken Access Control). This 20-point checklist covers horizontal + vertical privilege escalation, JWT tampering, and IDOR — with copy-paste test cases.
Read article