SoftwareTestPilot
Manual Testing

Security Testing

Curated Security Testing articles inside the Manual Testing hub — tutorials, real-world patterns, and interview-ready Q&A written by working QA engineers. 7 guides and counting.

Latest Security Testing articles

Security TestingApr 15, 202632 min read

Security Testing for QA Engineers: Complete 2026 Guide (OWASP, Burp Suite, ZAP)

The 2026 complete security testing guide for QA engineers — OWASP Top 10, OWASP API Security Top 10, SQL injection, XSS, BOLA, authentication and authorization testing, Burp Suite, OWASP ZAP, and security in CI/CD.

Read article
Security TestingJun 27, 20269 min read

Accessibility Testing WCAG Guide: Complete Handbook

Complete WCAG accessibility testing guide. WCAG 2.2 levels, POUR principles, axe-core, screen reader testing, keyboard navigation, CI/CD integration, and legal compliance.

Read article
Security TestingJun 27, 20269 min read

OWASP Security Testing Checklist: Complete 2026 Guide

Complete 2026 OWASP security testing checklist. OWASP Top 10 for web and API, hands-on test cases for SQL injection, XSS, BOLA, and security automation in CI/CD.

Read article
Security TestingJul 17, 20268 min read

GDPR-Safe Test Data Strategies for QA Teams

How to run realistic QA without breaching GDPR: masking, synthesis, anonymisation, and the legal red-lines every tester must know.

Read article
API SecurityJul 17, 202611 min read

Top 10 JWT Security Vulnerabilities Every QA Should Test in 2026

The 10 JWT attacks QA teams miss: alg=none, key confusion, jku/kid injection, weak secrets, algorithm downgrade, and more — with test payloads and how to detect each one.

Read article
Application SecurityJul 20, 202616 min read

Security Testing Complete Guide 2026 — Web, API & Mobile for QA Engineers

The 2026 security testing guide for QA engineers — OWASP Top 10, API Security Top 10, DAST vs SAST, ZAP & Burp basics, authentication & authorization tests, and a shift-left workflow.

Read article
Access ControlJul 20, 202611 min read

RBAC Security Testing — 20-Point Checklist for QA (2026)

Role-based access control bugs are the #2 OWASP category (Broken Access Control). This 20-point checklist covers horizontal + vertical privilege escalation, JWT tampering, and IDOR — with copy-paste test cases.

Read article

Other Manual Testing topics