Security Testing
Practical application, API and access-control security testing for QA engineers — OWASP Top 10, JWT, RBAC and shift-left security workflows.
Topics in Security Testing
Focused clusters under this hub. Tap any topic to filter the article list.
Latest in Security Testing
Top 10 JWT Security Vulnerabilities Every QA Should Test in 2026
The 10 JWT attacks QA teams miss: alg=none, key confusion, jku/kid injection, weak secrets, algorithm downgrade, and more — with test payloads and how to detect each one.
Read articleSecurity Testing Complete Guide 2026 — Web, API & Mobile for QA Engineers
The 2026 security testing guide for QA engineers — OWASP Top 10, API Security Top 10, DAST vs SAST, ZAP & Burp basics, authentication & authorization tests, and a shift-left workflow.
Read articleRBAC Security Testing — 20-Point Checklist for QA (2026)
Role-based access control bugs are the #2 OWASP category (Broken Access Control). This 20-point checklist covers horizontal + vertical privilege escalation, JWT tampering, and IDOR — with copy-paste test cases.
Read articleExplore other categories
External reference: ISTQB Foundation Level