<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
    <channel>
        <title>Anilkumar | Product Security Engineer</title>
        <link>https://appsecexpert.com</link>
        <description>Thoughts, write-ups, and guides on AppSec, DevSecOps, and Software Engineering.</description>
        <language>en-us</language>
        <lastBuildDate>Thu, 04 Jun 2026 14:02:42 GMT</lastBuildDate>
        
        <item>
            <title><![CDATA[Bug Bounty Tips for Beginners: How to Find Your First Valid Bug]]></title>
            <link>https://appsecexpert.com/blog/bug-bounty-tips-for-beginners</link>
            <guid>https://appsecexpert.com/blog/bug-bounty-tips-for-beginners</guid>
            <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Most beginners quit bug bounty hunting after a few weeks of zero findings. This guide covers the mindset shifts, target selection strategy, and practical techniques that lead to your first valid report.]]></description>
            <category>Bug Bounty</category><category>Penetration Testing</category><category>AppSec</category><category>Beginners</category>
        </item>
        <item>
            <title><![CDATA[Product Security for B2B SaaS Startups: Where to Begin]]></title>
            <link>https://appsecexpert.com/blog/prodsec-for-b2b-saas-startups</link>
            <guid>https://appsecexpert.com/blog/prodsec-for-b2b-saas-startups</guid>
            <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A practical guide to building a product security function at a B2B SaaS startup — what to prioritize, what to skip, and how to make security a competitive advantage with a small team.]]></description>
            <category>Product Security</category><category>SaaS</category><category>Startups</category><category>DevSecOps</category><category>AppSec</category>
        </item>
        <item>
            <title><![CDATA[AppSec for Fintech in India: Regulations, Risks, and Reality]]></title>
            <link>https://appsecexpert.com/blog/appsec-for-fintech-in-india</link>
            <guid>https://appsecexpert.com/blog/appsec-for-fintech-in-india</guid>
            <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A practitioner's guide to application security for Indian fintech companies — covering RBI and SEBI compliance requirements, the threat landscape, and how to build a security program that satisfies regulators and protects customers.]]></description>
            <category>Fintech</category><category>AppSec</category><category>RBI</category><category>India</category><category>Compliance</category><category>Secure SDLC</category>
        </item>
        <item>
            <title><![CDATA[How I Built a DevSecOps Pipeline with Semgrep + GitHub Actions]]></title>
            <link>https://appsecexpert.com/blog/devsecops-pipeline-semgrep-github-actions</link>
            <guid>https://appsecexpert.com/blog/devsecops-pipeline-semgrep-github-actions</guid>
            <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A practical walkthrough of embedding SAST into CI/CD using Semgrep and GitHub Actions — from zero findings noise to actionable signal that developers actually trust.]]></description>
            <category>DevSecOps</category><category>Semgrep</category><category>GitHub Actions</category><category>SAST</category><category>CI/CD</category>
        </item>
        <item>
            <title><![CDATA[STRIDE Threat Modeling Walkthrough: A Real Web App Example]]></title>
            <link>https://appsecexpert.com/blog/stride-threat-modeling-walkthrough</link>
            <guid>https://appsecexpert.com/blog/stride-threat-modeling-walkthrough</guid>
            <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A hands-on walkthrough of STRIDE threat modeling applied to a real-world web application — including data flow diagrams, trust boundaries, and how to turn findings into actionable engineering tasks.]]></description>
            <category>Threat Modeling</category><category>STRIDE</category><category>AppSec</category><category>Secure Design</category>
        </item>
        <item>
            <title><![CDATA[OWASP Top 10 for Developers — What Actually Matters in 2026]]></title>
            <link>https://appsecexpert.com/blog/owasp-top-10-for-developers-2026</link>
            <guid>https://appsecexpert.com/blog/owasp-top-10-for-developers-2026</guid>
            <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A practitioner's take on the OWASP Top 10 — skipping the theory and focusing on what developers actually need to know to write secure code in 2026.]]></description>
            <category>OWASP</category><category>AppSec</category><category>Secure Coding</category><category>Developers</category>
        </item>
        <item>
            <title><![CDATA[Burp Suite vs OWASP ZAP: Which to Use and When]]></title>
            <link>https://appsecexpert.com/blog/burp-suite-vs-owasp-zap</link>
            <guid>https://appsecexpert.com/blog/burp-suite-vs-owasp-zap</guid>
            <pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A practitioner's comparison of Burp Suite and OWASP ZAP based on real-world use across penetration testing engagements and DevSecOps pipelines — not feature checklists.]]></description>
            <category>Burp Suite</category><category>OWASP ZAP</category><category>DAST</category><category>Penetration Testing</category><category>Tools</category>
        </item>
        <item>
            <title><![CDATA[Securing CI/CD Pipelines: A Practical Guide]]></title>
            <link>https://appsecexpert.com/blog/securing-cicd-pipelines</link>
            <guid>https://appsecexpert.com/blog/securing-cicd-pipelines</guid>
            <pubDate>Mon, 03 Mar 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[Learn how to embed security natively into your developer workflows using pre-merge SAST and DAST checks, without slowing down delivery.]]></description>
            <category>DevSecOps</category><category>CI/CD</category><category>SAST</category>
        </item>
    </channel>
</rss>