<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>AppSec &amp; APIs on FirewallSync</title><link>https://firewallsync.com/categories/appsec/</link><description>Recent content in AppSec &amp; APIs on FirewallSync</description><generator>Hugo</generator><language>en-us</language><copyright>FirewallSync</copyright><lastBuildDate>Thu, 01 Oct 2026 09:00:00 +0000</lastBuildDate><atom:link href="https://firewallsync.com/categories/appsec/index.xml" rel="self" type="application/rss+xml"/><item><title>The Vulnerability Backlog That Never Shrinks</title><link>https://firewallsync.com/posts/the-vulnerability-backlog-that-never-shrinks/</link><pubDate>Thu, 01 Oct 2026 09:00:00 +0000</pubDate><guid>https://firewallsync.com/posts/the-vulnerability-backlog-that-never-shrinks/</guid><description>Vulnerability backlogs grow faster than teams can patch because most programs measure the wrong thing: total count instead of exploitability and exposure.</description></item><item><title>Dependency Audits Without Slowing Down Releases</title><link>https://firewallsync.com/posts/dependency-audits-without-slowing-down-releases/</link><pubDate>Tue, 29 Sep 2026 09:00:00 +0000</pubDate><guid>https://firewallsync.com/posts/dependency-audits-without-slowing-down-releases/</guid><description>Most supply-chain security advice assumes you can afford to review every dependency by hand. Here&amp;rsquo;s a tiered approach that scales with a normal release cadence.</description></item><item><title>Container Image Scanning: What CI Pipelines Still Miss</title><link>https://firewallsync.com/posts/container-image-scanning-what-ci-pipelines-still-miss/</link><pubDate>Mon, 28 Sep 2026 09:00:00 +0000</pubDate><guid>https://firewallsync.com/posts/container-image-scanning-what-ci-pipelines-still-miss/</guid><description>Image scanning in CI catches known CVEs in base layers, but most pipelines still ship vulnerable configs and secrets that scanners aren&amp;rsquo;t tuned to see.</description></item><item><title>The API Key Mistakes That Keep Making Breach Reports</title><link>https://firewallsync.com/posts/the-api-key-mistakes-that-keep-making-breach-reports/</link><pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate><guid>https://firewallsync.com/posts/the-api-key-mistakes-that-keep-making-breach-reports/</guid><description>Secrets scanning tools have gotten good. The breaches keep happening anyway, mostly for three preventable reasons.</description></item></channel></rss>