Skip to content

Similar papers

Review Aug 2026

TENET: Telegram Mini App (in)security

This work presents TENET, a purpose-built auditing tool whose design decisions are grounded in the structural properties of the secrets targeted and empirically validated against a ground-truth dataset, and proposes mitigation measures and best practices for both Telegram platform developers and third-party Mini App cr...

Andrea Ciccotelli, Federico Zappone, R. Di Pietro · 0 citations
Open access Oct 2026

Secrets Unlocked: Evaluating LLMs for Secrets Detection in Android Apps

Mobile apps frequently embed sensitive secrets, such as API keys, access tokens, client secrets, and private keys that support internal functionality or enable integration with external systems and third-party services. Developers frequently embed these secrets into Android apps, which allows attackers to extract them...

Marco Alecci, Jordan Samhi, Tegawendé F. Bissyandé et al. · 0 citations
Review Open access 2026

Security Analysis of LLM-Generated Web API Backends

A security assessment on 75 FastAPI backends generated by three contemporary LLMs revealed a disconnect between functional correctness and secure logic, which is interpreted as a review-risk pattern, which is called the human-in-the-loop paradox.

Abdul Ali Khan, S. Rauti, T. Mäkilä · 0 citations
Open access Oct 2026

A Python-based web application firewall for SQLi protection in heterogeneous web server environments

Structured query language injection (SQLi) remains one of the most critical threats to web applications. Conventional web application firewall (WAF) such as ModSecurity provide protection but face limitations in heterogeneous environments and often require additional configurations on web servers. This issue is problem...

Muhammad Nur Yasir Utomo, Eddy Tungadi, M. Ahyar · 0 citations
Open access Sep 2026

Security analysis of selected web applications using vulnerability scanners

Web applications are among the most frequently targeted systems in today’s cyber-threat landscape, and vulnerabilities such as SQL injection, cross-site scripting and various configuration errors have dominated the OWASP Top 10 list for years. This article examines the security of a web application using modern vulnera...

Mariusz Choroś, Marta Dziuba-Kozieł · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.