> Markdown version of [/videos/1343-what-the-hack-is-web-app-sec](https://www.wearedevelopers.com/videos/1343-what-the-hack-is-web-app-sec). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # What The Hack is Web App Sec? As AI accelerates code generation, are you accidentally scaling classic vulnerabilities? Learn how to integrate automated checks and build a zero-trust developer workflow. - **Speakers:** Jackie - **Event:** Coffee With Developers - **Published:** June 2, 2025 - **Duration:** 24:01 - **URL:** https://www.wearedevelopers.com/videos/1343-what-the-hack-is-web-app-sec ## Summary Web application security is often treated as an intimidating, post-development afterthought rather than an accessible, foundational practice. Bridging the gap between specialized security teams and everyday software engineers requires recognizing that security is fundamentally a human and organizational challenge, not just a technical one. Much like web accessibility, secure coding represents a vast, evolving domain where perfection is impossible, but early integration prevents costly remediation and data breaches down the line. Establishing a resilient security posture relies on integrating lightweight, automated checks directly into the developer workflow. Implementing static security analysis tools—such as Ruff for Python—within git hooks and CI/CD pipelines creates immediate feedback loops. As AI-assisted development accelerates code generation, the sheer volume of classic vulnerabilities like cross-site scripting (XSS) and SQL injection is scaling proportionately. Navigating this shift demands that teams augment rapid development with structured, security-focused code reviews and continuous learning environments. Cultivating a collaborative security culture means dismantling silos and normalizing open discussions about vulnerabilities, which directly helps combat developer imposter syndrome. Rather than relying solely on a CISO, teams can build collective awareness through gamified security workshops, such as collaboratively hacking a deliberately vulnerable web app. Ultimately, the most profound shift a developer can make is adopting a zero-trust mindset toward user data: rigorously applying input validation and constantly questioning the origin and integrity of every variable before it enters the system. **Keywords:** web application security, secure coding practices, static security analysis, git hooks integration, ai-generated code vulnerabilities, xss prevention, sql injection mitigation, user input validation, ci/cd pipeline security, security-focused code review, organizational security culture, developer imposter syndrome, zero-trust mindset, gamified security workshops, vulnerability management ## Chapters 1. **Making application security accessible for developers** (00:01) — Relatable storytelling helps bridge disciplines and motivates developers to care about application security. 1. **Bridging operations, organizations, and security engineering** (02:54) — Security encompasses people and organizations beyond just technology, requiring specialized roles that developers cannot easily balance alone. 1. **Categorizing developer and consumer facing security threats** (04:42) — While technical and consumer threats differ in nature, establishing trust across all interactions requires factoring security into processes from the start. 1. **Balancing business value with proactive security investments** (07:31) — Organizations increasingly recognize that investing early in software security reduces costly data breaches and provides a competitive advantage. 1. **Mitigating common vulnerabilities through targeted code reviews** (10:39) — Implementing routine security workshops and focused code reviews significantly reduces the occurrence of easily preventable vulnerabilities like SQL injections. 1. **Evaluating artificial intelligence for code generation and vulnerabilities** (11:58) — AI assistants accelerate development but can introduce subtle security flaws, increasing the overall volume of application attacks. 1. **Distributing security ownership across the product team** (16:06) — Securing an application is a collaborative effort that requires frontend developers and designers to actively participate rather than relying solely on specialists. 1. **Integrating static security analysis into deployment workflows** (18:17) — Running static analysis tools via git hooks and promoting open communication about knowledge gaps builds a stronger security culture. 1. **Treating untrusted user input as a core security habit** (21:52) — Questioning the origin and intent of all data parameters builds a critical security mindset that prevents common application exploits. ## Related Moments - [Bridging the gap between developers and security tools](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") - [Scaling security teams through developer advocates](https://www.wearedevelopers.com/videos/193-building-security-champions) (from "Building Security Champions") - [Exploring pathways to application security careers and research workflows](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Shifting left and creating internal security champion programs](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Improving developer education with realistic security training environments](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) (from "How GitHub secures open source") - [Making security a foundational feature in software development](https://www.wearedevelopers.com/videos/100358-always-on-the-right-track-with-rails-with-eileen-uchitelle-senior-system-engineer-at-github) (from "Always on the Right Track with Rails with Eileen Uchitelle, Senior System Engineer at GitHub") ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/2628442-staff-developer-advocate-github-security-lab) at **GitHub** - [Staff Hardware Security Engineer](https://www.wearedevelopers.com/jobs/ext/1915092-staff-hardware-security-engineer) at **Arm** - [Founding Developer Advocate](https://www.wearedevelopers.com/jobs/48425-founding-developer-advocate) at **Plumber** - [SoC Security Architecture](https://www.wearedevelopers.com/jobs/ext/3020627-soc-security-architecture) at **ARM** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio** - [SoC Offensive Security Staff Engineer](https://www.wearedevelopers.com/jobs/48479-soc-offensive-security-staff-engineer) at **Arm**