The curriculum
Learn
Start anywhere. Threat modelling first is the honest recommendation — everything downstream depends on knowing who you are hiding from. Or follow a path, which is an order to take them in — or start from a scenario if you have a specific worry rather than a subject. If you want one specific thing rather than a course, every chapter is listed on its own.
- Courses
- 11
- Lessons
- 104
- Exams
- 10
Secure Coding
Secure Coding
Not a vulnerability taxonomy. The habits that stop you writing the bug in the first place — parameterised queries, contextual encoding, authorization at the boundary, secrets with no fallbacks — each one taught with the check that enforces it and the incident that caused it to be written.
Expects Web Application Security
- 8 lessons
- 5 labs
- 1 exam
AI Code Security
Secure Coding
You are shipping code you did not write. This is how to review it: the bugs models actually produce, the packages they invent that attackers then register, what happens when a model with tools reads attacker-controlled text, and why the confident, idiomatic, plausible version gets reviewed least carefully.
Expects Secure Coding
- 5 lessons
- 1 lab
- 1 exam