Secure Coding


All blog articles on the subject of Secure Coding

Niklas Fuhrberg

Published on 25.08.2024 in the category Communication Security published.

What is the NIS 2 Directive? (Part 1)

In response to the increasing number of cyberattacks, the EU is introducing new measures. Among these is NIS 2, which sets new requirements for companies. (read more)


Niklas Fuhrberg

Published on 19.08.2024 in the category Communication Security published.

NIS 2: What do companies need to do? (Part 3)

As a first step, responsibilities within the company should be established. In addition to a coordinating body, such as an Information Security Officer, the executive management must also fulfill specific obligations. (read more)


Christian Birker

Published on 27.01.2023 in the category Software Security published.

What Could (Possibly) Go Wrong? - Designing Threat Modeling with a Card Game

To make the threat modeling process more playful, aramido developed a card game. This helps development teams with Security by Design. (read more)


Hannah Schneider

Published on 21.10.2021 in the category Web Application Security published.

The New OWASP Top 10 - 2021

The OWASP Top 10 - 2021 describes the ten most common security risks for web applications. They help developers implement applications securely. (read more)


Andreas Sperber

Published on 14.09.2020 in the category Security Advisories published.

Security Advisory: 1CRM Insufficient Data Protection (CVE-2020-15958)

A security vulnerability in the 1CRM software allowed unauthorized users to access sensitive files and system backups. (read more)


Tristan Wagner

Published on 09.07.2020 in the category Security Advisories published.

Two Vulnerabilities in TeamBeam

aramido was able to identify two vulnerabilities in the data exchange platform TeamBeam. (read more)


Benjamin Pokrant

Published on 06.05.2020 in the category Security Advisories published.

HTML Injection Vulnerability in WordPress Plugin WPForms

A security vulnerability in the WordPress plugin WPForms allowed attacks via HTML injection. How does this vulnerability affect systems and how can it be closed? (read more)


Andreas Sperber

Published on 09.07.2019 in the category Communication Security published.

HTTP Security Headers Protect Your Visitors

Security headers protect website users and expand the defense-in-depth strategy. We demonstrate how they are implemented and their specific impact. (read more)


Andreas Sperber

Published on 21.11.2018 in the category Web Application Security published.

What are the OWASP Top 10 - 2017?

The OWASP Top 10 - 2017 describes the ten most common security risks for web applications. They help developers implement applications securely. (read more)


Elisabeth Apicella

Published on 07.11.2018 in the category Security Advisories published.

Reflected HTML Injection in CRM Software

A security vulnerability in the web software CRM+ by Brainformatik allowed attacks via HTML injection. Who is affected and what should you do now? (read more)



Regina Okun

Published on 19.06.2018 in the category aramido published.

PHP Secure Coding Training: aramido launches external seminar offerings

Following the great success of the PHP Secure Coding training as an in-house seminar, the training can now also be booked as an external seminar. (read more)


Regina Okun

Published on 08.05.2018 in the category aramido published.

Where is the Crumple Zone of IT Systems?

Should security incidents be prevented or expected? aramido CEO Andreas Sperber answers this question on informatik-aktuell.de. (read more)



Armin Harbrecht

Published on 03.03.2017 in the category Security Advisories published.

Multiple Vulnerabilities in the New CyberForum Portal

aramido found several security vulnerabilities on the CyberForum website. They show the typical dangers of websites with user-generated content. (read more)


Armin Harbrecht

Published on 06.02.2017 in the category Security Advisories published.

Security through Transparency – How We Disclose Security Vulnerabilities

The responsible disclosure of security vulnerabilities is a proven approach to making IT systems more secure for everyone. (read more)


Armin Harbrecht

Published on 05.01.2017 in the category Software Security published.

Secure Software Updates

How can I, as a software manufacturer, provide my users with secure updates? Learn about secure software update mechanisms. (read more)


Andreas Sperber

Published on 15.12.2016 in the category Web Application Security published.

Live-Hacking a Symfony application

Andreas Sperber from aramido is a guest at SensioLabs in Cologne on Dec 21, 2016. He hacks a Symfony app and shows what can be done for IT security. (read more)