Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478)
The Thymeleaf vulnerability with a CVSS score of 9.1 grabs your attention, as it should. But before you call the cavalry and claim this as …

The Thymeleaf vulnerability with a CVSS score of 9.1 grabs your attention, as it should. But before you call the cavalry and claim this as …

Is your Java application actually secure, or does it just look that way? In this episode of the Foojay Podcast, Frank is joined by Steve …

Spring Boot 3.5 goes EOL June 30, 2026. But the real risk isn't the migration. It's what happens to CVE reporting once a project reaches end …

AI coding tools sound confident even when they're wrong. Here's the psychology behind why Java developers accept bad suggestions — and …

Master AI agents with 5 developer best practices for building scalable architecture with MCP, subagents, context isolation, and guardrails.

DPoP is one of the most exciting developments in the IAM (Identity and Access Management) space in recent years. Yet many backend developers …

A Tomcat update splits TLSv1.3 cipher configuration into a new attribute, silently dropping your Spring Boot cipher restrictions. Here's how …

first, a word about ecosystems Before we dive into Shai-Hulud, before we label it “sophisticated” or “advanced” or “next generation,” we …

This is a follow-on to the article The Real Mechanics of Vulnerabilities in an Upstream/Downstream, Topsy-Turvy EOL World. What you'll learn …

Secure Java projects with SonarQube AI Code Assurance. Use AI CodeFix and the MCP Server to auto-remediate technical debt instantly.