Securing Laravel
  • Home
  • In Depth Articles
  • Security Tips
  • Archives
  • About
  • Laravel Security Audits & Pentests
  • Practical Laravel Security Course
Sign in Subscribe
Newsletter

Oops, broken link...

The teams discount link was broken

Stephen Rees-Carter

Stephen Rees-Carter

26 Nov 2021
Share

This post is for subscribers only

Subscribe now

Already have an account? Sign in

Read more

Security Tip: Do You Know Your SameSite Cookies?

Security Tip: Do You Know Your SameSite Cookies?

[Tip #133] SameSite=Lax is the Laravel default, and it quietly protects you from CSRF. So why do I keep finding SameSite=None in the apps I audit? Let's talk about what it does and how to use it safely.

By Stephen Rees-Carter 03 Aug 2026
In Depth: Three Reasonable Decisions, One Critical Vulnerability

In Depth: Three Reasonable Decisions, One Critical Vulnerability

[In Depth #41] What do you get when you combine an API, SameSite=None, and a Session cookie?

lock-1 By Stephen Rees-Carter 20 Jul 2026
Security Tip: Have You Heard Of Slopsquatting?

Security Tip: Have You Heard Of Slopsquatting?

[Tip #132] Your AI agent hallucinates a package name, confidently installs it, and keeps working - except an attacker registered that exact name, packed with malware. Welcome to slopsquatting.

By Stephen Rees-Carter 01 Jul 2026
Security Tip: Safely Updating Dependencies

Security Tip: Safely Updating Dependencies

[Tip #131] Updating packages used to be a no-brainer, but now you need to be careful. Updates may be malicious. But not updating leaves vulns unpatched. So what do you do??? 🤷

By Stephen Rees-Carter 20 Jun 2026

Securing Laravel

The essential security resource for Laravel developers.

Securing Laravel
  • Subscribe
  • In Depth Articles
  • Security Tips
  • Archives
  • Stephen's Socials
Powered by Ghost