Developer security wargame where developers practice real-world security incidents.

Sydney, Australia (HQ)
Catch vulnerabilities at design time, before the code exists. New course: threat model any feature in under 30 minutes with STRIDE and the SecDim Threat Thinking Matrix. No security background needed.
1
1
220
Rust closes off whole classes of memory bugs. Your application logic is still yours to get right. New: a Rust category in SecDim Play. Find and fix real vulnerabilities in running Rust code, scored on whether the fix holds.
2
1
106
Your app ships an LLM now. That is a new attack surface. New course: the OWASP LLM Top 10 in code, with hands-on challenges for prompt injection, malicious models, excessive agency, and more.
2
2
72
Most apps log too much of the wrong thing and miss the attacker entirely. New course: detect attacks from your logs, scrub sensitive data, and plant honeytokens that fire the moment someone probes.
2
39
New vibe coding challenges are live in the SecDim Play AI Game. Find and fix the vulnerabilities an AI assistant ships by default. Real, running code, scored on whether the fix actually holds.
2
1
37
AI writes working code in seconds. It doesn't write secure code by default. New course: threat model before you prompt, review AI output like an attacker, and write the security tests AI skips. Now on SecDim Learn:
1
25
We will be hosting a one of a kind Vibe Coder's Security Workshop at NDC Oslo, complete with an attack and defence secure coding wargame. Come say Hi if you are attending 👋 #appsec #securecoding #ai
4
80
Code review catches mistakes humans can reason about. Fuzzing finds the weird cases: malformed inputs, state transitions, parser edges, etc. Our new advanced course, Fuzzing with AI, covers the first principles and practical implementation. #AppSec #SecureCoding #Fuzzing #AI
1
36