Subject 01
Security
- Web app pentest — OWASP Top 10
- API & auth abuse — sessions, tokens, IDOR
- Cloud & infra config — buckets, headers, TLS, secrets
- Data exposure & privacy — PII leaks, logs, backups
- Supply chain — dependencies, CI, third-party scripts
- AI & LLM attack surface — prompt injection, tool abuse
retest.asia



Four subjects. Security first.
