RT

Ranjith Tharayil

Cybersecurity Expert & Professor of Computer Science

Cybersecurity expert and Professor of Computer Science. Writing about web security, vulnerabilities, and building safer software.

612 Articles published
7 Security scanners built
Ranjith Tharayil is a cybersecurity expert and Professor of Computer Science with deep expertise in web application security, vulnerability research, and penetration testing. He brings both academic rigour and real-world practitioner experience to the field — translating complex security concepts into practical, actionable guidance for engineering teams and growing businesses.
His research and writing spans the full spectrum of modern application security: from OWASP Top 10 vulnerabilities and CWE classifications to compliance frameworks and DevSecOps practices. At PenScan, he applies this expertise to help teams find, prioritise, and fix real vulnerabilities — without needing a dedicated security hire. Every post on this blog reflects the no-jargon, evidence-based approach he brings to teaching security.
Web Application Security Penetration Testing Vulnerability Research OWASP Top 10 Security Automation DevSecOps CWE Analysis Compliance & Audit Prep
PenScan
Cybersecurity Expert & Professor

Articles by Ranjith Tharayil

Security

What is Wrap-around Error (CWE-128)?

Learn about wrap-around error (CWE-128), including how it works, real-world examples, and framework-specifi...

Jul 29, 2026 5 min read
Security

What is Use of Invariant Value in Dynamically (CWE-344)?

Learn how the Use of Invariant Value in Dynamically Changing Context vulnerability works, see real-world co...

Jul 29, 2026 5 min read
Security

What is Use of Hard-coded Cryptographic Key (CWE-321)?

Learn how hard-coded cryptographic keys work, see real-world code examples and framework-specific fixes for...

Jul 29, 2026 5 min read
Security

What is Unverified Ownership (CWE-283)?

Unverified Ownership (CWE-283) allows attackers to gain unauthorized access. Learn how it works, real-world...

Jul 29, 2026 5 min read
Security

What is Uncaught Exception (CWE-248)?

Uncaught Exception (CWE-248) occurs when an exception is not properly handled, leading to system crashes or...

Jul 29, 2026 5 min read
Security

What is Trust of System Event Data (CWE-360)?

Trust of System Event Data (CWE-360) can lead to severe security breaches by relying on unverified event da...

Jul 29, 2026 5 min read
Security

What is Small Seed Space in PRNG (CWE-339)?

Small Seed Space in PRNG (CWE-739) vulnerability explained with real-world examples, secure code fixes, and...

Jul 29, 2026 5 min read
Security

What is Session Fixation (CWE-384)?

Learn how session fixation vulnerabilities work, see real-world code examples, and discover framework-speci...

Jul 29, 2026 5 min read
Security

What is Same Seed in Pseudo-Random Number (CWE-336)?

Learn how same seed in pseudo-random number generator (PRNG) vulnerabilities work, see real-world code exam...

Jul 29, 2026 5 min read
Security

What is Concurrent Execution using Shared (CWE-362)?

Learn how race conditions occur, real-world examples of code that causes them, and framework-specific fixes...

Jul 29, 2026 5 min read
Security

What is Product UI does not Warn User of Unsafe (CWE-356)?

Learn how Product UI does not Warn User of Unsafe Actions works, real-world examples, and framework-specifi...

Jul 29, 2026 5 min read
Security

What is Predictable Seed in Pseudo-Random Number (CWE-337)?

Learn how predictable seed in PRNG works, see real-world code examples, and get framework-specific fixes to...

Jul 29, 2026 5 min read
View all 612 articles

Stop hoping you're secure.
Know that you are.

Add your domain, verify ownership with a DNS record, and run your first full security assessment. No consultants, no contracts, no infrastructure to manage.

1 free credit included  ·  No credit card required  ·  Credits valid for 1 year