Courses from 1000+ universities
AI got cheap enough that Duolingo’s most expensive plan may not survive it. I read the earnings call transcript and opened the app to see what is actually changing for learners.
600 Free Google Certifications
Artificial Intelligence
IT & Networking
Software Engineering
Supporting Victims of Domestic Violence
Know Thyself - The Value and Limits of Self-Knowledge: The Examined Life
Understanding Dementia
Organize and share your learning with Class Central Lists.
View our Lists Showcase
Learn how OWASP SKF integrates the ASVS to manage application security requirements and explore SKF Labs deployed on Kubernetes.
Technical challenges of adapting and improving OWASP ZAP for large-scale security scanning.
Visual explanation of why OAuth2, OIDC, JWT, and bearer tokens exist, how their workflows differ, and when to use them securely.
Explore runtime protection that hardens web applications and APIs against entire classes of vulnerabilities without changing code, builds, tests, or deployments.
What a secure software supply chain really involves, and why SBOMs are only the beginning of building a dedicated security function.
Learn how API specifications can expose APIs to attackers and how scanning tools reveal vulnerabilities caused by misconfigured API endpoints.
Explore how the open Dime data format builds trust-based networks, supports secure communication, and offers a modern alternative to X.509 certificates.
Learn to architect resilient software through defense-in-depth design, incident preparedness, extensibility, and overlooked web vulnerabilities.
Learn how telemetry from real-world applications exposes which open-source libraries, vulnerabilities, and licenses create genuine software supply-chain risk.
A five-domain playbook for integrating security teams, controls, and prioritized tasks into DevOps workflows across the software development lifecycle.
Applies the OWASP DevSecOps Maturity Model through live code demonstrations with open-source security tools.
Learn to audit Electron desktop apps by turning XSS vulnerabilities into remote code execution through preload scripts and IPC.
Automate continuous application-security attacks in development by running Dockerized web applications and tools, integrating scans into CI/CD, and delivering results to developers.
Learn how attackers exploit API vulnerabilities and how defenders can detect, test, and protect against them using a purple-team approach.
Learn how to design, write, and manage Capture-the-Flag events that educate security audiences.
Get personalized course recommendations, track subjects and courses with reminders, and more.