Three new lessons just dropped: LLM Slopsquatting, CSS Injection, and CORS Try new lessons
Hacksplaining
Log in Sign up Train your team
  1. Lessons
  2. Insecure Design

  3. Lab Preview

Want everyone on your software team to learn this? Get completion tracking and compliance reporting with Hacksplaining for Teams. Free 14-day trial.

Train my team

Mistakes happen, and it's key that you learn lessons any time a vulnerability makes it into production. A post-mortem should be performed to identity where safeguards failed to protect you. Remember, you are generally looking for failures in the process rather than individuals to blame - since nobody should be acting alone, and errors are generally caused by oversights rather than recklessness.

A timeline of events in a post mortem
Lab progress
16 / 18
Back Stage 16 of 18 Continue
Hacksplaining

Defend your code.

Learn

All Lessons LLM Prompt Injection SQL Injection XSS CSRF

Teams

For Teams Features Pricing FAQ

Resources

Glossary OWASP Top 10 PCI Compliance Book

Legal

Privacy Terms DPA Subprocessors

© 2026 Hacksplaining. Built with in Seattle, WA, USA

About Us · Need help? Reach out to support@hacksplaining.com