SCFM: Secure Coding Field Manual is a must for every programmer assigned to write secure code and regularly scan source code with tools like HP Fortify. SCFM is a desk reference to attacks and programming language mitigations for OWASP Top 10 and CWE/SANS Top 25 security vulnerabilities. Languages covered include Java, C/C++, C#/VB.NET/ASP.NET, HTML5/JSON, COBOL, and PL/SQL & DB2.