Malicious packages continue to infect our public package repositories; all developers must understand these threats!
While these core competencies stray slightly to the red team / pen test side, this is a solid list of what folks need to know as they grow.
SSRF vulns are growing; application security people must understand SSRF and know how to properly find it and mitigate it.
Security professionals need to have basic skills to understand and operate the technologies in our developers' tech stack.
As application security people, we must understand the threats that impact our entire user population and look for ways to help secure the Enterprise.