I've covered this before, but google's team has done a fantastic job of promoting improved application security practices. The gruyere (http://google-gruyere.appspot.com/) is a set of application security training activities focused on educating developers on how to identify and respond to application security issues using a real application. For those with no budget for security training, this is perfect!