Trending

#OWASP

Latest posts tagged with #OWASP on Bluesky

Posts tagged #OWASP

Post image

Delve more into Authorization issues in AppSec at OWASP BASC

Vikas Malik talks about how AI Agents break Authorization Assumptions.

Check out more at www.basconf.org

#owasp #basconf #basc2026 #appsec

0 0 0 0
Post image

OWASP Ottawa is excited to announce our April 2026 meetup!

Rodrigo Rocha will be presenting their talk “Threat Modeling in Practice: From Diagram to Defense" on April 15th, 2026.

Details below👇

#owasp #ottawa #cybersecurity #threatmodeling #networking #infosec

1 0 1 0

- Add ASVS and CAPEC mapping API (cornucopia.owasp.org/api/docs) by Mahaboobunnisa Md
- Add ZAP Attack Proxy for nightly DAST scan and create mapping API endpoints for Website App, DBD and MobileApp editions (cornucopia.owasp.org/api/docs) by Mradul Tiwari

#owasp #appsec #cybersec #games #security

1 0 0 0

Mradul Tiwari , Aashish Kharel, Anirudh Panwar, Mahaboobunnisa Md, Prasun Srivastav, Anand kushwaha, Adarsh Kumar, Suresh Krishna P, Isha Parmar, Abhijit Sahoo, Ayman Algamal

Here is a short summary of what has been done:

#owasp #appsec #cybersec #games #security

1 0 1 0
Preview
Release Release v2.7.0 · OWASP/cornucopia What's Changed feat: add API endpoints for DBD edition by @Mysterio-17 in #2715 feat: Create mapping API endpoints for webapp and mobileapp editions by @Mysterio-17 in #2744 feat: add ZAP nightly ...

OWASP Cornucopia just released v2.7.0

github.com/OWASP/cornuc...

I just want to give a huge thank you to everyone who contributed this week. In non-particular order. Thank you so much

#owasp #appsec #cybersec #games #security

3 2 2 0
Original post on infosec.exchange

Hello AppSec community!

Our preparations for German #OWASP Day 2026 (GOD) are in full swing. As some of you may have noticed, the website is already live (and kicking): https://god.owasp.de/

This year’s GOD will take place on September 24, 2026, in Karlsruhe. It's a one-day conference with two […]

1 2 0 0
Post image

We’ve been working on something special…

🌟 Our first Impact Report is here!
Real stories, real voices, real impact, all made possible by you.

📄 owasp.org/assets/fil...

We are very proud of this one. Excited for what’s next 💪❤️

#OWASP #Impactreport #community #opensource #infosec #appsec

4 0 0 0
Preview
Modul WEBSEC – Web Security in der Softwarearchitektur Das iSAQB®-Modul WEBSEC vertieft Sicherheitsaspekte in der Softwarearchitektur – mit Threat Modeling, Kryptographie und Schutz vor typischen Webangriffen.

Willst du Web-Apps wirklich sicher machen❓

Modul WEBSEC: Sicherheitsgrundlagen anwenden
✓ Angriffsvektoren erkennen
✓ OWASP Top 10 umsetzen
✓ Strategien für Web- & Embedded-Systeme

18.–20. Mai 2026 | München
👉 https://f.mtr.cool/wymrhbcgxg

#WebSecurity #OWASP

0 0 0 0
Preview
OWASP Top 10 Explained: Real-World Vulnerabilities & How to Fix Them ⚠️ If your application is not tested against OWASP Top 10, it's not secure — it's just...

OWASP Top 10 Explained: Real-World Vulnerabilities & How to Fix Them ⚠️ If your application is not tested against OWASP Top 10, it's not secure — it's just untested. Let’s be ho...

#devsecops #security #owasp #webdev

Origin | Interest | Match

1 0 0 0
Post image

#OWASP Global #AppSec EU call for volunteers is now open! If you are interested in helping the foundation host this event, sign up today: owasp.wufoo.com/form...

#cybersecurity #devsecops

0 0 0 0
Preview
Migrating from CRS 3.3 to CRS 4.25 LTS — Part 2: Configuration This is Part 2 of the CRS 3.3 → 4.25 LTS migration series. Part 1 provided an overview of the migration. This post covers the crs-setup.conf changes — the most immediately breaking part of the upgrade for most operators. If you take one thing from this post: do not reuse your CRS 3 crs-setup.conf with CRS 4 without reviewing every variable in it. Some variables were renamed, some were removed, and several new ones are required for features that did not exist in CRS 3.

Part 2 of the CRS 3→4 migration series: configuration. Don't reuse your old crs-setup.conf — variables were renamed, split, and added. Post includes a full checklist and an interactive migration tool.
coreruleset.org/2026...
#OWASP #CRS #WAF #AppSec

0 0 0 0
Post image

Learn again more on AI Security at OWASP BASC

Dan D'Avella will talk about Autonomous Remediation using AI Security Agents.

Check out more at www.basconf.org

#owasp #basc2026 #basconf #appsec

0 0 0 0
Post image

Our #OWASP February Virtual 25th Anniversary videos are now live! www.youtube.com/play...

#cybersecurity #appsec #devsecops

1 0 0 0
Post image

Exciting news from @infosecmap@bird.makeup

🎙️ Podcasts & Live Streams: all cybersecurity talks & shows in one searchable hub.
And don't forget to explore the OWASP Hub: chapters, events, meetups & trainings worldwide.

infosecmap.com/owasp/

#InfoSecCommunity #LiveStreams #OWASP

3 0 0 0
Preview
iX-Workshop: OWASP Top 10 – Sicherheitsrisiken für Webanwendungen verstehen Lernen Sie die wichtigsten Sicherheitslücken in Webanwendungen kennen und erfahren Sie, wie Sie sich erfolgreich schützen können.

Lernen Sie die wichtigsten Sicherheitslücken in Webanwendungen kennen und erfahren Sie, wie Sie sich erfolgreich schützen können. #OWASP

0 0 0 0
Post image

Learn all about AI Security at OWASP BASC

Jonathan Dutson will talk about how Agentic Workflows can be compromised

Check out more at www.basconf.org

#owasp #appsec #basconf #basc2026

0 0 0 0
Post image

Last Day to buy tickets! Last few tickets left!

Grab your chance to listen and meet experts in application security and get some new skills. Buy your ticket at www.basconf.org — ticket refunded at check-in!

#appsec #basconf #owasp #basc2026

0 0 0 0
Post image

Up your game in auditing applications at OWASP BASC

Michael Kreuger is conducting a workshop to learn how to audit your application for SDKs in it.

Check out more at www.basconf.org

#owasp #basconf #basc2026 #appsec

0 0 0 0
Post image

Tomorrow is the last day to buy BASC tickets!

Grab yours at www.basconf.org and get access to a day full of talks, workshops and a chance to win some amazing raffle prizes.

#appsec #basc2026 #basconf #owasp

0 0 0 0
Post image

Learn some new skills at OWASP BASC

Tony Quadros will be conducting a hands on workshop on writing custom static analysis rules

Check out more at www.basconf.org

#appsec #basconf #basc2026 #owasp

0 0 0 0
Preview
How Google Cloud Armor Helps Close OWASP Top 10 Risks in 2026 Most teams don’t fail OWASP because they ignore it. They fail because they can’t turn it into enforcement.

A useful point on Google Cloud Armor: OWASP awareness is not enough without enforcement. Strong edge controls can help reduce injection attempts, abusive automation, and pressure on fragile apps.
medium.com/google-cloud...
#CloudSecurity #GoogleCloud #GCP #OWASP #DevSecOps

0 0 0 0
Preview
Full Disclosure: [CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability

Kine of a neat vulnerability discovered in the OWASP Common Rule Set. Test your stuff on Windows folks!

https://seclists.org/fulldisclosure/2026/Apr/0

#owasp #cve

1 0 0 0
Post image

Dive into the world of SBOMs at OWASP BASC

Kelli Schwalm will speak on how to tell if your SBOM is wrong.

Check out more at www.basconf.org

#owasp #appsec #basconf #basc2026

0 0 0 0
Preview
GenAI Security Project ramps up guidance for AppSec teams New resources for providing practical guidance and tools for securing generative and agentic AI have been released by OWASP's GenAI Securi...

AI risks are evolving fast and OWASP's GenAI Security Project is keeping pace—new red-teaming taxonomy, 200+ mapped solutions, and updated guidance for AppSec teams. jpmellojr.blogspot.com/2026/04/gena.... #AppSec #GenAI #OWASP #AISecurity

1 0 0 0
Post image

Only 3 days left to secure your ticket to the application security conference. Spend a day learning from 18 talks, 4 expert‑led workshops, and enjoy raffle prizes. Buy at www.basconf.org — ticket refunded at check-in!

#appsec #basconf #owasp #basc2026

0 0 0 0
Post image

Learn about traditional and non traditional methods of AppSec

Gaurav Kulkarni will talk about how variant hunting redefines vulnerability management

Check out more at www.basconf.org

#appsec #owasp #basconf #basc2026

0 0 0 0
Post image

Big thank you to our Platinum sponsor NowSecure !

NowSecure provides a full suite of security and privacy testing solutions purpose-built for mobile apps.
Want to sponsor OWASP BASC 2026? Check out our website www.basconf.org

#owasp #basc #basc2026 #appsec

0 0 0 0
Preview
Workshop Resources: OWASP Threat and Safeguard Matrix (TaSM) The Cybersecurity Club hosted a global workshop led by Ross Young to introduce OWASP's Threat and Safeguard Matrix (TaSM), a practical framework that maps material threats to safeguards aligned with the NIST Cybersecurity Framework. Attendees worked through phishing, ransomware, web application attacks, third‑party data loss, and AI data‑leak scenarios involving ChatGPT and Google Gemini to identify coverage gaps, prioritize investments, and explore AI automation from Clear Capabilities. #OWASP #TaSM #RossYoung #ClearCapabilities #ChatGPT #GoogleGemini #NIST

Ross Young led a global workshop on OWASP’s Threat and Safeguard Matrix (TaSM), linking threats like phishing, ransomware, and AI data leaks to safeguards aligned with NIST standards. #OWASP #AIsecurity #USA

0 0 0 0
Post image

Only 4 days left to buy your ticket to the application security conference. Spend a day learning with 18 talks, 4 workshops led by experts, plus raffle prizes. Purchase at www.basconf.org — ticket refunded at check-in! #appsec #basconf #owasp #basc2026

0 0 0 0
OWASP PTK Findings as ZAP Alerts (Juice Shop Walkthrough) OWASP PTK 9.8.0 and the ZAP OWASP PTK add-on 0.3.0 now let ZAP display OWASP PTK findings directly as ZAP Alerts. This post shows how to install the add-on, choose which PTK rules to run (SAST / IAST ...

This is huge!
www.zaproxy.org/blog/2026-04...
OWASP PTK massively increases ZAP’s browser side testing capabilities .. and automation is up next!
Many thanks to Denis Podgurskii for this great integration.
#zaproxy #owasp #appsec

6 2 0 0