Trending

#appsec

Latest posts tagged with #appsec on Bluesky

Posts tagged #appsec

Post image

Scalable AI governance starts with a clear security roadmap.

Join us, sponsor Snyk, and expert Brendan Hann tomorrow for this FREE webcast on building a practical path to scalable AI security.

Register now: https://ow.ly/5W4950YFxov

#AISecurity #DevSecOps #AppSec

0 0 0 0
Original post on infosec.exchange

Hello AppSec community!

Our preparations for German #OWASP Day 2026 (GOD) are in full swing. As some of you may have noticed, the website is already live (and kicking): https://god.owasp.de/

This year’s GOD will take place on September 24, 2026, in Karlsruhe. It's a one-day conference with two […]

1 2 0 0
Post image

We’ve been working on something special…

🌟 Our first Impact Report is here!
Real stories, real voices, real impact, all made possible by you.

📄 owasp.org/assets/fil...

We are very proud of this one. Excited for what’s next 💪❤️

#OWASP #Impactreport #community #opensource #infosec #appsec

3 0 0 0
Preview
Cybersecurity for Startups: Your Guide to Staying Protected Master cybersecurity for startups with our timeline-based guide. Learn how early security audits protect your valuation & ensure compliance to scale safely.

🧠Hackers don’t care if you’re early-stage

They scan
They find
They exploit

Startups with weak basics are the easiest targets.

👉Fix it early, not after a breach: 7asecurity.com/blog/2026/04...


#CyberSecurity #Startups #AppSec #InfoSec

0 0 0 0
Preview
260408 rootshell.online Created on Wed Apr 8 05:00:00 CST 2026 - A news, tutorials and conferences about security published on YouTube - Find the RSS Feed with latest playlists at h...

What’s trending in cybersecurity today? Find out with the latest YouTube playlist we’ve curated. 👀 www.youtube.com/playlist
#Malware #Phishing #IncidentResponse #CyberAwareness #AppSec

0 0 0 0
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed (CVE-2025-59528)     Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed (CVE-2025-59528) 0 views Eyal Estrin unread, 12:55 AM (1 hour ago)    to https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3gcm-f6qx-ff7p Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights Social: @eyalestrin Connect: https://linktr.ee/eyalestrin Blog: https://security-24-7.com Reply all Reply to author Forward

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed (CVE-2025-59528) #appsec

0 0 0 0
GrafanaGhost: The Phantom Stealing Your Data Groups Conversations All groups and messages Sign in     GrafanaGhost: The Phantom Stealing Your Data 0 views Eyal Estrin unread, 12:55 AM (30 minutes ago)    to https://noma.security/blog/grafana-ghost/ Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights Social: @eyalestrin Connect: https://linktr.ee/eyalestrin Blog: https://security-24-7.com Reply all Reply to author Forward

GrafanaGhost: The Phantom Stealing Your Data #appsec

1 0 0 0
Preview
Veracode Veracode’s powerful cloud-based platform, deep security expertise, and systematic, policy-based approach provide enterprises with a simpler and more scalable way to reduce application-layer risk across their global software infrastructures.

The latest update for #Veracode includes "What #RSAC2026 Actually Told Us About Your Security Debt" and "Mastering Software #SupplyChain Management in 2026".

#cybersecurity #softwaresecurity #AppSec #DevSecOps https://opsmtrs.com/3eO6tf7

0 0 0 0
Microsoft AI Agent Governance Toolkit

~Socket~
Microsoft released an open-source toolkit to enforce runtime security policies for autonomous AI agents.
-
IOCs: (None identified)
-
#AI #AppSec #ThreatIntel

0 0 0 0
Post image

#OWASP Global #AppSec EU call for volunteers is now open! If you are interested in helping the foundation host this event, sign up today: owasp.wufoo.com/form...

#cybersecurity #devsecops

0 0 0 0
Preview
AI code scanners halt Internet Bug Bounty payouts The Internet Bug Bounty program has paused new submissions, citing a massive expansion in vulnerability discovery by AI code scanners.

Automated AI code scanners are identifying flaws at an industrial scale, completely outstripping the funding budgets designed for human researchers. #ai #infosec #bugbounty #appsec #devsecops #cybersecurity #opensource #technology

2 0 0 0
Post image

The shift from prompts to autonomous agents is creating a new security reality.

Join us, sponsor Snyk, and a panel of experts on April 15th for this FREE webcast on agentic AI security, discovery and benchmarking risk.

Register now: https://ow.ly/2bCU50YEV6L

#AISecurity #AgenticAI #AppSec

0 0 0 0
The Team PCP Snowball Effect: A Quantitative Analysis https://blog.gitguardian.com/team-pcp-snowball-analysis/

The Team PCP Snowball Effect: A Quantitative Analysis #appsec

0 0 0 0
WhatsApp TEE Security Audit

~Trailofbits~
Trail of Bits audited WhatsApp's Private Inference TEEs, finding and helping patch 28 vulnerabilities, including 8 high-severity flaws, before launch.
-
IOCs: (None identified)
-
#AppSec #TEE #ThreatIntel #WhatsApp

0 0 0 0
Preview
The 2026 Guide to Penetration Testing Pricing and Scoping Budgeting for a security audit? Learn everything you need to know about penetration testing pricing in 2026 and get a transparent, fixed-price quote today.

🧠Cheap pentests don’t save money
They create blind spots

Automated scans = fast
Real attacks = manual

If your app handles real data, you need testing that actually breaks things

See how pricing really works: 7asecurity.com/blog/2026/04...

#CyberSecurity #PenTesting #AppSec #InfoSec

0 0 0 0
Preview
Migrating from CRS 3.3 to CRS 4.25 LTS — Part 2: Configuration This is Part 2 of the CRS 3.3 → 4.25 LTS migration series. Part 1 provided an overview of the migration. This post covers the crs-setup.conf changes — the most immediately breaking part of the upgrade for most operators. If you take one thing from this post: do not reuse your CRS 3 crs-setup.conf with CRS 4 without reviewing every variable in it. Some variables were renamed, some were removed, and several new ones are required for features that did not exist in CRS 3.

Part 2 of the CRS 3→4 migration series: configuration. Don't reuse your old crs-setup.conf — variables were renamed, split, and added. Post includes a full checklist and an interactive migration tool.
coreruleset.org/2026...
#OWASP #CRS #WAF #AppSec

0 0 0 0
Preview
CVE-2026-1114: CWE-284 Improper Access Control in parisneo parisneo/lollms In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offli

CRITICAL vuln in parisneo/lollms v2.1.0: Weak JWT secret lets attackers forge admin tokens & escalate privileges. Patch to v2.2.0 now! 🔒 radar.offseq.com/threat/cve-2026-1114-cwe... #OffSeq #CVE20261114 #AppSec

0 0 0 0
Preview
Zenity Design and implement governance policies, identify security risks, detect emerging threats and drive automatic mitigation and response.

The latest update for #Zenity includes "After RSA, Here Is What Comprehensive Agentic AI Security Actually Looks Like" and "Identity Isn't Enough: Why #AI Agent Security Requires Runtime Context".

#cybersecurity #lowcodesecurity #appsec https://opsmtrs.com/3GN6TxH

0 0 0 0
Preview
GitGuardian GitGuardian is the code security platform for the DevOps generation.

The latest update for #GitGuardian includes "#Gartner IAM Summit 2026: Identity Expanded Faster Than Most Programs Did" and "NHI Governance Is the Outcome. GitGuardian Is How You Get There".

#cybersecurity #DevOps #infosec #appsec https://opsmtrs.com/3XY1xZb

0 0 0 0
Post image

Learn again more on AI Security at OWASP BASC

Dan D'Avella will talk about Autonomous Remediation using AI Security Agents.

Check out more at www.basconf.org

#owasp #basc2026 #basconf #appsec

0 0 0 0
Post image

Our #OWASP February Virtual 25th Anniversary videos are now live! www.youtube.com/play...

#cybersecurity #appsec #devsecops

1 0 0 0
Post image

React2Shell under active exploitation.
766+ hosts compromised.
Automated secret harvesting at scale.
Cloud creds, API keys, SSH keys exposed.
Are you rotating secrets fast enough?
Follow TechNadu.
#CyberSecurity #AppSec #InfoSec

0 0 1 0
Preview
OWASP GenAI Security Project Gets New Update, Tools Matrix In recognition of 21 GenAI risks, the standards groups recommends firms take separate but linked approaches to defending GenAI and agentic AI systems.

OWASP GenAI Security Project Gets New Update, Tools Matrix
www.darkreading.com/application-...

#InfoSec #TechSky #AppSec #AgenticAI #GenAI

0 0 0 0
Preview
260405 rootshell.online Created on Sun Apr 5 23:00:00 CST 2026 - A news, tutorials and conferences about security published on YouTube - Find the RSS Feed with latest playlists at h...

Fresh cyber content every day. Watch the newest playlist and learn how hackers think—and how to defend. 🚀 www.youtube.com/playlist
#Hacking #CyberDefense #AppSec #Ransomware #DarkWeb

0 0 0 0
Post image

Learn all about AI Security at OWASP BASC

Jonathan Dutson will talk about how Agentic Workflows can be compromised

Check out more at www.basconf.org

#owasp #appsec #basconf #basc2026

0 0 0 0
Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads     Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads 0 views Eyal Estrin unread, 9:16 AM (26 minutes ago)    to https://www.trendmicro.com/en_us/research/26/d/weaponizing-trust-claude-code-lures-and-github-release-payloads.html Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights Social: @eyalestrin Connect: https://linktr.ee/eyalestrin Blog: https://security-24-7.com Reply all Reply to author Forward

Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads #appsec

0 0 0 0
Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2 Groups Conversations All groups and messages Sign in     Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2 0 views Eyal Estrin unread, 11:16 AM (26 minutes ago)    to https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/ Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights Social: @eyalestrin Connect: https://linktr.ee/eyalestrin Blog: https://security-24-7.com Reply all Reply to author Forward

Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2 #appsec

1 0 0 0
Original post on securityboulevard.com

[un]prompted 2026 – Guardrails Beyond Vibes Author, Creator & Presenter: Jeffrey Zhang, Security Engineer, Stripe & Siddh Shah, Software Engineer, Stripe Our thanks to [un]prompted for pu...

#Network #Security #Security #Bloggers #Network #[un]prompted […]

[Original post on securityboulevard.com]

0 0 0 0
Post image

Last Day to buy tickets! Last few tickets left!

Grab your chance to listen and meet experts in application security and get some new skills. Buy your ticket at www.basconf.org — ticket refunded at check-in!

#appsec #basconf #owasp #basc2026

0 0 0 0
Video

Another talk announcement for BSides Luxembourg!

🧠💻 𝗧𝗔𝗟𝗞 𝗧𝗢 𝗔 𝗦𝗛𝗘𝗟𝗟: 𝗘𝗫𝗣𝗟𝗢𝗜𝗧𝗜𝗡𝗚 𝗔𝗜 𝗔𝗚𝗘𝗡𝗧𝗦 𝗜𝗡 𝗥𝗘𝗔𝗟 𝗧𝗜𝗠𝗘 – Parth Shukla ⚡

AI agents are no longer just chatbots—they can execute commands, access files, and interact with real systems. But what if an attacker […]

[Original post on infosec.exchange]

1 3 1 0