Trending

#webappsec

Latest posts tagged with #webappsec on Bluesky

Latest Top
Trending

Posts tagged #webappsec

Preview
CVE-2026-28411: CWE-288: Authentication Bypass Using an Alternate Path or Channe CVE-2026-28411 is a critical security vulnerability identified in the WeGIA web management software developed by LabRedesCefetRJ. The vulnerability stems from the unsafe use of PHP's extract() function on the $_REQUEST superglobal array in

CRITICAL: LabRedesCefetRJ WeGIA (<3.6.5) auth bypass lets attackers access admin & sensitive data. Upgrade to 3.6.5+ now to stay secure! 🔒 radar.offseq.com/threat/cve-2026-28411-cw... #OffSeq #WebAppSec #Vulnerability

0 0 0 0
Preview
Using ZAP's Encode/Decode/Hash Add-on with CyberChef via Encode/Decode Scripts Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.

I wrote a Blog post about combining ZAP with CyberChef.

#AppSec #WebAppSec #BugBountyTips

www.zaproxy.org/blog/2026-02...

3 1 0 0

@zaproxy.org Released add-ons today:

GraphQL ➡️ Fixes the optional integration with the Tech Detection add-on which had been failing.

OpenAPI ➡️ Re-enables Swagger Secret Detector Script Scan Rule, the JS Engine memory leak has been addressed.

#AppSec #DevSecOps #WebAppSec #BugBountyTips

2 2 0 0

some days it’s dry. some days it’s gold. you only get the gold if you show up. #webappsec

3 0 0 0
Preview
GitHub - zaproxy/zaproxy: The ZAP by Checkmarx Core project The ZAP by Checkmarx Core project. Contribute to zaproxy/zaproxy development by creating an account on GitHub.

Hey Bluesky. Can you get @zaproxy.org to 15k ⭐️?

#OpenSource #DAST #AppSec #WebAppSec #ITSec #CyberSec #PenTest #BugBountyTips

Current Stars 14500

github.com/zaproxy/zapr...

1 0 0 0
Preview
Release Version 2.4.0 · paragonie/sodium_compat The biggest change (besides unit testing) in this release is the optimization of Curve25519 field arithmetic by using object properties instead of an internal array. This skips some internal overhe...

We're happy to announce an update to sodium_compat that improves performance.

See github.com/paragonie/so...

#PHP #cryptography #libsodium #crypto #encryption #infosec #webappsec #appsec

1 0 0 0
Preview
Lab: Authentication bypass via OAuth implicit flow | Web Security Academy This lab uses an OAuth service to allow users to log in with their social media account. Flawed validation by the client application makes it possible for ...

I just completed the Web Security Academy lab:

Authentication bypass via OAuth implicit flow

#AuthenticationBypass #WebAppSec #Cybersecurity

portswigger.net/web-security...

1 0 1 0
URL Fuzzer - ML-powered scanner for web recon & fuzz testing Uncover hidden files and directories with our ML-powered URL Fuzzer. Cut false positives by 50% and get cleaner results from every fuzz scan.

Now it’s even easier to:
✅ Uncover unlinked or forgotten resources
✅ Spot exposed config files, DB dumps, and admin panels
✅ Cut through static and surface real exposure - fast

📎 Try the new experience 👉 pentest-tools.com/website-vuln...

#offensivesecurity #webappsec #vulnerabilityassessment

0 0 0 0
Post image

“API security is about to have its moment.”

In our latest CISO Spotlight, Rick Bohm dives into:
- Humanizing security through storytelling
- Why APIs are the weakest link
- What tomorrow’s CISOs need to succeed

📖 Read: lab.wallarm.com/ciso-spotlig...

#APIsecurity #CyberSecurity #WebAppSec

0 0 0 0

According to LinkedIn I've been working in/on Open Source for 11 years. I suspect that's on the low side, between ZAP and OWASP, but whatever.

#DAST #AppSec #WebAppSec

2 0 1 0
Preview
Rack Ruby vulnerability could reveal secrets to attackers (CVE-2025-27610) - Help Net Security Researchers found vulnerabilities in the Rack Ruby interface, including CVE-2025-27610, potentially leading to disclosure of sensitive info.

Rack Ruby vulnerability could reveal secrets to attackers (CVE-2025-27610)

📖 Read more: www.helpnetsecurity.com/2025/04/25/r...

#cybersecurity #cybersecuritynews #Ruby #WebAppSec

0 0 0 0

I've just had a minor #GitHub issue in @zaproxy.org #ZAP #zaproxy progress from issue opened to PR in 4 hours followed immediately by release of the fix. Amazing work, made possible by @checkmarxzero.bsky.social support for the project. #infosec #Pentesting #WebAppSec #AppSec

4 1 1 0

Big thanks to
@psiinon.bsky.social @kingthorin.bsky.social and all
@zaproxy.org contribs for your work on #ZAP #zaproxy. Amazing #infosec #Pentesting tool. Huge thanks to @checkmarxzero.bsky.social & @crashappsec.bsky.social for supporting this important project. #WebAppSec #AppSec

4 2 1 0
Preview
ZAP Updates - March 2025 We released 2.16.1 and made more authentication handling improvements.

The @zaproxy.org team did some stuff in March 😎 You can get the details here:
www.zaproxy.org/blog/2025-04...

#DAST #AppSec #WebAppSec #DevSecOps

2 0 0 0

11/ #Cybersecurity #InfoSec #Vulnerability #Ransomware #Malware #npm #Firefox #Pegasus #SolarInverters #DataBreach #ThreatIntel #CyberThreats #SecurityNews #WebAppSec #ZeroDay #PatchManagement #infostealer #blacklock #crushftp #mamont

0 0 0 0
Preview
ZAP 2.16.1 ZAP 2.16.1 has just been released. This is a bug fix release, along with some minor enhancements

📰 ZAP ⚡ release 2.16.1 just landed: www.zaproxy.org/blog/2025-03...

#AppSec #WebAppSec #BugBountyTips #PenTest #DevSecOps

2 0 0 0
Post image

Giant set of #zaproxy add-on releases this morning. Including many fixes and improvements.

#DAST #AppSec #DevSecOps #WebAppSec #RedTeam #WebAppSec

0 0 0 0
Preview
a man in a red robe is celebrating with his arms in the air and says `` that 's a win ! '' ALT: a man in a red robe is celebrating with his arms in the air and says `` that 's a win ! ''

#WednesdayWin I had a PR merged this morning which means none of ZAP's core scan rules (active and passive) no longer use CWE-200 which is not supposed to be mapped 🥳🎉

#AppSec #WebAppSec #standards #DevSecOps #PenTest #Redteam #PurpleTeam

How have you WON this week?!?!

0 0 1 0
Post image

According to my VM update this morning @zaproxy.org y 2.16.0 is now available on @kalilinux.bsky.social nux

#DAST #PenTest #WebAppSec #AppSec #RedTeam #PurpleTeam

1 1 0 0
Preview
ZAP 2.16.0 ZAP 2.16.0 has just been released. It includes a brand new spider, detachable tabs, policy definitions, and lots more…

We’ve just released @zaproxy.org 2.16!!

#DAST #DevSecOps #AppSec #WebAppSec #PurpleTeam #PenTest #Pentesting

www.zaproxy.org/blog/2025-01...

0 0 0 0
Post image

#WebAppSec #AppSec #DAST #PenTest #PurpleTeam #DevSecOps

3 1 0 0
Preview
The Future of Zed Attack Proxy – Simon Bennetts, Ori Bendet – ASW #302 Zed Attack Proxy has been a crucial web app testing tool for decades. It&#8217;s also had a struggle throughout 2024 to obtain funding that would enable the tool to add more features while remaining t...

Get the latest on @zaproxy.bsky.social's future from @psiinon.bsky.social & Ori Bendet via SC Magazine and Application Security Weekly podcast

#AppSec #WebAppSec #DAST #PenTesting #DevSecOps #RedTeam

www.scworld.com/podcast-segm...

1 1 0 0
Preview
Checkmarx Joins Forces with ZAP to Supercharge Dynamic Application Security Testing (DAST) for the Enterprise and Enhance Community Growth - Checkmarx ZAP project leaders Simon Bennetts, Rick Mitchell and Ricardo Pereira will join Checkmarx as employees PARAMUS, N.J. – September 24, 2024–– Checkmarx, the industry leader in cloud-native application s...

I'm very excited and proud to announce that I've accepted a position with Checkmarx to work on #DAST full time! 😀

@zaproxy.bsky.social #OpenSource #AppSec #WebAppSec #RedTeam #PenetrationTesting

checkmarx.com/press-releas...

1 0 2 0
community-scripts/other/tips/selenium/edge at main · zaproxy/community-scripts A collection of ZAP scripts provided by the community - pull requests very welcome! - zaproxy/community-scripts

New @zaproxy community tip provided by yours truly (hit the GitHub link below).

#zaproxy #DAST #AppSec #WebAppSec

github.com/zaproxy/comm...

2 1 0 0
Preview
Sponsor @kingthorin on GitHub Sponsors IT Sec guy, @zaproxy co-lead, @OWASP WSTG co-lead, @OWASP VWAD co-lead, Hac⧼3r, supporter of oxford commas, #INTJ.

Recent #OpenSource work:
- datafaker 2.2.0 release
- ZAP new default Replacer Rules (Block CSP reports and prevent caching)
- ZAP new default History Tags
- ZAP logging views for the core API
- Prep work for ZAP's 2.15 release #soon

github.com/sponsors/kin...

#AppSec #WebAppSec

0 0 0 0
Redirecting…

Did you know @OWASP has a directory of vulnerable web apps that you can test your skills and new ideas on?

#AppSec #WebAppSec #PenTest #BugBOuntyTips #OWASP

owasp.org/vwad

1 1 0 0
OWASP AppSec Days Pacific Northwest Conference The AppSec Days PNW conference is a collaborative effort between OWASP chapters from the Pacific Northwest.

Do I know anyone that's attending AppSec Days Pacific Northwest Conference??
www.appsecpnw.org

twitter.com/appsecpnw

#AppSec #WebAppSec #Canda #BritishColumbia

0 0 0 0
Post image

Чи безпечно користуватися Telegram та чи повʼязаний він з ФСБ і ГРУ РФ?

#telegram #cybersecurity #infosecurity #ukraine #boycottrussia #ukrainerussiawar #infosec #infosecurity #nationalsecurity #security #messengers #securemessengers #apss #webappsec

spadok.org.ua/tekhnologiyi...

0 0 0 0
Preview
THE OSINT AMBITION 30 Tips how to use OSINT for bug hunting: 1. Use Google Dorks to find vulnerabilities in web applications. 2. Use Shodan to find vulnerable IoT devices. 3. Use Whois to find information about domain...

30 Tips on how to use OSINT for bug hunting

👇Check below👇

#OSINT #privacy #security #cybersec #infosec #penetrationtesting #Bughunting #webappsec #websec #hacking

Check the post in our telegram channel.
t.me/osintambitio...

3 1 0 0
Vulnversity Learn about active recon, web app attacks and privilege e...

Vulnversity - I have just completed this room! Check it out: https://tryhackme.com/room/vulnversity #tryhackme #recon #privesc #webappsec #video #vulnversity via @realtryhackme

Many thanks to @AsharasInABox for the systemctl tip

Note to self - read the MAN page(s)

0 0 0 0