Simon Bennetts ⚡

ZAP Project Lead

Simon Bennetts ⚡ boosted:
Simon Bennetts ⚡ boosted:

Heres what the ZAP team have been working on during April zaproxy.org/blog/2025-05-05-za

Simon Bennetts ⚡ boosted:
Simon Bennetts ⚡ boosted:

ZAP by Checkmarx 2.16.1 has just been released. This is a bug fix release, along with some minor enhancements.
See zaproxy.org/blog/2025-03-25-za

Simon Bennetts ⚡ boosted:
Simon Bennetts ⚡ boosted:
Simon Bennetts ⚡ boosted:

There's now a ZAP Slack that's open to everyone. You can get an invite to it via zaproxy.org/slack/invite

Simon Bennetts ⚡psiinon@infosec.exchange
2025-02-10

@pamplemouss_ @zaproxy We dont tend to use it that much I;'m afraid. We have a private slack, which we might be openning up in a bit? Or theres the old OWASP slack of course 😀

Simon Bennetts ⚡ boosted:
Simon Bennetts ⚡ boosted:

In ZAP 2.16.0 we introduced a new Client Spider 🕷️. This blog post and video explain why we did that, how it works, and where it’s going.
zaproxy.org/blog/2025-01-31-cl
#zaproxy #appsec

Simon Bennetts ⚡ boosted:
Paco Hope #resistpaco@infosec.exchange
2025-01-30

#AI #ChatGPT #OpenAI #DeepSeek

This meme needed to be made.

I hate to steal someone else's work. A reverse Tineye search didn't get me the original. I'd give credit if I could.

A five-panel comic. The first panel shows a cat sitting with a fishing line in the water and a small bucket next to them to put fish in. In the second pane another cat is approaching and in the third pane the second cat has sat down. The second cat has its own fishing rod, but it is fishing from the first cat's bucket, not the water. In the 4th pane a third cat is approaching. And in the fifth pane the third cat has sat down and is fishing from the second cat's bucket. In the fifth pane, the original cat is labeled "me", the second cat is labeled "openAI" and the third cat is labeled "DeepSeek." The joke is that people fish: OpenAI steals what people do, and then DeepSeek steals from OpenAI the things that OpenAI stole from people.
Simon Bennetts ⚡ boosted:
daniel:// stenberg://bagder
2025-01-24

Then suddenly my previous PR to CISA for fixing the wrong curl CVE (mentioned in the blog post) gets a response!

For the record, thank you @bagder for the PR, we also noticed this Mastodon thread, since there's a history of getting CVSS wrong for curl vulnerabilities, we'll try to pay closer attention in the future.
Simon Bennetts ⚡ boosted:

Whats new in ZAP 2.16.0?

See the latest ZAP Chat video: youtu.be/o_IgsCaaQMo
#appsec #zaproxy

Simon Bennetts ⚡ boosted:

ZAP by Checkmarx 2.16.0 has just been released. It includes a brand new spider, detachable tabs, policy definitions, and lots more...
See zaproxy.org/blog/2025-01-10-za

Simon Bennetts ⚡ boosted:

Today’s ZAP weekly release is the new 2.16.0 Release Candidate: zaproxy.org/download/#weekly
Please try it out and let @psiinon know how you get on with it!

Simon Bennetts ⚡ boosted:
Simon Bennetts ⚡ boosted:
Frederik Braun �freddy@security.plumbing
2024-12-27

Alrighty friends, who's going to be at #38C3 and wants to talk web/browser security?

Simon Bennetts ⚡ boosted:

We have decided to delay the ZAP 2.16 release until the New Year.
We will generate another weekly next week and then expect to release a new Release Candidate early next year.
Why? Because we have a very significant enhancement which we want to get into 2.16 😀

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst