#Appsec

maschmiinw
2025-12-20

Just finished "Alice and Bob learn Secure Coding" by @SheHacksPurple. I loved the language and framework agnostic parts. That said, the language specific part was also interesting.

I'm quite sure this book, and her book about Application Security will help me a lot next year argumenting about how and why to secure a project entering its maintenance phase and cannot ask a security team.

1/2

2025-12-19

Genuine question for the #infosec community:

What's the biggest time sink in your year-end security review?

For me it was always the compliance evidence gathering. Exporting from 6 different tools, mapping to controls manually, reformatting for auditors.

Building a platform that auto-generates audit-ready reports across SOC2, PCI-DSS, ISO27001, HIPAA, and GDPR.

Curious what pain points others are hitting this time of year.

#appsec #compliance #devsecops

OWASP Foundationowasp@infosec.exchange
2025-12-19

🎉 Big news! Early Bird tickets for OWASP Global AppSec Vienna 2026 are here!
25 years of OWASP ✨ Stunning Vienna 🇦🇹 World-class training 🧠 & a conference like no other 🔥
Why wait? Register now for early bird pricing: owasp.glueup.com/event/162243/
#appsec #owasp #cybersecurity #securebydesign

OWASP Karlsruheowasp_ka@chaos.social
2025-12-19

Auf nach HH, dieses Jahr auf dem #39c3: events.ccc.de/congress/2025/hu

Wir haben spontan ein Assembly im CCH organisiert, also kommt vorbei und schnackt mit uns über dieses und jenes.

Gerne auch Teilnehmende von anderen @owasp_de Stammtischen. #appsec #owasp

2025-12-18

Become a vendor at New England's leading application security conference. Since its start in 2012, OWASP BASC has consistently welcomed at least 150 attendees.

Sponsoring this event offers a remarkable chance to engage with top experts in application security and to expand your visibility within the OWASP Community in New England and beyond. For more information, please check out our sponsorship kit at www.basconf.org

#appsec #owasp #basc2026 #basc #applicationsecurity

OWASP Foundationowasp@infosec.exchange
2025-12-18

New for Global AppSec Vienna! CFPods are OPEN 🎉
PODs = 2–3 hr, hands-on, small-group sessions running alongside the conference. Less listening, more doing 💪
Got an interactive idea? Submit now 👉 sessionize.com/owasp-global-ap

⏰ Closes Feb 16, 2026
#appsec #owasp #cybersecurity

Carolina Code Conferencecarolinacodes
2025-12-18

FYI: AppSec Tool: Speed, Accuracy, and False Positives! : What makes a good dev-centric AppSec tool? Speed is critical; aim for under 5 minutes. False positives erode trust, while false negatives are a problem too. Runtime security tools can offer rapid feedback. youtube.com/shorts/oEIM1ckVpzE

What’s trending in cybersecurity today? Find out with the latest YouTube playlist we’ve curated. 👀 youtube.com/playlist?list=PLXq
#Malware #Phishing #IncidentResponse #CyberAwareness #AppSec

What’s trending in cybersecurity today? Find out with the latest YouTube playlist we’ve curated. 👀 youtube.com/playlist?list=PLXq
#Malware #Phishing #IncidentResponse #CyberAwareness #AppSec

2025-12-17

AI-generated code is reshaping the software supply chain - but governance gaps remain.
Only 24% of orgs fully assess IP, licensing, security & quality risks. SBOM validation strongly correlates with faster remediation.

Details:
technadu.com/the-imperative-of

#AppSec #SBOM #SupplyChainSecurity

The Imperative of Software Supply Chain Security: AI-Generated Code Risks, Secure SDLC Practices, and SBOM Validation
2025-12-17

AI-generated code is reshaping the software supply chain - but governance gaps remain.
Only 24% of orgs fully assess IP, licensing, security & quality risks. SBOM validation strongly correlates with faster remediation.

Details:
technadu.com/the-imperative-of

#AppSec #SBOM #SupplyChainSecurity

The Imperative of Software Supply Chain Security: AI-Generated Code Risks, Secure SDLC Practices, and SBOM Validation
OWASP Foundationowasp@infosec.exchange
2025-12-17

Thinking about attending the OWASP London Training Days?
londonowasptrainingdays2025.sc

Watch this free video to get a taste of @dawidczagan’s training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access

HTTP Parameter Pollution - Video Tutorial youtube.com/watch?v=09ZJPcw_smE
#appsec #owasp

What’s trending in cybersecurity today? Find out with the latest YouTube playlist we’ve curated. 👀 youtube.com/playlist?list=PLXq
#Malware #Phishing #IncidentResponse #CyberAwareness #AppSec

2025-12-16

🛡️ Thử thách Mạng cho Kỹ sư Bảo mật: 100+ câu hỏi về địa chỉ IP, subnetting, CIDR và phân đoạn mạng. Kiến thức nền tảng cho phỏng vấn tại GitLab, Stripe,... ⭐ Ghim repo trên GitHub để cập nhật bài tập mới!
#mạng_máy_tính #Bảo_mật_thông_tin #phỏng_vấn #AppSec #Kỹ_sư_Bảo_mật #mở_nguồn

dev.to/fosres/computer-network

OWASP Foundationowasp@infosec.exchange
2025-12-16

🎉 Early Bird tickets are here for OWASP Global AppSec Vienna 2026!
Join us in Vienna to celebrate 25 years of OWASP with training (Jun 22–24) & conference (Jun 25–26) Expect: World-class Keynotes | 🛠️ Demos | 📱 MobileAppSecCon & more!
Register now 👉 owasp.glueup.com/event/162243/
#appsec #owasp

OWASP Foundationowasp@infosec.exchange
2025-12-16

🔥 Trainer Spotlight: @MarisaFagan & @JulianeReimann! 🔥
Join their 1-Day Security Champions Program 🔐 Turn engineers into security heroes with hands-on exercises & strategies that make a real impact.
Register 👉 londonowasptrainingdays2025.sc

#appsec #securitychampions #owasp #training

2025-12-15

Happy Holidays everyone!☃️We’re taking a break next week for our annual shutdown to celebrate another successful year and give our team time to recharge. 🙌
#doyensec #appsec #security

Snowy scene showing hills and pine trees. Announcement that we're closed from 12/22-12/26.
OWASP Foundationowasp@infosec.exchange
2025-12-15

🎤 Ready to shine on the OWASP stage? Join our free event, “So You Want to Be an OWASP Speaker,” inspired by Who Wants to Be a Millionaire?
Learn to craft standout CfPs, deliver great talks, and boost your confidence, no lifelines needed!
Join us: owasp.glueup.com/event/so-you-

#appsec #cybersecurity

ZAP 2.17.0 is now available!
It includes performance improvements, a significant reduction in “duplicate” alerts reported, and new Insights which give you key information about scans.
zaproxy.org/blog/2025-12-15-za
#zaproxy #appsec

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst