#zaproxy

ZAP 2.17.0 is now available!
It includes performance improvements, a significant reduction in “duplicate” alerts reported, and new Insights which give you key information about scans.
zaproxy.org/blog/2025-12-15-za
#zaproxy #appsec

ZAP Updates for November 2025:
zaproxy.org/blog/2025-12-03-za
2.17.0 is coming soon, along with Insights and fixes for some issues that caused ZAP to log 50 million errors in one day!
#zaproxy #appsec

New ZAP blog post - read how Telmon Maluleka is enhancing ZAP with AI for Bug Bounty Hunting
zaproxy.org/blog/2025-11-28-en
#zaproxy #appsec #bugbounty

ZAP logged 50 MILLION errors yesterday 😮 Read the blog for more details!
zaproxy.org/blog/2025-11-25-50
#zaproxy #appsec

2025-10-29

Ok Cyberz community bring on your #WednesdayWin stories!

For me:
- I've recently past my 1yr mark at Checkmarx 🎉
- I've finished some #zaproxy rule and add-on work.
- I'm starting some #zaproxy core work 😁

Willa :donor: :nyancat:willasaywhat@infosec.exchange
2025-09-08

Anyone have experience using the ZAP docker images to scan sites? I have a context file I’m feeding the full scan image but it appears to only scan the top level and not recurse. I can see it authenticating and running the checks, but it finds only 12 URLs whereas other scanners find 212. #dast #zaproxy

The ZAP team has forked and will maintain WAVSEP going forwards. This blog post explains why.

zaproxy.org/blog/2025-09-08-za

#zaproxy #appsec #wavsep

ZAP Updates - August 2025:
zaproxy.org/blog/2025-09-02-za

Microsoft Online Login Support, forking wavsep and much, much more!
#zaproxy #appsec

We have a new #evangelists channel on the ZAP Slack: zaproxy.org/slack/
For an invite go to zaproxy.org/slack/invite
Join up and help spread the word about #zaproxy !

2025-08-13

Time for #WedneadayWins again. This week my #OpenSource journey includes more #zaproxy scan rule work, documentation contributions, a bit of GitHub actions stuff for myself personal repos. Dabbling in a bunch of different things.

Bring on your stories everyone!

All of the ZAP Docker images in the Software Security Project Docker Hub org have now been deleted.
If you were pulling from this org then please switch to the zaproxy org or use GHCR as per zaproxy.org/download/#docker
#zaproxy #appsec

ZAP Updates - July 2025
Authentication improvements, Edge support, timing rule changes, Docker news, and a new scan rule.
zaproxy.org/blog/2025-08-01-za
#zaproxy #appsec

Yesterday there were more than 25K ZAP scans run using old versions of ZAP. These are no longer being maintained.
Update your ZAP installs now!
#zaproxy #appsec

There is a new "ZAP is Out of Date" scan rule - learn more about it via this blog post
zaproxy.org/blog/2025-07-25-th
#zaproxy #appsec

We've recently made some requested changes to the naming and implementation of scan rules which used Time Based attacks. @kingthorin_rm has written about it here: zaproxy.org/blog/2025-07-22-ti
#zaproxy #appsec

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst