Advertisement · 728 × 90
#
Hashtag

#AppSEC

Advertisement · 728 × 90
Szymon presenting at a conference wearing a suit made of code

Szymon presenting at a conference wearing a suit made of code

If you want to ship features faster 🚀, without piling up security debt, make sure to check out our Szymon Drosdzol's presentation at #DevWorld 🇳🇱Amsterdam!

Duck Stage 1 - Hall 3, May 7th, 17:00

agenda.devworldconference.com/DevworldConf...

#doyensec #appsec #security

0 0 0 0
Preview
Wallarm Security and DevOps teams choose Wallarm to discover all cloud-native APIs and legacy web applications running in their environment, and to detect & respond to threats against them.

The latest update for #Wallarm includes "Attacking the MCP Trust Boundary" and "Why #API Discovery Is the First Step to Securing #AI".

#cybersecurity #APISecurity #AppSec https://opsmtrs.com/453oM6P

0 0 0 0
Preview
Salt Security The leading API security company, providing the context needed to discover APIs, stop attacks, and remediate vulnerabilities to accelerate business innovation.

The latest update for #SaltSecurity includes "You're Not Watching MCPs. Anthropic's Vulnerability Shows Why You Should Be." and "Claude Mythos Changed Everything. Your #APIs Are the First Target.".

#cybersecurity #APISecurity #AppSec https://opsmtrs.com/40EBWWv

0 0 0 0
Socket Introduces Org Notifications

~Socket~
Socket launched Organization Notifications to provide batched, filterable email updates for security alerts.
-
IOCs: (None identified)
-
#AppSec #Socket #ThreatIntel

0 0 0 0
Preview
Mend Mend identifies every open source component in your software, including dependencies. It then secures you from vulnerabilities and enforces license policies throughout the software development lifecycle.

The latest update for #Mendit includes "A Poisoned Xinference Package Targets #AI Inference Servers" and "From Panic to Playbook: Modernizing Zero‑Day Response in #AppSec".

#CyberSecurity #DevOps #OpenSource #Compliance https://opsmtrs.com/3zEYo7d

1 0 0 0
Preview
GitGuardian GitGuardian is the code security platform for the DevOps generation.

The latest update for #GitGuardian includes "SnowFROC 2026: Secure Defaults, Real Trust, and a Better Layer on Top" and "Vercel April 2026 Incident: Non-Sensitive Environment Variables Need Investigation Too".

#cybersecurity #DevOps #infosec #appsec https://opsmtrs.com/3XY1xZb

1 0 0 0
Preview
LLMmap puts its finger on ML attacks A team of researchers has developed a technique that uses "fingerprinting" to identify large language models (LLMs) embedded in applicatio...

Researchers have developed a technique that uses “fingerprinting” to identify large language models embedded in applications, which can be used to accelerate attacks. jpmellojr.blogspot.com/2026/04/llmm... #AI #LLM #AppSec #LLMap

0 0 0 0
Emergency DevSec Station drop: NPM Worm in the Wild
Emergency DevSec Station drop: NPM Worm in the Wild YouTube video by DevSec Station

Then using your publish token to infect every package you maintain.
youtu.be/cACKs6IQZt8
One command can protect you immediately: npm config set ignore-scripts true
Do it today, please. Tell your team. Watch the full 60 seconds.
#AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm

3 0 1 0
Preview
The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic | flyingpenguin I’ve been getting more and more curious about the risk from Anthropic’s Claude Mythos Preview. So I pulled the system card, a whoppingly inefficient 244-page document that devotes just seven pages to…

The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic

www.flyingpenguin.com/the-boy-that... #cybersecurity #appsec #AI

1 0 0 0
Preview
260422 rootshell.online Created on Wed Apr 22 11:00:00 CST 2026 - A news, tutorials and conferences about security published on YouTube - Find the RSS Feed with latest playlists at ...

What’s trending in cybersecurity today? Find out with the latest YouTube playlist we’ve curated. 👀 www.youtube.com/playlist
#Malware #Phishing #IncidentResponse #CyberAwareness #AppSec

0 0 0 0
Post image

At OWASP Global AppSec Vienna, there will be sessions, coffee runs, vendor chats… BUT what if you left with more than swag?

Meet The Mentor ☕⚡ 25 June 2026, 10:30–11:45 CEST — speed-dating for mentors & mentees. Real convos and real connections.

#appsec #owasp #OWASPVienna26 #mentors #conference

0 0 0 0

For anyone using CodeQL, this is solid! Adding sanitizers and validators to models-as-data should make security analysis way more precise. Less noise, more signal when you're hunting for vulnerabilities. Big win for secure coding practices. #CodeQL #AppSec

1 0 0 0
Preview
260422 rootshell.online Created on Wed Apr 22 05:00:00 CST 2026 - A news, tutorials and conferences about security published on YouTube - Find the RSS Feed with latest playlists at ...

What’s trending in cybersecurity today? Find out with the latest YouTube playlist we’ve curated. 👀 www.youtube.com/playlist
#Malware #Phishing #IncidentResponse #CyberAwareness #AppSec

0 0 0 0
BaseFortify CVE report for CVE-2026-41144 showing NASA F Prime vulnerability with integer overflow and arbitrary file write details

BaseFortify CVE report for CVE-2026-41144 showing NASA F Prime vulnerability with integer overflow and arbitrary file write details

🧠 Technical breakdown

• CWE-190: Integer Overflow
• CWE-787: Out-of-bounds write
• 32-bit addition wraps → bypass ⚠️
• No path sanitization
• Arbitrary file write → potential RCE

Hard-to-detect logic flaw 🔍

#AppSec #SecureCoding #Infosec #NASA

0 0 1 0
Post image

Early bird closes April 30, save €500 on a full-course ticket for #SecAppDev 2026. You get 5 days, 10+ speakers, 22 lectures, and 4 workshops all about #appsec in Leuven, Belgium.

One week to go on the #earlybird! secappdev.org/registration/

0 0 0 0
Prompt Injection leads to RCE and Sandbox Escape in Antigravity     Prompt Injection leads to RCE and Sandbox Escape in Antigravity 0 views Eyal Estrin unread, 3:03 AM (15 minutes ago)    to https://www.pillar.security/blog/prompt-injection-leads-to-rce-and-sandbox-escape-in-antigravity Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights Social: @eyalestrin Connect: https://linktr.ee/eyalestrin Blog: https://security-24-7.com Reply all Reply to author Forward

Prompt Injection leads to RCE and Sandbox Escape in Antigravity #appsec

1 0 0 0
Socket Introduces New Reports Framework

~Socket~
Socket launched a new Reports dashboard for chart-based views of vulnerabilities, dependencies, and usage.
-
IOCs: (None identified)
-
#AppSec #Socket #ThreatIntel

0 0 0 0
Preview
Veracode Veracode’s powerful cloud-based platform, deep security expertise, and systematic, policy-based approach provide enterprises with a simpler and more scalable way to reduce application-layer risk across their global software infrastructures.

The latest update for #Veracode includes "#ApplicationSecurity Prioritization: How the Best Teams Fix What Matters Most" and "Seamless #DevSecOps for GitLab: Security Built Into Every Pipeline".

#cybersecurity #softwaresecurity #AppSec https://opsmtrs.com/3eO6tf7

0 0 0 0
Preview
Mend Mend identifies every open source component in your software, including dependencies. It then secures you from vulnerabilities and enforces license policies throughout the software development lifecycle.

The latest update for #Mendit includes "From Panic to Playbook: Modernizing Zero‑Day Response in #AppSec" and "Anthropic's Project Glasswing: What It Means for AppSec".

#CyberSecurity #DevOps #OpenSource #Compliance https://opsmtrs.com/3zEYo7d

1 0 0 0
Preview
Wallarm Security and DevOps teams choose Wallarm to discover all cloud-native APIs and legacy web applications running in their environment, and to detect & respond to threats against them.

The latest update for #Wallarm includes "Why #API Discovery Is the First Step to Securing AI" and "#CISO Spotlight: Dimitris Georgiou on Building Security that Serves People First".

#cybersecurity #APISecurity #AppSec https://opsmtrs.com/453oM6P

0 0 0 0
Socket for Jira Integration Released

~Socket~
Socket introduces a Jira Cloud integration for automated security alert ticketing and two-way sync.
-
IOCs: (None identified)
-
#AppSec #Jira #ThreatIntel

0 0 0 0
Post image Post image Post image Post image

OWASP Ottawa would like to extend its gratitude to Rodrigo Rocha for an insightful presentation on their topic, "Threat Modeling in Practice" at our April 2026 meetup! 👏

Missed it? Catch the recording on our YouTube channel!

🎥: www.youtube.com/watch?v=TXpb...

#ottawa #cyber #owasp #appsec

2 1 0 0
Post image

Freddy Dezeure at #SecAppDev 2026. Former Head of CERT-EU. Now Deputy CISO of Europe at Microsoft. Freddy will deliver the opening keynote on security by Default, NIS2, DORA, and security controls that actually hold. More details on secappdev.org/2026/speaker... #AppSec

0 0 0 0
Post image

El mayor riesgo no es lo desconocido, sino lo que se repite.

Repasamos las 10 vulnerabilidades en apps más comunes y cómo prevenirlas según #OWASP

👉 https://f.mtr.cool/hjqzxwfclg

#AppSec #Ciberseguridad #Dev

1 0 0 0
Django Audit Reporter | Secudea Independent industrial cybersecurity services, training, and practical guidance for operational environments.

Released Django Audit Reporter to make Django dependency reviews easier.

It audits one or more Django projects and generates a consolidated report with optional email delivery.

Read further on secudea.be/tools/django...
Get in from: github.com/dietersar/dj...

#Django #Python #AppSec

1 0 0 0
Post image

SecAppDev is not a conference, it's a one-week intensive course in Leuven.
90-minute lectures, a small and intimate group, hand-picked faculty. Join us June 1–5, 2026 to learn all about application security secappdev.org #AppSec #SecAppDev

0 0 0 0
BaseFortify CVE report page showing CVE-2026-41329 OpenClaw sandbox bypass vulnerability with description and CVSS score

BaseFortify CVE report page showing CVE-2026-41329 OpenClaw sandbox bypass vulnerability with description and CVSS score

The issue lies in improper context validation.

By manipulating parameters like senderIsOwner and abusing inherited context, attackers can break out of the sandbox.

Result → unauthorized privilege escalation.

#AppSec #AIsecurity #Infosec

0 0 1 0
Preview
CVE-2026-24467: CWE-640: Weak Password Recovery Mechanism for Forgotten Password OpenAEV's password reset implementation prior to version 2.0.13 has multiple weaknesses: reset tokens never expire and are only 8-digit numeric codes. Attackers can generate many valid tokens over time and brute-force them efficiently, enab

OpenAEV-Platform (<2.0.13) has a CRITICAL flaw: non-expiring, short reset tokens allow unauthenticated account takeover — even for admins. Patch to 2.0.13 now! radar.offseq.com/threat/cve-2026-24467-cw... #OffSeq #Vulnerability #AppSec

0 0 0 0
Preview
GitGuardian GitGuardian is the code security platform for the DevOps generation.

The latest update for #GitGuardian includes "Vercel April 2026 Incident: Non-Sensitive Environment Variables Need Investigation Too" and "ATLSECCON 2026: Context, Identity, and Restraint in Modern Security".

#cybersecurity #DevOps #infosec #appsec https://opsmtrs.com/3XY1xZb

0 0 0 0
Original post on securityboulevard.com

[un]prompted 2026 – Rob T. Lee, Glenn Thorpe, Dan Hubbard & Sergej Epp – Vibe Coded (Micro-Talks) Author, Creator & Presenter: Rob T. Lee, Glenn Thorpe, Dan Hubbard & Sergej Epp Our...

#Network #Security #Security #Bloggers #Network #[un]prompted #AI […]

[Original post on securityboulevard.com]

0 0 0 0