Filter
Exclude
Time range
-
Minimum likes
CISA added 2 actively exploited flaws to its KEV list: WSO2 API Manager RCE (9.8) and an Adobe Commerce account-takeover bug (9.1). Both stem from Broken Access Control, OWASP's #1 risk. Patch by Sept 27. thehackernews.com/2026/09/ws… #CyberSecurity #AppSec #OWASP
8
GitHub integrates Copilot Memory into Agentic Autofix to generate smarter, context-aware security fixes based on codebase history. #appsec #github #copilot #devsecops
9
hunt hunt hunt hunt hunt. #BugBounty #Bugcrowd #AppSec
3
99
#AI is creating more code and more security tools to manage. In a new Techstrong TV interview, I had the chance to discuss why AppSec teams need better context, prioritization and remediation workflows as AI scales. #AppSec sprou.tt/1qBDPcwWk6a
2
26
🔐 Vous êtes connecté. Mais avez-vous vraiment accès à cette donnée ? GET /api/factures/4821 Remplacez 4821 par 4822… et vous obtenez la facture d’un autre client ? 👉 Authentification ≠ Autorisation. C’est une faille IDOR/BOLA. #Cybersecurite #API #AppSec #BOLA #Cyberka
1
7
🌐 Votre API retourne 200 OK. Tout va bien ? Pas forcément. Une erreur métier ou un accès refusé peut aussi se cacher derrière un 200. 👉 Les bons codes HTTP comptent pour la sécurité, le monitoring et les clients. #API #HTTP #AppSec #DevSecOps #Cyberka
1
7
🔐 Votre JWT est valide. Mais l’utilisateur a-t-il encore les droits ? Authentification ≠ Autorisation. Un rôle peut être retiré alors que le token reste valide. 👉 Un JWT valide ne doit jamais suffire à autoriser une action sensible. #JWT #AppSec #Cybersecurite #API
1
9
Most AI audit posts are about agents reviewing code. Trail of Bits had theirs build custom tooling from scratch before the Miden review even started, and they say it turned up a high-sev bug. #AISecurity #SecurityAudit #AppSec
1
42
🚫 Web Malware Scan Results Website: reimagined-funicular-ivory[.]vercel[.]app Security Verdict: CONFIRMED SCAM Full analysis & details: scanmalware.com/result/e71b6… #AppSec #Exploit #EthicalHacking
38
🚫 Web Malware Scan Results Website: sp12ct-morsel-biz-kavren-holdik[.]pages[.]dev Security Verdict: CONFIRMED SCAM Full analysis & details: scanmalware.com/result/d4512… #AIForGood #AppSec #DigitalSecurity
23
3,200 vulnerabilities fixed. 98% stayed fixed. Zero human security review. See how StackHawk used AI coding agents to find, fix and verify vulnerabilities in production. 📅 October 1 | 1 PM ET 📷 Register now: buff.ly/RcKPrS1 #AppSec #AISecurity
7
3,200 vulnerabilities fixed. 98% stayed fixed. Zero human security review. See how StackHawk used AI coding agents to find, fix and verify vulnerabilities in production. 📅 October 1 | 1 PM ET 🎟️ Register now: buff.ly/RcKPrS1 #AppSec #AISecurity
1
544
A model that says something wrong is an embarrassment. An agent that runs it is an incident. In OWASP's Agentic Top 10, only two or three of the ten are about the model. xygeni.io/sscs-glossary/what… #AgenticAI #AppSec #OWASP #AISecurity #Xygeni
15
Most scanners hand you a scary list and walk off. ArgosX hands you the reproduction and the one-paste fix for each finding. Watch the bug happen, then close it. getargosx.com #indiedev #appsec
1
9
From firmware to the software inside connected devices, @FiniteStateInc's world is very much our kind of world. Thanks for supporting @AppSec_Village and the AppSec community as a Silver Sponsor. 🖤 Find out more about what they do here: finitestate.io/ #AppSec
3
248
Define scope. Test the web app or API. Verify the finding. Pentrova turns confirmed issues into replayable evidence your engineers can check in staging. Explore: pentrova.ai/ #AppSec
3