OWASP Global AppSec EU 2026: thoughts and conclusions from the floor
A practitioner's recap of OWASP Global AppSec EU 2026 at the Austria Center in Vienna, OWASP's 25th anniversary edition: how AI security, su...
32 posts tagged with "appsec".
All postsA practitioner's recap of OWASP Global AppSec EU 2026 at the Austria Center in Vienna, OWASP's 25th anniversary edition: how AI security, su...
Inside the AI-offense era: autonomous systems like XBOW, Big Sleep, and Claude Mythos find and weaponize flaws in hours, while 28.3% of CVEs...
Inside the SAST shift: why rule-based static analysis drowns teams in false positives and misses logic bugs, how AI-powered SAST reasons abo...
Inside npm v12: GitHub is disabling preinstall/install/postinstall scripts, Git, and remote-URL dependencies by default, killing the install...
Inside Miasma (Shai-Hulud's npm successor): a 157-byte binding.gyp file executes code during npm install with no lifecycle script, compromis...
Inside the shift to autonomous offense: AI agents now run the full infrastructure kill chain at machine speed, from recon to domain takeover...
Inside CVE-2026-45659: an insecure-deserialization (CWE-502) flaw lets any authenticated SharePoint Server Site Member run code on-prem (CVS...
Inside CVE-2026-48095: an undefined-behavior shift in 7-Zip's NTFS handler allocates a 1-byte buffer, then writes 256 MB into it, corrupting...
AI agents run continuous black-box and grey-box DAST against your live web apps, returning real bugs with a request, a response, and a repro...
Inside CVE-2026-43640: the C# short-circuit boolean that lets any authenticated Bitwarden admin with a stolen session pull or rotate the org...
Ivanti Ivanti Endpoint Manager Mobile (versions up to 12.8.0.0) contains an improper input validation vulnerability that allows remote code...
Inside CVE-2026-42945 (NGINX Rift): the 18-year-old heap buffer overflow in NGINX's ngx_http_rewrite_module that enables unauthenticated RCE...
Connect your repositories and let AI agents handle continuous scanning, research, and triage.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.