#owasp

19 posts · Last used 3d

Back to Timeline
Lisi Hocke @lisihocke@mastodon.social · 5d ago
what I've experienced at OWASP Global AppSec EU 2026 and why I wouldn't have been there in the first place if it weren't for @m1r314@infosec.exchange | A Tester's Journey: OWASP Global AppSec EU 2026 - Achievement Unlocked https://www.lisihocke.com/2026/07/owasp-global-appsec-eu-2026-achievement-unlocked.html #OWASPVienna26 #OWASP #GlobalAppSec #AchievementUnlocked
2
1
2
OWASP Hamburg @owasp_hamburg@infosec.exchange · 4d ago

Moin!

Wie vorangekündigt: 28.7. ist das nächste OWASP-Treffen, bei dem ein bisschen Hamburger Lokalpariotismus mitschwingt 😉

Wie vielleicht vermutet, ist die Rede vom OWASP Juice Shop, a.k.a. "probably the most modern and sophisticated insecure web application". Das ist ein sog. OWASP-Flagship-Projekt, dass vor Kurzem sein 20. Release hatte.

Eckdaten:
  • Lokation: Baumwall 7, New Work SE (danke, New Work, vor allen Dingen: Gerrit)

  • Vortrag: Freshly Squeezed: Prompt-Injecting Juice Shops New AI Brain

  • Sprecher: Björn Kimminich und Jannik Hollenbach

  • Datum: 28.7.2026

  • Start: 18:00

  • Anmeldung: Wäre hilfreich für die Getränke, die unser Host bestellt. Entweder per Mail oder: https://www.meetup.com/owasp-hamburg-stammtisch/events/315684286

  • Presentation Language: TBD. (if you plan to come and English is better for you, let us know)

Abstract

OWASP Juice Shop's chatbot now runs on real LLM backends, either local models or the major providers' APIs.

And we're not just going to show you the new LLM challenges: we'll solve them with you, live on stage. You call out the payloads, we fire them at the bot: coaxing it into leaking data it shouldn't, hijacking its behavior with well-placed prompts, and finding out on the spot which attacks land and which ones it shrugs off. Bring your nastiest prompt-injection ideas!

We maintainers also had a "fun" year fielding large quantities of AI bot contributions of wildly differing quality. The talk covers how running a popular open-source project has changed since the boom of AI coding agents.

Beyond LLMs, 2026 kept MultiJuicer, the project for managing multiple Juice Shop instances across local or remote hackathons and trainings, busy too. It now ships with a new CTF / wargames scoreboard for tracking participant scores, which we'll show off along the way.

Nachbereitung

Das Portugiesenviertel könnte uns danach weiter verwöhnen. Wenn du zur Nachbereitung dabei bist, sag mir Bescheid. Dann würde ich für dich mit reservieren.

Sonstiges

Falls du selbst Lust auf einen Vortrag hast, oder du generell Vorträgen ein werbefreies Dach über dem Kopf bieten kannst, melde dich gerne!

Generelles zum OWASP-Treffen

Bei unseren für alle offenen Treffen geht es um Software und deren Sicherheit im Internet und/oder #Infosec allgemein. Hier treffen sich Menschen, die sich beruflich oder privat mit IT-Sicherheit beschäftigen: Entwickler, Manager, Pentester und alle an (Web)sicherheit interessierte. Die Atmosphäre ist offen und locker. Uns geht's um den Erfahrungsaustausch, Technikschnack und um's Netzwerken. Wer Produkte oder Dienstleistungen verkaufen will, ist hier falsch. Ihr seid herzlich willkommen, euren Kollegen oder Bekannten einen Hinweis auf unsere Treffen weiterzuleiten. Alle Treffen sind frei, für jeden Menschen offen und kostenlos, mit oder ohne #OWASP-Mitgliedschaft.

0
0
0
Uncle Joe @sydseter.com@bsky.brid.gy · Jul 16, 2026
OWASP Cornucopia just released v3.3.1 github.com/OWASP/cornuc... A Special thanks to Mayur Agnihotri for adding AISVS v1 “High-Impact Action Approval and Irreversibility Controls” and to Adarsh Kumar for continuing pushing out bug fixes. You both rock! #appsec #security #aisvs #owasp #ai #agentic Release Release v3.3.1 · OWASP...
0
0
0
OWASP Foundation @owasp@infosec.exchange · Jul 16, 2026
💙 Love what OWASP does? Become a member! Support the open-source projects, resources, and community that make OWASP possible while enjoying benefits like conference discounts, exclusive learning resources, an @owasp.org email address, and voting rights. Join today! 👉 https://owasp.glueup.com/organization/6727/memberships #OWASP #AppSec #CyberSecurity
2
0
2
OWASP Foundation @owasp@infosec.exchange · Jul 15, 2026
OWASP Dependency-Track 5.0 is now generally available. Codenamed Hyades, v5 delivers the biggest redesign in project history: stateless, horizontally scalable APIs; durable execution that resumes BOM processing and vulnerability analysis after crashes; component integrity verification against upstream registry tampering; and a CEL-based policy engine. Early adopters processed 20,000+ SBOMs/hour. PostgreSQL is now the sole supported database. https://dependencytrack.org/ #OWASP #SBOM
5
0
2
Daniel Isaac E @daniel_e@infosec.exchange · Jul 13, 2026
🚨 The biggest mistake in modern web security? Believing your WAF is enough. For years, we were taught: Deploy a Web Application Firewall and you're protected. That mindset no longer matches how many real-world attacks work. Today's attackers increasingly focus on: 🔓 Broken Authorization (BOLA/BFLA) 🔑 Identity & OAuth/JWT abuse 🔌 API vulnerabilities 🧠 Business Logic flaws ⚡ Race Conditions 🤖 Legitimate functionality abused in unintended ways These attacks often don't rely on payloads that a WAF is designed to block. Instead, they exploit trust. As cybersecurity professionals, we need to think beyond signatures and filtering rules. Understanding how attackers chain application logic, identities, and APIs together is becoming just as important as finding SQL injection or XSS. I wrote an article exploring this shift in modern application security. 📖 Read it here: 👉 https://danielisaace.hashnode.dev/stop-trusting-your-waf-modern-attackers-have-already-moved-on I'm curious to hear from the community: What do you think is the most overlooked attack vector in modern web applications today? Your perspective might help someone else rethink their security strategy. #CyberSecurity #ApplicationSecurity #AppSec #WebSecurity #API #OWASP #EthicalHacking #PenetrationTesting #DevSecOps #SecurityResearch #CyberDefense #InfoSec
0
0
1
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · Jul 13, 2026
🧠 Aprende a pensar como un ciberatacante para construir defensas web con un elevado nivel de ciberseguridad 🔒 ♾ Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio ✔️ De 8:00 pm a 11:00 pm (UTC -05:00) 🔈 WhatsApp: https://wa.me/51949304030 🧲 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf #WebSecurity #AppSec #OWASP #Penetesting #VulnerabilityResearch #ZedAttackProxy
0
0
0
Tanya Janca | SheHacksPurple :verified: :verified: @SheHacksPurple@infosec.exchange · Jul 10, 2026
Watch this video to hear key take aways, insights, and observations from my attendance at OWASP Global AppSec EU in Vienna, Austria, 2026. #OWASP #AppSec #aisecurity https://twp.ai/E5DeU3
1
0
0
Shostack + Associates @shostackassociates@infosec.exchange · Jul 09, 2026
The S+A team had a blast in Vienna at OWASP Global AppSec EU 2026 🇦🇹 From leading our Threat Modeling Intensive to meeting fellow members of the AppSec community, we loved the turnout and the lively discussions. Thanks to everyone who showed up with intention, dove deep, and learned by doing! We shared some reflections on the training in our blog post 👇 https://shostack.org/blog/owasp-to-blackhat-recap/ #ThreatModeling #AppSec #OWASP
0
1
0
OWASP London @OWASPLondon@infosec.exchange · Jul 08, 2026
Many thanks to Diana Kelley for presenting her talk: "Protecting Trust Boundaries in Agentic #AI: Defending Against Prompt Injection and Context Poisoning" at #OWASP London meetup last week! The video recording is now available on our YouTube Channel: 👇 https://www.youtube.com/watch?v=pTPjL_gg6mo
0
0
0
OWASP Foundation @owasp@infosec.exchange · Jul 07, 2026
Join us at the next OWASP Dorset Meetup on 15 July at Bournemouth University! Hear from Will Thomas and Atanas B on nation-state obfuscation networks and secure AI-assisted development. Food, drinks, networking & great talks. 🎟️ https://lnkd.in/eYjmFZUR #OWASP #AppSec #AI
0
0
0
Tanya Janca | SheHacksPurple :verified: :verified: @SheHacksPurple@infosec.exchange · Jul 03, 2026
Watch this video to hear key take aways, insights, and observations from my attendance at OWASP Global AppSec EU in Vienna, Austria, 2026. #OWASP #AppSec #aisecurity https://twp.ai/E5Dkei
0
0
0
NowSecure @NowSecure@infosec.exchange · Jul 02, 2026
Great week in Vienna at #OWASP Global AppSec Europe and the inaugural #OWASPMAScon! NowSecure was proud to support the event as a sponsor, speaker, and long-time @owasp@infosec.exchange MAS Advocate. Missed it? Check out the recap: https://loom.ly/0QW3Zq0 And see you in Berlin this fall!
0
1
0
NowSecure @NowSecure@infosec.exchange · Jul 01, 2026
#OWASP MASTG v2.0 is here! We're proud that the NowSecure team contributed 320+ pull requests to make this milestone a reality. Cheers to everyone in the @owasp@infosec.exchange Mobile App Security Project who collaborated to advance the state of #mobileappsec: https://loom.ly/gXI5PeA
0
1
1
Tanya Janca | SheHacksPurple :verified: :verified: @SheHacksPurple@infosec.exchange · Jun 27, 2026
Thank you #owasp for having me in Vienna for the always fantastic #owaspglobalappsec! #globalappsecvienna 💟
0
0
0
OWASP Ottawa @OWASP_Ottawa@infosec.exchange · Jan 14, 2026

OWASP is leaving Meetup.

Starting in February #OWASP #Ottawa will no longer be planning our events using Meetup.

To learn of our events you can:

2
1
1

You've seen all posts