#owasp

26 posts· Last used 10d

Save the date: Saturday October 17th. #OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters. This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon. For the community. By the community. #OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity
1
0
2
0

Moin!

Wie vorangekündigt: 28.7. ist das nächste OWASP-Treffen, bei dem ein bisschen Hamburger Lokalpariotismus mitschwingt 😉

Wie vielleicht vermutet, ist die Rede vom OWASP Juice Shop, a.k.a. "probably the most modern and sophisticated insecure web application". Das ist ein sog. OWASP-Flagship-Projekt, dass vor Kurzem sein 20. Release hatte.

Eckdaten:
  • Lokation: Baumwall 7, New Work SE (danke, New Work, vor allen Dingen: Gerrit)

  • Vortrag: Freshly Squeezed: Prompt-Injecting Juice Shops New AI Brain

  • Sprecher: Björn Kimminich und Jannik Hollenbach

  • Datum: 28.7.2026

  • Start: 18:00

  • Anmeldung: Wäre hilfreich für die Getränke, die unser Host bestellt. Entweder per Mail oder: https://www.meetup.com/owasp-hamburg-stammtisch/events/315684286

  • Presentation Language: TBD. (if you plan to come and English is better for you, let us know)

Abstract

OWASP Juice Shop's chatbot now runs on real LLM backends, either local models or the major providers' APIs.

And we're not just going to show you the new LLM challenges: we'll solve them with you, live on stage. You call out the payloads, we fire them at the bot: coaxing it into leaking data it shouldn't, hijacking its behavior with well-placed prompts, and finding out on the spot which attacks land and which ones it shrugs off. Bring your nastiest prompt-injection ideas!

We maintainers also had a "fun" year fielding large quantities of AI bot contributions of wildly differing quality. The talk covers how running a popular open-source project has changed since the boom of AI coding agents.

Beyond LLMs, 2026 kept MultiJuicer, the project for managing multiple Juice Shop instances across local or remote hackathons and trainings, busy too. It now ships with a new CTF / wargames scoreboard for tracking participant scores, which we'll show off along the way.

Nachbereitung

Das Portugiesenviertel könnte uns danach weiter verwöhnen. Wenn du zur Nachbereitung dabei bist, sag mir Bescheid. Dann würde ich für dich mit reservieren.

Sonstiges

Falls du selbst Lust auf einen Vortrag hast, oder du generell Vorträgen ein werbefreies Dach über dem Kopf bieten kannst, melde dich gerne!

Generelles zum OWASP-Treffen

Bei unseren für alle offenen Treffen geht es um Software und deren Sicherheit im Internet und/oder #Infosec allgemein. Hier treffen sich Menschen, die sich beruflich oder privat mit IT-Sicherheit beschäftigen: Entwickler, Manager, Pentester und alle an (Web)sicherheit interessierte. Die Atmosphäre ist offen und locker. Uns geht's um den Erfahrungsaustausch, Technikschnack und um's Netzwerken. Wer Produkte oder Dienstleistungen verkaufen will, ist hier falsch. Ihr seid herzlich willkommen, euren Kollegen oder Bekannten einen Hinweis auf unsere Treffen weiterzuleiten. Alle Treffen sind frei, für jeden Menschen offen und kostenlos, mit oder ohne #OWASP-Mitgliedschaft.

0
0
0
1
OWASP Dependency-Track 5.0 is now generally available. Codenamed Hyades, v5 delivers the biggest redesign in project history: stateless, horizontally scalable APIs; durable execution that resumes BOM processing and vulnerability analysis after crashes; component integrity verification against upstream registry tampering; and a CEL-based policy engine. Early adopters processed 20,000+ SBOMs/hour. PostgreSQL is now the sole supported database. https://dependencytrack.org/ #OWASP #SBOM
5
0
2
0
🚨 The biggest mistake in modern web security? Believing your WAF is enough. For years, we were taught: Deploy a Web Application Firewall and you're protected. That mindset no longer matches how many real-world attacks work. Today's attackers increasingly focus on: 🔓 Broken Authorization (BOLA/BFLA) 🔑 Identity & OAuth/JWT abuse 🔌 API vulnerabilities 🧠 Business Logic flaws ⚡ Race Conditions 🤖 Legitimate functionality abused in unintended ways These attacks often don't rely on payloads that a WAF is designed to block. Instead, they exploit trust. As cybersecurity professionals, we need to think beyond signatures and filtering rules. Understanding how attackers chain application logic, identities, and APIs together is becoming just as important as finding SQL injection or XSS. I wrote an article exploring this shift in modern application security. 📖 Read it here: 👉 https://danielisaace.hashnode.dev/stop-trusting-your-waf-modern-attackers-have-already-moved-on I'm curious to hear from the community: What do you think is the most overlooked attack vector in modern web applications today? Your perspective might help someone else rethink their security strategy. #CyberSecurity #ApplicationSecurity #AppSec #WebSecurity #API #OWASP #EthicalHacking #PenetrationTesting #DevSecOps #SecurityResearch #CyberDefense #InfoSec
0
0
1
0
🧠 Aprende a pensar como un ciberatacante para construir defensas web con un elevado nivel de ciberseguridad 🔒 ♾ Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio ✔️ De 8:00 pm a 11:00 pm (UTC -05:00) 🔈 WhatsApp: https://wa.me/51949304030 🧲 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf #WebSecurity #AppSec #OWASP #Penetesting #VulnerabilityResearch #ZedAttackProxy
0
0
0
0
The S+A team had a blast in Vienna at OWASP Global AppSec EU 2026 🇦🇹 From leading our Threat Modeling Intensive to meeting fellow members of the AppSec community, we loved the turnout and the lively discussions. Thanks to everyone who showed up with intention, dove deep, and learned by doing! We shared some reflections on the training in our blog post 👇 https://shostack.org/blog/owasp-to-blackhat-recap/ #ThreatModeling #AppSec #OWASP
0
1
0
0