security engineer, holistic tester, quality enabler, agile experimenter, sociotechnical symmathecist, team glue. volleyball player, game lover, story escapist. she/her. #tech #security #CyberSecurity #SecurityEngineering #ProdSec #AppSec #DevSecOps #testing #quality #development #software #collaboration #pairing #EnsembleProgramming #EnsembleTesting #SoftwareTeaming #agile #experimenting #sociotechnical
This is mostly about OWASP meetings in Hamburg. Toots in DE/EN OWASP Hamburg runs a meeting for >15 years about appsec / general security. All humans are welcome to attend.
Moin!
Wie vorangekündigt: 28.7. ist das nächste OWASP-Treffen, bei dem ein bisschen Hamburger Lokalpariotismus mitschwingt 😉
Wie vielleicht vermutet, ist die Rede vom OWASP Juice Shop, a.k.a. "probably the most modern and sophisticated insecure web application". Das ist ein sog. OWASP-Flagship-Projekt, dass vor Kurzem sein 20. Release hatte.
Eckdaten:-
Lokation: Baumwall 7, New Work SE (danke, New Work, vor allen Dingen: Gerrit)
-
Vortrag: Freshly Squeezed: Prompt-Injecting Juice Shops New AI Brain
-
Sprecher: Björn Kimminich und Jannik Hollenbach
-
Datum: 28.7.2026
-
Start: 18:00
-
Anmeldung: Wäre hilfreich für die Getränke, die unser Host bestellt. Entweder per Mail oder: https://www.meetup.com/owasp-hamburg-stammtisch/events/315684286
-
Presentation Language: TBD. (if you plan to come and English is better for you, let us know)
OWASP Juice Shop's chatbot now runs on real LLM backends, either local models or the major providers' APIs.
And we're not just going to show you the new LLM challenges: we'll solve them with you, live on stage. You call out the payloads, we fire them at the bot: coaxing it into leaking data it shouldn't, hijacking its behavior with well-placed prompts, and finding out on the spot which attacks land and which ones it shrugs off. Bring your nastiest prompt-injection ideas!
We maintainers also had a "fun" year fielding large quantities of AI bot contributions of wildly differing quality. The talk covers how running a popular open-source project has changed since the boom of AI coding agents.
Beyond LLMs, 2026 kept MultiJuicer, the project for managing multiple Juice Shop instances across local or remote hackathons and trainings, busy too. It now ships with a new CTF / wargames scoreboard for tracking participant scores, which we'll show off along the way.
NachbereitungDas Portugiesenviertel könnte uns danach weiter verwöhnen. Wenn du zur Nachbereitung dabei bist, sag mir Bescheid. Dann würde ich für dich mit reservieren.
SonstigesFalls du selbst Lust auf einen Vortrag hast, oder du generell Vorträgen ein werbefreies Dach über dem Kopf bieten kannst, melde dich gerne!
Generelles zum OWASP-TreffenBei unseren für alle offenen Treffen geht es um Software und deren Sicherheit im Internet und/oder #Infosec allgemein. Hier treffen sich Menschen, die sich beruflich oder privat mit IT-Sicherheit beschäftigen: Entwickler, Manager, Pentester und alle an (Web)sicherheit interessierte. Die Atmosphäre ist offen und locker. Uns geht's um den Erfahrungsaustausch, Technikschnack und um's Netzwerken. Wer Produkte oder Dienstleistungen verkaufen will, ist hier falsch. Ihr seid herzlich willkommen, euren Kollegen oder Bekannten einen Hinweis auf unsere Treffen weiterzuleiten. Alle Treffen sind frei, für jeden Menschen offen und kostenlos, mit oder ohne #OWASP-Mitgliedschaft.
Co-leader OWASP Cornucopia. If you like what we do for open source, visit our code repository github.com/OWASP/cornucop... and give us a star ⭐ 🌈 «Difference is of the essence of humanity» 🦄 – John Hume #appsec #owasp #cornucopia #threatmodeling 🌉 bridged from 🦋 sydseter.com, follow @bsky.brid.gy to interact
We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide
We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide
Offensive-security–focused cybersecurity student. Interested in adversary behavior, covert techniques, and real-world attack paths. Writing on Medium.
🏴☠️ Hacking 👽 Forensics 🌐 OSINT 🛡️ CyberSecurity 🐞 Malware 🐧Linux
Author of Alice and Bob Learn Secure Coding AND Alice and Bob Learn Application Security! She/her/lady/woman. shehackspurple.ca Secure Coding Training and Public Speaking Inquiries & other: Tanya (at) shehackspurple (dot) ca #AppSec, #DevSecOps 🌻
Shostack + Associates helps customers deliver better products, faster and with less churn or internal conflict. Our approach focuses on threat modeling as a way to “measure twice, cut once.”
#OWASP London Chapter Twitter: https://twitter.com/OWASPLondon Meetup page: https://meetup.com/OWASP-London Facebook page: https://www.facebook.com/OWASPLondon LinkedIN page: https://uk.linkedin.com/company/owasplondon YouTube channel: https://youtube.com/OWASPLondon
We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide
Author of Alice and Bob Learn Secure Coding AND Alice and Bob Learn Application Security! She/her/lady/woman. shehackspurple.ca Secure Coding Training and Public Speaking Inquiries & other: Tanya (at) shehackspurple (dot) ca #AppSec, #DevSecOps 🌻
Author of Alice and Bob Learn Secure Coding AND Alice and Bob Learn Application Security! She/her/lady/woman. shehackspurple.ca Secure Coding Training and Public Speaking Inquiries & other: Tanya (at) shehackspurple (dot) ca #AppSec, #DevSecOps 🌻
The OWASP Chapter for Canada's Capital region. https://owasp.org/www-chapter-ottawa/ Join us for monthly meetups discussing a variety of security topics.
OWASP is leaving Meetup.
Starting in February #OWASP #Ottawa will no longer be planning our events using Meetup.
To learn of our events you can:
- Keep following us here and turn on notifications.
- Follow us on BlueSky at https://bsky.app/profile/owaspottawa.bsky.social
- and our owasp.org/ottawa page.
You've seen all posts