mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

2.7K
active users

#appsec

14 posts14 participants4 posts today
Sonar Research<p>Ever wondered what's going on behind the scenes of your API client? 🕵️‍♀️</p><p>We dug in and found a variety of JS sandboxing pitfalls! Find out how Postman and Insomnia tried to isolate untrusted code and what challenges they faced:</p><p><a href="https://www.sonarsource.com/blog/scripting-outside-the-box-api-client-security-risks-part-1/?utm_medium=social&amp;utm_source=mastodon&amp;utm_campaign=research&amp;utm_content=blog-api-sandbox-pitfalls-250513-1&amp;utm_term=---all&amp;s_category=Organic&amp;s_source=Social%20Media&amp;s_origin=social" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">sonarsource.com/blog/scripting</span><span class="invisible">-outside-the-box-api-client-security-risks-part-1/?utm_medium=social&amp;utm_source=mastodon&amp;utm_campaign=research&amp;utm_content=blog-api-sandbox-pitfalls-250513-1&amp;utm_term=---all&amp;s_category=Organic&amp;s_source=Social%20Media&amp;s_origin=social</span></a> </p><p><a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vulnerability</span></a></p>
OWASP Boston<p>Speakers and Presenters invited! Talk at the OWASP Boston Chapter Meetup held every second Wednesday of the month! Share your experience in Application Security. Submit your talk at <a href="https://docs.google.com/forms/d/1uSfwHWiGazP_4JJ8tI0ECU23YlWzXINg4ZeDlbPZUuk/viewform" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">docs.google.com/forms/d/1uSfwH</span><span class="invisible">WiGazP_4JJ8tI0ECU23YlWzXINg4ZeDlbPZUuk/viewform</span></a> <br><a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/owasp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owasp</span></a> <a href="https://infosec.exchange/tags/owaspboston" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owaspboston</span></a></p>
Josh Grossman (tghosth👻) :verified:<p>Link to the new post is here and don't forget to check out my other posts in this series "So you want to train at Black Hat (or other conferences)?"</p><p><a href="https://www.bouncesecurity.com/blog/2025/05/13/planning-the-practical.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bouncesecurity.com/blog/2025/0</span><span class="invisible">5/13/planning-the-practical.html</span></a></p><p><a href="https://infosec.exchange/tags/BlackHat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BlackHat</span></a> <a href="https://infosec.exchange/tags/Training" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Training</span></a> <a href="https://infosec.exchange/tags/OWASP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OWASP</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a></p>
Marco Ciappelli🎙️✨:verified: :donor:<p>This Newsletter Is About <a href="https://infosec.exchange/tags/RSAC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC</span></a>... But Our Heads Are Already in London</p><p>From San Francisco to London, via Barcelona: Stories Told, Stories Coming...</p><p>We just wrapped another incredible RSA Conference — and yes, this newsletter is all about that. But if you know us (and many of you do), our minds are already across the pond.</p><p>Because you know what’s coming next.</p><p>That’s right. Infosecurity Europe 2025. London. ExCeL. </p><p>And us — Sean Martin, CISSP and Marco Ciappelli — with our mics, cameras, and a ton of curiosity.</p><p>We’ve been media partners for <a href="https://infosec.exchange/tags/InfosecurityEurope" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfosecurityEurope</span></a> since 2017, and every year we do our thing: record in and around the venue, wander the city, capture the vibe. Whether it’s the Thames, Big Ben, Abbey Road, St. Paul’s, the National Gallery, or Carnaby Street — we’ll be there, filming on location and sharing it with you.</p><p>And of course, we’ll also be deep in the <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> conversations shaping Europe — with podcast interviews, video briefings, and candid chats that explore where tech and society meet. </p><p>We’ll keep you in the loop every step of the way.</p><p>But let's talk some more about <a href="https://infosec.exchange/tags/RSAC2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC2025</span></a> ... click below, read, share - you know what to do! 😊 </p><p><a href="https://www.linkedin.com/pulse/newsletter-rsac-our-heads-already-london-itspmagazine-savpc/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">linkedin.com/pulse/newsletter-</span><span class="invisible">rsac-our-heads-already-london-itspmagazine-savpc/</span></a></p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://infosec.exchange/tags/infosecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosecurity</span></a> <a href="https://infosec.exchange/tags/technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>technology</span></a> <a href="https://infosec.exchange/tags/society" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>society</span></a> <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/owasp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owasp</span></a></p>
OWASP Foundation<p>Exciting opportunity alert! 🌟 Join us on stage at <a href="https://infosec.exchange/tags/OWASP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OWASP</span></a> Global <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> USA in Washington, DC this November. ✨ Share your knowledge and apply to present at this amazing event. Don't miss your chance to shine - submit your presentations here: <a href="https://sessionize.com/owasp-global-appsec-USA-2025-cfp2/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">sessionize.com/owasp-global-ap</span><span class="invisible">psec-USA-2025-cfp2/</span></a> 🎤 <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a> <a href="https://infosec.exchange/tags/devsecops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devsecops</span></a> <a href="https://infosec.exchange/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a></p>
Tanya Janca | SheHacksPurple :verified: :verified:<p>I just published my Trip Report from an amazing week at B-Sides SF and <a href="https://infosec.exchange/tags/RSAC2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC2025</span></a>! Highlights, photos, and everything in between — check it out here:<br><a href="https://shehackspurple.ca/2025/05/09/rsac2025/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">shehackspurple.ca/2025/05/09/r</span><span class="invisible">sac2025/</span></a></p><p><a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/BSidesSF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BSidesSF</span></a> <a href="https://infosec.exchange/tags/RSAC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC</span></a> <a href="https://infosec.exchange/tags/Infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infosec</span></a></p>
anchore<p>🔐 SBOMs aren't just another security fad. Join <a href="https://mstdn.business/tags/SBOMlearningWeek" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOMlearningWeek</span></a> with our free eBook that shows how SBOMs revolutionize <a href="https://mstdn.business/tags/software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>software</span></a> <a href="https://mstdn.business/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> by bringing transparency to dependencies and vulnerabilities. Get practical implementation guides for SPDX, CycloneDX, and more: <a href="https://get.anchore.com/sbom101-guide-for-devsecops-community/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/sbom101-guide-</span><span class="invisible">for-devsecops-community/</span></a> <a href="https://mstdn.business/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a></p>
OWASP Boston<p>Have you been doing some interesting research in Application Security? Want to show us something cool in AppSec? Submit your talk and get ready to speak at the OWASP Boston Chapter Meetup! <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/owasp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owasp</span></a> <a href="https://infosec.exchange/tags/owaspboston" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owaspboston</span></a> . Submit your talk at <a href="https://docs.google.com/forms/d/1uSfwHWiGazP_4JJ8tI0ECU23YlWzXINg4ZeDlbPZUuk/viewform" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">docs.google.com/forms/d/1uSfwH</span><span class="invisible">WiGazP_4JJ8tI0ECU23YlWzXINg4ZeDlbPZUuk/viewform</span></a></p>
OWASP Foundation<p>🚨 Last call to register! </p><p>Join security professionals from around the world at OWASP Global AppSec EU 2025 in Barcelona!</p><p>Don’t miss out on five days packed with cutting-edge talks, hands-on training, and invaluable networking opportunities.</p><p>📅 May 27–31, 2025<br>📍 Barcelona, Spain</p><p>🔗 Sign up now: <a href="https://owasp.glueup.com/event/123983/register/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">owasp.glueup.com/event/123983/</span><span class="invisible">register/</span></a></p><p>Let’s shape the future of application security together. See you in Barcelona! </p><p><a href="https://infosec.exchange/tags/OWASP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OWASP</span></a> <a href="https://infosec.exchange/tags/AppSecEU2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSecEU2025</span></a> <a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/Barcelona" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Barcelona</span></a> <a href="https://infosec.exchange/tags/RegisterNow" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RegisterNow</span></a></p>
Marco Ciappelli🎙️✨:verified: :donor:<p>🎙️ When AI writes code, builds models, and simulates threats… who checks the checker?</p><p>In this last On Location Conversation from <a href="https://infosec.exchange/tags/RSAC2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC2025</span></a>, Alex Kreilein and John Sapp Jr. join Sean Martin, CISSP to explore what trust actually means in the age of AI-generated security tooling — and how modern <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> teams must rethink validation, <a href="https://infosec.exchange/tags/resiliency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>resiliency</span></a>, and <a href="https://infosec.exchange/tags/risk" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>risk</span></a>.</p><p>This episode cuts deep into:</p><p>Why “trust the output” is not enough in AI-driven workflows<br>How <a href="https://infosec.exchange/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a> security debt is becoming the new tech debt<br>Why we need <a href="https://infosec.exchange/tags/zerotrust" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zerotrust</span></a> thinking applied to models and agents<br>The real shift: from patching CVEs to building resilient architecture<br>The role of traceability, governance, and context-driven decision-making</p><p>If you’re serious about secure AI, application security, and shifting AppSec left (the right way), this conversation will challenge what you think you know — and help reframe what secure development actually looks like.</p><p>🎥 Watch the full video:<br>👉 <a href="https://youtu.be/kJdQz9LmT6s" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtu.be/kJdQz9LmT6s</span><span class="invisible"></span></a></p><p>🎧 Listen to the audio podcast:<br>👉 <a href="https://eventcoveragepodcast.com/episodes/why-we-cant-completely-trust-the-intern-even-if-its-ai-an-rsac-conference-2025-conversation-with-alex-kreilein-and-john-sapp-jr-on-location-coverage-with-sean-martin-and-marco-ciappelli" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">eventcoveragepodcast.com/episo</span><span class="invisible">des/why-we-cant-completely-trust-the-intern-even-if-its-ai-an-rsac-conference-2025-conversation-with-alex-kreilein-and-john-sapp-jr-on-location-coverage-with-sean-martin-and-marco-ciappelli</span></a></p><p>✨ Thank you to our Full Coverage Sponsors:<br>ThreatLocker 👉 <a href="https://itspm.ag/threatlocker-r974" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/threatlocker-r974</span><span class="invisible"></span></a><br>Akamai Technologies 👉 <a href="https://itspm.ag/akamailbwc" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/akamailbwc</span><span class="invisible"></span></a><br>BLACKCLOAK 👉 <a href="https://itspm.ag/itspbcweb" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/itspbcweb</span><span class="invisible"></span></a><br>SandboxAQ 👉 <a href="https://itspm.ag/sandboxaq-j2en" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/sandboxaq-j2en</span><span class="invisible"></span></a><br>Archer Integrated Risk Management 👉 <a href="https://itspm.ag/rsaarchweb" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/rsaarchweb</span><span class="invisible"></span></a><br>ISACA 👉 <a href="https://itspm.ag/isaca-96808" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/isaca-96808</span><span class="invisible"></span></a><br>Object First 👉 <a href="https://itspm.ag/object-first-2gjl" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/object-first-2gjl</span><span class="invisible"></span></a><br>Edera 👉 <a href="https://itspm.ag/edera-434868" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/edera-434868</span><span class="invisible"></span></a></p><p>🎙️ Explore more RSAC 2025 coverage:<br>👉 <a href="https://www.itspmagazine.com/rsa-conference-usa-2025-rsac-san-francisco-usa-cybersecurity-event-infosec-conference-coverage" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">itspmagazine.com/rsa-conferenc</span><span class="invisible">e-usa-2025-rsac-san-francisco-usa-cybersecurity-event-infosec-conference-coverage</span></a></p><p>🎧 Catch all of our event conversations:<br>👉 <a href="https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverage" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">itspmagazine.com/technology-an</span><span class="invisible">d-cybersecurity-conference-coverage</span></a></p><p>🎤 Want to tell your Brand Story Briefing as part of our coverage?<br>👉 <a href="https://itspm.ag/evtcovbrf" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">itspm.ag/evtcovbrf</span><span class="invisible"></span></a></p><p>📆 Want Sean Martin, CISSP and Marco Ciappelli to cover your event or moderate your panel?<br>👉 <a href="https://www.itspmagazine.com/contact-us" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">itspmagazine.com/contact-us</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/RSAC2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC2025</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/AIsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AIsecurity</span></a> <a href="https://infosec.exchange/tags/zerotrust" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zerotrust</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/securityleadership" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securityleadership</span></a> <a href="https://infosec.exchange/tags/riskmanagement" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>riskmanagement</span></a> <a href="https://infosec.exchange/tags/technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>technology</span></a> <a href="https://infosec.exchange/tags/eventcoverage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>eventcoverage</span></a> <a href="https://infosec.exchange/tags/secureAI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>secureAI</span></a> <a href="https://infosec.exchange/tags/shiftleft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>shiftleft</span></a> <a href="https://infosec.exchange/tags/CISO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CISO</span></a></p>
Tanya Janca | SheHacksPurple :verified: :verified:<p>We also discuss Dustin’s new venture, Katilyst (<a href="https://www.katilyst.com/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">katilyst.com/</span><span class="invisible"></span></a>), a new startup focused on empowering engineering teams to take ownership of security in a practical, scalable way.</p><p><a href="https://infosec.exchange/tags/RSAC2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC2025</span></a> <a href="https://infosec.exchange/tags/SecurityChampions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityChampions</span></a> <a href="https://infosec.exchange/tags/Katilyst" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Katilyst</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a></p><p>2/2</p>
OWASP Foundation<p>Planning to attend <a href="https://infosec.exchange/tags/OWASP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OWASP</span></a> Global <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> EU soon? 🚀 Connect with a mentor for resume tips, career guidance, or public speaking help! Join the Mentor/Mentee program for a year-long mentorship to enhance your skills. Register here: <a href="https://owasp.wufoo.com/forms/zymozl71uei0k3/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">owasp.wufoo.com/forms/zymozl71</span><span class="invisible">uei0k3/</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
Sam Stepanyan :verified: 🐘<p>UK Government publishes Software Security Code Of Practice:<br><a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> </p><p>👇 <br><a href="https://www.gov.uk/government/publications/software-security-code-of-practice" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">gov.uk/government/publications</span><span class="invisible">/software-security-code-of-practice</span></a></p>
Konstantin :C_H:<p>&lt;script&gt;alert(1)&lt;/script&gt; - 403 Forbidden<br>&lt;img src=x onerror=console.log(1)&gt; - 403 Forbidden<br>&lt;svg onload=print()&gt; - 403 Forbidden</p><p>I've recently encountered a web application firewall in a pentest, blocking all my attempts to insert an XSS payload.</p><p>In such cases, I love to use the <a href="https://infosec.exchange/tags/PortSwigger" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PortSwigger</span></a> cross-site scripting cheat sheet: <a href="https://portswigger.net/web-security/cross-site-scripting/cheat-sheet" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">portswigger.net/web-security/c</span><span class="invisible">ross-site-scripting/cheat-sheet</span></a></p><p>I copied all payloads to the clipboard, pasted them into the Intruder's word list and hit the "Start attack" button.</p><p>Within seconds, I had a working proof of concept.</p><p>How do you use the XSS cheat sheet? I'm keen to know!</p><p><a href="https://infosec.exchange/tags/Pentesting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Pentesting</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://infosec.exchange/tags/BugBounty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BugBounty</span></a> <a href="https://infosec.exchange/tags/Hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hacking</span></a></p>
Tanya Janca | SheHacksPurple :verified: :verified:<p>Want learn the absolute basics of application security? Check out this helpful YouTube playlist! <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a></p><p><a href="https://youtube.com/playlist?list=PLI9RITMnVbyiNqF0_ZOR09bzn6y83h5Pp&amp;si=rH1xOJrfbWcBPEvI" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">youtube.com/playlist?list=PLI9</span><span class="invisible">RITMnVbyiNqF0_ZOR09bzn6y83h5Pp&amp;si=rH1xOJrfbWcBPEvI</span></a></p>
OWASP Foundation<p>Get ready to dive into the excitement of <a href="https://infosec.exchange/tags/OWASP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OWASP</span></a> Global <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> EU! 🚀 Be a crucial part of the event by volunteering. Your help can truly elevate the experience! Fill out the form today to seize this amazing opportunity! Join us here: <a href="https://owasp.wufoo.com/forms/z1jihpei0ws2e3v/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">owasp.wufoo.com/forms/z1jihpei</span><span class="invisible">0ws2e3v/</span></a></p>
Tanya Janca | SheHacksPurple :verified: :verified:<p>👉 Download now 🔥 </p><p><a href="https://newsletter.shehackspurple.ca/c/secure-sdlc-cheat-sheet" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">newsletter.shehackspurple.ca/c</span><span class="invisible">/secure-sdlc-cheat-sheet</span></a></p><p><a href="https://infosec.exchange/tags/SecureSDLC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecureSDLC</span></a> <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a><br>2/2</p>
Lenin alevski 🕵️💻<p>New Open-Source Tool Spotlight 🚨🚨🚨</p><p>DefectDojo consolidates DevSecOps workflows with ASPM and vulnerability management into one tool. It supports deduplication, end-to-end testing, and analysis—all Docker-deployable. Highly maintained with 4k stars on GitHub. <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a></p><p>🔗 Project link on <a href="https://infosec.exchange/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> 👉 <a href="https://github.com/DefectDojo/django-DefectDojo" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/DefectDojo/django-D</span><span class="invisible">efectDojo</span></a></p><p><a href="https://infosec.exchange/tags/Infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infosec</span></a> <a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/Software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Software</span></a> <a href="https://infosec.exchange/tags/Technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Technology</span></a> <a href="https://infosec.exchange/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://infosec.exchange/tags/CTF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTF</span></a> <a href="https://infosec.exchange/tags/Cybersecuritycareer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecuritycareer</span></a> <a href="https://infosec.exchange/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://infosec.exchange/tags/redteam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>redteam</span></a> <a href="https://infosec.exchange/tags/blueteam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>blueteam</span></a> <a href="https://infosec.exchange/tags/purpleteam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>purpleteam</span></a> <a href="https://infosec.exchange/tags/tips" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tips</span></a> <a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> <a href="https://infosec.exchange/tags/cloudsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cloudsecurity</span></a></p><p>— ✨<br>🔐 P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking 💻🏴‍☠️</p>
Bill<p>If your general impression of the emerging application space with these hip companies that drop a vowel from their name are all built on cool hip new platforms that take care of most application security considerations, I have something to tell you. </p><p>They are not.</p><p><a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/programming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>programming</span></a></p>
Marco Ciappelli🎙️✨:verified: :donor:<p>🚀 New Brand Story from <a href="https://infosec.exchange/tags/RSAC2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC2025</span></a>: Runtime Protection at the New Digital Front Line</p><p>At <a href="https://infosec.exchange/tags/RSAC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RSAC</span></a> Conference 2025, Sean Martin, CISSP sat down with Rupesh Chokshi, Senior Vice President and GM of Application Security at Akamai Technologies, to talk about how AI-driven applications and <a href="https://infosec.exchange/tags/APIs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APIs</span></a> are reshaping the security landscape.</p><p>🔐 Why are runtime attacks on APIs and <a href="https://infosec.exchange/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a> apps growing—and why is prevention alone no longer enough?</p><p>Find out how Akamai is evolving its Web Application and API Protection (<a href="https://infosec.exchange/tags/WAAP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WAAP</span></a>) strategies to meet these emerging threats head-on.</p><p>🎙️ Watch, listen, or read the full story here:<br>👉 <a href="https://www.itspmagazine.com/their-stories/the-new-front-line-runtime-protection-for-ai-and-api-driven-attacks-a-brand-story-with-rupesh-chokshi-from-akamai-an-on-location-rsac-conference-2025-brand-story" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">itspmagazine.com/their-stories</span><span class="invisible">/the-new-front-line-runtime-protection-for-ai-and-api-driven-attacks-a-brand-story-with-rupesh-chokshi-from-akamai-an-on-location-rsac-conference-2025-brand-story</span></a></p><p><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/apisecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>apisecurity</span></a> <a href="https://infosec.exchange/tags/technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>technology</span></a> <a href="https://infosec.exchange/tags/infosecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosecurity</span></a></p>