home.social

Search

19 results for “owasp”

  1. is proud to announce that Magno Logan, product security leader, researcher, and educator will present at OWASP Ottawa Day 2026.

    "Nobody's Mining Crypto Anymore: What Attackers Actually Want From Your CI"

    A look at how attackers are compromising GitHub Actions and software supply chains and what teams can do to better secure CI/CD workflows, tokens, and release infrastructure.

    📅 October 17, 2026
    📍 University of Ottawa - STEM 117
    ℹ️ Information: tinyurl.com/87j33b82
    🎟️ Tickets (free): tinyurl.com/mr2z6z8r

  2. OWASP Community, we need you! 🙌
    Volunteer at Global AppSec US in San Francisco this November, support the community, get involved, and earn a free conference ticket!

    Sign up today: owasp.wufoo.com/forms/z15hopm9

  3. On behalf of OWASP Ottawa, a huge thank you to Managed Risk Partners for supporting OWASP’s 25th Anniversary event at OWASP Ottawa Day!

    Your generosity makes it possible for us to bring together the Ottawa security community for a full day of workshops, mentoring sessions, and talks. Events like this only happen because organizations like Managed Risk Partners believe in investing in the community and in giving people a place to learn, connect, and grow.

    We couldn't have pulled off this milestone without you. Thank you for backing OWASP Ottawa and for helping us celebrate 25 years of AppSec.

  4. is proud to announce that Faustin Bouchard, whose work centred on AI interpretability, alignment, and behavioural integrity, will be speaking at OWASP Ottawa Day 2026.

    "Stop Policing Words. Govern Authorization."

    This talk reframes AI security as an authorisation problem, focusing on what systems allow malicious prompts to do rather than on the prompts themselves.

    📅 October 17, 2026
    📍 University of Ottawa - STEM 117
    ℹ️ Information: tinyurl.com/87j33b82
    🎟️ Tickets (free): tinyurl.com/mr2z6z8r

  5. Our next meetup is possible due to our sponsors Maze!

    This month we have Shubham Santosh Upadhyay talking about Prompt Injection and what causes it and can one detect it.

    RSVP to grab a spot at meetup.com/owaspboston/events/

    #owasp #boston #appsec

  6. iX-Workshop: OWASP Top 10 – Schwachstellen in Webanwendungen und Gegenmaßnahmen

    Lernen Sie die wichtigsten Sicherheitslücken in Webanwendungen kennen und erfahren Sie, wie Sie sich erfolgreich schützen können.

    heise.de/news/iX-Workshop-OWAS

    #XSS #CSRF #IT #iXWorkshops #OWASP #news

  7. Stickers arrived in time for the @owasp_juiceshop event with @owasp Chennai... ✨🧃✨

  8. I added a media page for Wirken because why not? OWASP slides are there too

    gebruder.ottenheimer.app/wirke

  9. One massive #tech conference. One place for the #Java #community

    At #JCONUSA26 Micah Silverman will talk about '#AI #Security Engineer Foundations: #OWASP Top 10 for Agentic Applications' as a Breakout Session!
    Introduces the OWASP Top 10 for…

    Join the #IBMTechXchange in Atlanta: 2026.usa.jcon.one

  10. Security Tip: Stop manual dependency audits and start automating. 🛡️ Modern applications rely on hundreds of third-party libraries. Integrating tools like Snyk, GitHub Advanced Security, or OWASP Dependency-Check into your CI/CD pipeline ensures every build is scanned for known vulnerabilities before deployment. Stay ahead of the latest threats and vulnerabilities: cvedatabase.com #CVE #InfoSec #CyberSecurity #DevSecOps #AppSec

  11. A useful error log should explain the failure without copying the customer’s secrets.

    Record a correlation ID, operation, outcome and timing. Exclude passwords and access tokens; redact sensitive payload fields before they reach log storage.

    Test with a fake secret, trigger a failure, and check the logs—including error paths.

    cheatsheetseries.owasp.org/che

    #Security #SoftwareEngineering

  12. Building Defensible AI Systems: My New Book for Chief AI Officers

    Published October 3, 2026. A practical reference on AI risk, controls, and audit-ready evidence.

    I just published Building Defensible AI Systems: Security and Compliance. It turns AI frameworks and regulations into controls, decision rights, and evidence you can defend. It covers dollar-based risk quantification, ISO/IEC 42001, the NIST AI RMF, EU AI Act documentation, red teaming, agent governance, and vendor risk. Each chapter stands alone, with practical examples.

    Why Did I Write a Book on Defensible AI Systems?

    Someone asks for evidence, and the room goes quiet. The AI policy sits in a folder. The risk score is a color on a heat map. The vendor promised privacy, and nobody checked. The model is already in production.

    AI is moving into business-critical decisions faster than organizations can assign ownership, set controls, and prove what they did. When a model acts without clear decision rights or technical guardrails, risk stops being a theory. It becomes financial exposure.

    I wrote this book to close the gap between engineering teams and risk officers. It skips abstract ethics and high-level summaries of regulation. You get controls, code, and evidence workflows you can put to work.

    By defensible, I mean something simple. When someone challenges a decision your AI system made, you can show who owned it, which controls applied, and what the records say.

    What Will You Be Able to Do After Reading It?

    • Put a dollar figure on AI risk. Replace heat maps with Factor Analysis of Information Risk (FAIR) and Monte Carlo simulation, with working Python and R examples.
    • Use the main frameworks as working methods. The book applies ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, and the NIST AI Risk Management Framework.
    • Prepare EU AI Act evidence. Build technical documentation, fundamental rights impact assessments, transparency measures, logging, and post-market monitoring records.
    • Find threats before attackers do. Run AI threat assessments and red team exercises mapped to MITRE ATLAS and the OWASP lists for large language models.
    • Govern AI agents. Set identity, authority limits, and runtime control gates for autonomous systems.
    • Control shadow AI and vendors. Test claims that a vendor does not train on your data, negotiate contract clauses, and write service levels you can enforce.
    • Run the operating model. Define roles, accountability, approval and escalation workflows, and monitoring after deployment.
    • Connect controls to value. Link governance to cost discipline, return on investment, and project delivery.

    The engineering side gets real attention. You will find runtime control gates, cryptographic session identities, least-privilege scoping, automated control planes with loss limits and kill-switch triggers, and AI Bills of Materials. The EU AI Act material references draft harmonized standards, which will change, so check current official texts before you lock in a compliance decision.

    Buy on Amazon.com

    At a glanceTitleBuilding Defensible AI Systems: Security and Compliance (AI Governance): How to Assess Risks and Operationalize AI ControlsAuthorHernan HuwylerFormatKindle edition, EnglishPublishedOctober 3, 2026Size2,267 pages, more than 80 chapters, 11 partsIncludesPython and R code, checklists, RACI-style role guidance, model card and risk register field guides

    Who Is Building Defensible AI Systems For?

    I wrote it for four groups who need to work from the same facts.

    • Chief AI Officers and AI governance leaders
    • Governance, risk, and compliance teams, internal audit, and legal
    • Chief information security officers, risk officers, and privacy leaders
    • AI architects, machine learning engineers, and product owners

    How Do You Read a 2,000-Page Reference Without Getting Lost?

    You do not read it front to back. I built it as a modular library. Every chapter keeps its own title and stands alone, so you can start with the problem on your desk. Chapter codes and cross-references point you to related material, and each chapter appears once in its main part to avoid repeating text.

    If you are…Start withThen go toBuilding a governance programPart 04 (operating models and RACI) and Part 02 (ISO/IEC 42001, NIST AI RMF)Part 01 for quantitative risk metricsEngineering secure AI systemsPart 06 (agents: identity and gates) and Part 07 (security, red teaming, OWASP and ATLAS)Part 09 for data quality and integrationPreparing for an audit or regulatory reviewPart 03 (EU AI Act and harmonized standards)Part 01 for FAIR loss calculations, Part 07 for event loggingManaging vendors and procurementPart 10 (procurement, contracts, third-party risk)Part 05 for total cost of ownership and financial controls

    What Makes It Different From Another Framework Summary?

    It uses numbers where most risk programs use colors. A loss exposure in dollars lets a board compare an AI project with any other investment. A red cell on a heat map does not.

    It gives you starting points you can run. The code, risk taxonomies, control gates, RACI matrices, and templates are meant for production use after you adapt them to your tech stack, jurisdiction, and risk appetite.

    It treats governance as architecture. I believe governance should enable adoption. Clear ownership, measurable risk, and audit-ready evidence are what let AI move into production with confidence.

    It is also honest about its limits. The book offers technical and operational guidance, not legal advice. Standards, enforcement dates, and draft specifications keep changing, so read the primary sources before you decide.

    Frequently Asked Questions

    What is Building Defensible AI Systems about?
    It is a practical technical reference for making AI governance work. It turns frameworks and regulations into controls, decision rights, and documentation across the full AI lifecycle, from business case and procurement to MLOps, red teaming, and continuous monitoring.

    Does it cover the EU AI Act?
    Yes. It covers technical documentation, fundamental rights impact assessments, transparency measures, logging, and post-market monitoring evidence.

    Which frameworks does it use?
    ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, the NIST AI Risk Management Framework, the OWASP lists for large language models, and MITRE ATLAS.

    Does it include code?
    Yes. You get Python and R examples for FAIR and Monte Carlo risk quantification, plus adaptable scripts and templates.

    Is it legal advice?
    No. It is technical and operational guidance. Confirm compliance decisions with current official sources and qualified counsel.

    Who wrote it?
    I did. I am an AI governance and quantitative risk practitioner with more than two decades of experience across multinational organizations. I teach AI governance and compliance as an executive professor at IE Business School, and I have trained more than 1,500 compliance, privacy, audit, and risk professionals.

    Get the Book

    Pick the part that matches the problem you have this month and start there. Then tell me which chapter you needed most, or which problem you wish it solved sooner.

    Buy on Amazon.com

  13. Vaultwarden mit Docker – Schritt für Schritt

    Deine Compose-Datei ist eine gute Grundlage. Ein paar Dinge darin machen allerdings Probleme. Die habe ich in der Anleitung korrigiert und unten am Ende erklärt.

    1. Voraussetzungen

    • Docker und das Docker-Compose-Plugin sind installiert (docker compose version).
    • Es gibt einen DNS-Eintrag, z. B. bitwarden.domain.com, der auf deinen Reverse Proxy zeigt.
    • Das externe Netz docknet existiert. Prüfen kannst du das mit docker network ls. Falls es fehlt:

    bash

    docker network create --subnet 172.16.0.0/24 docknet

    2. Verzeichnis anlegen

    bash

    mkdir -p /opt/vaultwarden && cd /opt/vaultwarden

    3. Admin-Token als Hash erzeugen

    bash

    docker run --rm -it vaultwarden/server:latest /vaultwarden hash

    Gib zweimal ein starkes Passwort ein und kopiere den Hash, der mit $argon2id$… beginnt. Mit diesem Passwort (nicht mit dem Hash) meldest du dich später unter /admin an.

    4. .env mit den Geheimnissen anlegen

    So stehen keine Passwörter direkt in der Compose-Datei.

    bash

    nano .env

    env

    # Einfache Anführungszeichen sind wichtig, damit die $-Zeichen im Hash nicht ersetzt werden
    ADMIN_TOKEN='$argon2id$v=19$m=65540,t=3,p=4$...'
    
    DB_NAME=vaultdb
    DB_USER=vaultuser
    DB_PASSWORD=EinLangesPasswortOhneSonderzeichen
    DB_ROOT_PASSWORD=NochEinLangesPasswort
    
    SMTP_PASSWORD='dein-smtp-passwort'

    bash

    chmod 600 .env

    Tipp: Nimm für DB_PASSWORD nur Buchstaben und Zahlen. Es landet in einer URL, und Zeichen wie @ : / # ? müssten dort sonst kodiert werden.

    5. docker-compose.yml

    yaml

    services:
      vaultwarden:
        image: vaultwarden/server:latest
        container_name: bitwarden_web
        restart: always
        depends_on:
          - dbvault8
        environment:
          DOMAIN: "https://bitwarden.domain.com"
          ADMIN_TOKEN: ${ADMIN_TOKEN}
          DATABASE_URL: "mysql://${DB_USER}:${DB_PASSWORD}@172.16.0.53:3306/${DB_NAME}"
          TZ: "Europe/Vienna"
          LOG_LEVEL: "info"
          SIGNUPS_ALLOWED: "false"
          SIGNUPS_VERIFY: "true"
          INVITATIONS_ALLOWED: "false"
          SHOW_PASSWORD_HINT: "false"
          WEB_VAULT_ENABLED: "true"
          SMTP_HOST: "mail.your-server.de"
          SMTP_PORT: "587"
          SMTP_SECURITY: "starttls"
          SMTP_FROM: "[email protected]"
          SMTP_FROM_NAME: "Bitwarden"
          SMTP_USERNAME: "[email protected]"
          SMTP_PASSWORD: ${SMTP_PASSWORD}
        volumes:
          - ./data:/data
        networks:
          docknet:
            ipv4_address: 172.16.0.3
    
      dbvault8:
        image: mysql:8.4
        container_name: bitwarden_db_8
        restart: always
        environment:
          MYSQL_DATABASE: ${DB_NAME}
          MYSQL_USER: ${DB_USER}
          MYSQL_PASSWORD: ${DB_PASSWORD}
          MYSQL_ROOT_PASSWORD: ${DB_ROOT_PASSWORD}
        volumes:
          - ./db-data_8:/var/lib/mysql
        networks:
          docknet:
            ipv4_address: 172.16.0.53
    
    networks:
      docknet:
        external: true

    6. Starten und Logs prüfen

    bash

    docker compose config        # zeigt, ob die Variablen korrekt eingesetzt werden
    docker compose up -d
    docker compose logs -f vaultwarden

    Beim ersten Start kann Vaultwarden ein paar Mal melden, dass die Datenbank nicht erreichbar ist, solange MySQL noch initialisiert. Das ist normal, weil es automatisch neu versucht. Fertig ist es, wenn Rocket has launched im Log steht.

    7. Reverse Proxy (Nginx Proxy Manager)

    Lege einen neuen Proxy Host an:

    • Domain: bitwarden.domain.com
    • Scheme / Forward IP / Port: http · 172.16.0.3 · 80
    • Websockets Support: an (wird für die Live-Synchronisation gebraucht)
    • Block Common Exploits: an
    • SSL-Tab: Let’s-Encrypt-Zertifikat, Force SSL, HTTP/2 und HSTS aktivieren

    Ports musst du am Container keine freigeben, weil NPM ihn direkt über docknet erreicht.

    8. Ersten Benutzer anlegen

    Da die Registrierung gesperrt ist, hast du zwei Möglichkeiten:

    • Über das Admin-Panel: Öffne https://bitwarden.domain.com/admin, melde dich mit dem Passwort aus Schritt 3 an und lade dich unter Users → Invite User selbst ein. Dafür muss SMTP funktionieren.
    • Ohne SMTP: Setze kurzzeitig SIGNUPS_ALLOWED: "true" und starte mit docker compose up -d neu. Dann registrierst du dich, stellst den Wert wieder auf "false" und startest erneut.

    9. SMTP testen

    Im Admin-Panel findest du unter SMTP Email Settings den Punkt Send test email.

    ⚠️ Wichtig: Was du im Admin-Panel speicherst, landet in data/config.json und überschreibt von da an die Werte aus der Compose-Datei. Wenn eine Änderung an der Compose-Datei scheinbar nichts bewirkt, liegt es fast immer daran.

    10. Backup

    bash

    # Datenbank sichern
    docker exec bitwarden_db_8 sh -c 'mysqldump -u root -p"$MYSQL_ROOT_PASSWORD" vaultdb' > vaultdb_$(date +%F).sql
    
    # data-Ordner sichern (Anhänge, Sends, RSA-Schlüssel, config.json)
    tar czf vw-data_$(date +%F).tar.gz data/

    Die Dateien data/rsa_key* gehören unbedingt ins Backup. Fehlen sie, sind nach einer Wiederherstellung alle Sitzungen ungültig.

    11. Updates

    bash

    docker compose pull && docker compose up -d && docker image prune -f

    Was ich an deiner Vorlage geändert habe

    OriginalProblemLösungports: ":80", ":443"Damit werden zufällige Host-Ports veröffentlicht. Vaultwarden selbst spricht außerdem nur HTTP auf Port 80.Ports entfernt, NPM regelt den Zugriff über docknetADMIN_TOKEN=""In der Listen-Schreibweise werden Anführungszeichen Teil des Werts. Der Token ist dann buchstäblich "" und das Admin-Panel ist mit "" offen.Argon2-Hash aus der .envSMTP_FROM_NAME="bitwarden"Gleiches Problem: Die Anführungszeichen landen im Absendernamen.Map-Schreibweise verwendetDOMAIN=[https://…](…)Das ist durch Kopieren als Markdown-Link kaputtgegangen.https://bitwarden.domain.comWEBSOCKET_ENABLEDSeit Version 1.29 veraltet, Websockets laufen jetzt direkt über Port 80.entferntPUID / PGIDDiese Variablen nutzen nur Images von linuxserver.io, Vaultwarden ignoriert sie.entfernt (bei Bedarf stattdessen user: "1000:1000")kein depends_onVaultwarden kann vor der Datenbank starten.depends_on ergänztmysql:8Ein schwammiger Tag, der sich bei einem pull unbemerkt ändern kann.auf mysql:8.4 (LTS) festgelegtPasswörter in der YAML-DateiSie landen leicht in Backups oder Git.in die .env ausgelagert

    Admin-Token für Vaultwarden erstellen

    Vaultwarden erwartet als ADMIN_TOKEN keinen Klartext, sondern einen Argon2-Hash deines Admin-Passworts. Beim Anmelden unter /admin tippst du das Passwort ein, und Vaultwarden vergleicht es mit dem Hash.

    Schritt 1: Hash erzeugen

    Variante A: Container läuft noch nicht

    bash

    docker run --rm -it vaultwarden/server:latest /vaultwarden hash

    Variante B: Container läuft bereits

    bash

    docker exec -it bitwarden_web /vaultwarden hash

    Du wirst zweimal nach dem Passwort gefragt:

    Password:
    Confirm Password:
    
    ADMIN_TOKEN='$argon2id$v=19$m=65540,t=3,p=4$Zk9xT2...$q8Hk3...'
    
    Generation of the Argon2id PHC string took: 512ms

    Kopiere die komplette Zeile mit ADMIN_TOKEN='…'.

    Standardmäßig nutzt der Befehl die Bitwarden-Voreinstellung. Mit /vaultwarden hash --preset owasp bekommst du die etwas strengeren OWASP-Parameter. Beides ist sicher.

    Schritt 2: Hash eintragen, auf die $-Zeichen achten

    Im Hash stehen mehrere $-Zeichen. Docker Compose hält sie für Variablen und würde den Hash kaputt machen. Je nachdem, wo du ihn einträgst, gehst du anders vor:

    In der .env (empfohlen): Übernimm die Zeile genau so, wie sie ausgegeben wurde, mit einfachen Anführungszeichen:

    env

    ADMIN_TOKEN='$argon2id$v=19$m=65540,t=3,p=4$Zk9xT2...$q8Hk3...'

    In der docker-compose.yml steht dann:

    yaml

          ADMIN_TOKEN: ${ADMIN_TOKEN}

    Direkt in der docker-compose.yml: Hier musst du jedes $ verdoppeln:

    yaml

          ADMIN_TOKEN: "$$argon2id$$v=19$$m=65540,t=3,p=4$$Zk9xT2...$$q8Hk3..."

    Schritt 3: Prüfen und neu starten

    bash

    docker compose config | grep ADMIN_TOKEN   # der Hash muss vollständig mit allen $ erscheinen
    docker compose up -d
    docker compose logs vaultwarden | grep -i admin

    Erscheint im Log keine Warnung wie You are using a plain text ADMIN_TOKEN, hat es geklappt. Dann meldest du dich unter https://bitwarden.domain.com/admin mit dem Passwort an, nicht mit dem Hash.

    Typische Stolperfallen

    • Login klappt nicht, obwohl der Hash stimmt: Wurde im Admin-Panel schon einmal gespeichert, steht in data/config.json ein eigener admin_token. Der hat Vorrang vor der Compose-Datei. Ändere ihn entweder im Admin-Panel unter General Settings → Admin token oder entferne die Zeile aus config.json und starte den Container neu.
    • Hash wirkt abgeschnitten: Die $-Zeichen wurden nicht maskiert (siehe Schritt 2). docker compose config zeigt dir das sofort.
    • Admin-Panel abschalten: Lässt du ADMIN_TOKEN ganz weg, ist /admin deaktiviert. Das ist sinnvoll, wenn alles eingerichtet ist und du das Panel nicht mehr brauchst.
    PDF | Print | eMail #bitwarden #docker #linux #safety #vaultwarden
  14. Our meetup continues and right now we have Emmanuel Gonzalez Carmona presenting his talk: "Agentic AppSec for the AI Era".

    Watch the livestream 📺 here:

    👇
    youtube.com/live/qhzDJwh_VJ0?s

  15. Our October meetup continues and right now we have Bhavin Bhatt live on stage presenting his talk: "Judgement Day Is Now: Machine Speed Defence in the age of AI-based attacks".
    Watch the livestream 📺 here:
    👇
    youtube.com/live/qhzDJwh_VJ0?s

  16. Our meetup has started and we currently have @HannahFoxwell on stage speaking about Platform as a Product - What Happens When We Treat Security As a User?
    Watch the 📺 livestream here:
    👇

    youtube.com/live/qhzDJwh_VJ0

  17. Check out this free video to give you a taster of what you can expect from Dawid Czagan's full-stack pentesting laboratory training in San Francisco this November🎉

    📺 HTTP Parameter Pollution - Video Tutorial

    youtube.com/watch?v=09ZJPcw_smE

Share on Mastodon

Enter the server where you have an account.