home.social

#applicationsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #applicationsecurity, aggregated by home.social.

fetched live
  1. 🔐 RELIANOID is heading to Tokyo!

    We'll be following the conversations at Gartner Security & Risk Management Summit Tokyo 2026, July 22–24.

    Zero Trust, cloud security, AI risk, cyber resilience, and secure application delivery are shaping the future of digital infrastructure.

    📍 Tokyo, Japan

    relianoid.com/about-us/events/

  2. Thanks to Xbow, a Platinum Sponsor of AppSecVillage. XBOW focuses on continuous app/API testing and proof of exploitability, helping teams cut through noise and understand real risk.

    🔗 buff.ly/5R1Q1Gm

    #AppSec #ApplicationSecurity

  3. Thanks to Xbow, a Platinum Sponsor of AppSecVillage. XBOW focuses on continuous app/API testing and proof of exploitability, helping teams cut through noise and understand real risk.

    🔗 buff.ly/5R1Q1Gm

    #AppSec #ApplicationSecurity

  4. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  5. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  6. 🚨 New Vulnerability Analysis: CVE-2026-47670 🚨

    In my latest technical deep dive, I break down a critical authenticated Remote Code Execution (RCE) vulnerability in DbGate (v7.1.8). Discover why relying on pseudo-sandboxing like require = null fails inherently inside Node.js environments when confronted with native, unblockable dynamic import() constructs.

    👉 denizhalil.com/2026/06/15/cve-

    #Cybersecurity #Infosec #NodeJS #VulnerabilityResearch #ApplicationSecurity #RCE

  7. CISOs Face Pressure to Deploy Vulnerable Code

    The harsh reality is that 95% of CISOs face pressure to downplay or delay reporting security issues, leading to a staggering 75% of organizations deploying vulnerable code into production environments. It's a precarious situation that demands a new approach to prioritize security without sacrificing business goals.

    osintsights.com/cisos-face-pre

    #ApplicationSecurity #VulnerableCode #Cisos #BusinessPressure #SecureDeployment

  8. AI Coding Tools Require Embedded Security to Counter Emerging Risks

    Security can't keep pace with AI coding tools unless it's embedded from the start - after all, with hundreds of daily code changes, it can't be a bolt-on activity that happens after the fact. It needs to be a fundamental part of the creation process itself.

    osintsights.com/ai-coding-tool

    #AiCodingTools #ApplicationSecurity #EmergingThreats #Devsecops #ArtificialIntelligence

  9. Fake Claude Code installer campaigns are abusing trusted developer workflows instead of exploiting software vulnerabilities.
    Rhys Downing of Ontinue explains how attackers used fake documentation pages, modified install commands, PowerShell loaders, and browser compromise techniques to steal credentials and establish persistence.

    “Developers are becoming a preferred target because they sit at the intersection of trust and access.”

    Read more:
    technadu.com/copy-paste-compro

    #Cybersecurity #ThreatResearch #Developers #ApplicationSecurity #Ontinue #SecureCoding

  10. 🔐 𝗥𝗘𝗟𝗜𝗔𝗡𝗢𝗜𝗗 will be attending 𝗜𝗻𝗳𝗼𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗘𝘂𝗿𝗼𝗽𝗲 𝟮𝟬𝟮𝟲 in London from June 2–4!

    As one of 𝘌𝘶𝘳𝘰𝘱𝘦’𝘴 𝘭𝘦𝘢𝘥𝘪𝘯𝘨 𝘤𝘺𝘣𝘦𝘳𝘴𝘦𝘤𝘶𝘳𝘪𝘵𝘺 𝘦𝘷𝘦𝘯𝘵𝘴, Infosecurity Europe brings together security professionals, innovators, and decision-makers to explore the future of cyber resilience, cloud security, AI-driven protection, Zero Trust, and more.

    relianoid.com/about-us/events/

  11. Vulnerable Code Proliferates as AI Exploits Rise in Supply Chains

    The alarming truth is that 75% of organizations are knowingly shipping vulnerable code, despite the risks, with the window from disclosure to exploit shrinking dramatically from 840 days in 2018 to just under two days today. This trend is expected to accelerate, with exploits potentially available in as little as one minute by 2028.

    osintsights.com/vulnerable-cod

    #VulnerableCode #AiExploits #SupplyChain #ApplicationSecurity #ZeroDay

  12. Agentic AI Turbo Boosts Mobile App Attacks

    The alarming rise of mobile app attacks is no longer looming on the horizon - it's here, with a staggering 87% of monitored apps facing threats in 2026, a drastic jump from 55% in 2022, fueled by the rapid adoption of AI models. This explosive growth in attacks is a wake-up call for businesses to bolster their mobile app security.

    osintsights.com/agentic-ai-tur

    #AgenticAi #MobileAppAttacks #EmergingThreats #ApplicationSecurity #ArtificialIntelligence

  13. Socket Expands Supply-Chain Visibility with Secure Annex Acquisition

    Socket is supercharging its supply-chain visibility with the acquisition of Secure Annex, a cutting-edge extension security startup, to give developers unprecedented control across the entire software development life cycle. This strategic move combines Socket's expertise in application dependencies with Secure Annex's…

    osintsights.com/socket-expands

    #SupplyChain #ApplicationSecurity #SoftwareDevelopment #Acquisition #SecureAnnex

  14. GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions

    Researchers at Socket have uncovered a sneaky new wave of GlassWorm malware, this time hiding in 73 OpenVSX extensions that behave like sleepers - seemingly harmless at first, but turning malicious after a stealthy update. Six of these extensions have already been activated, unleashing malware on unsuspecting developers.

    osintsights.com/glassworm-malw

    #GlasswormMalware #Openvsx #MalwareOperations #EmergingThreats #ApplicationSecurity

  15. Anthropic's Claude Desktop sparks EU consent concerns

    Can a single app really reach into your other software without asking for permission? The surprising behavior of Anthropic's Claude Desktop for macOS is raising eyebrows and sparking concerns about consent under EU law.

    osintsights.com/anthropics-cla

    #EuConsent #Macos #ApplicationSecurity #EmergingThreats #Gdpr

  16. Together, these measures enhance your security posture by protecting against unauthorized access and potential vulnerabilities.

    Read more 👉 lttr.ai/AqIiJ

    #Security #Infosec #ApplicationSecurity

  17. ZAST engine has identified and verified CVE-2026-1829 in Content Visibility for Divi Builder 4.01, along with one additional verified vulnerability in the same plugin.

    Project page: wordpress.org/plugins/content- Project footprint: 2,000+ active installations on WordPress.org.

    The critical issue is a code-execution path where user-controlled visibility expressions reach eval() through multiple application features. This is a representative example of why security teams need autonomous verification: dangerous APIs alone do not define risk. Reachability, privilege boundaries, and runtime behavior do.

    ZAST.AI promotes findings into reports only after successful PoC validation, which supports a zero-false-positive operating model and helps enterprise teams prioritize remediation on verified issues.

    Full report: blog.zast.ai/vulnerability%20r

    @wordfence @[email protected] @[email protected]

    #ApplicationSecurity #WordPressSecurity #AppSec #VulnerabilityResearch #AIForSecurity

  18. ZAST engine has identified and verified CVE-2026-1829 in Content Visibility for Divi Builder 4.01, along with one additional verified vulnerability in the same plugin.

    Project page: wordpress.org/plugins/content- Project footprint: 2,000+ active installations on WordPress.org.

    The critical issue is a code-execution path where user-controlled visibility expressions reach eval() through multiple application features. This is a representative example of why security teams need autonomous verification: dangerous APIs alone do not define risk. Reachability, privilege boundaries, and runtime behavior do.

    ZAST.AI promotes findings into reports only after successful PoC validation, which supports a zero-false-positive operating model and helps enterprise teams prioritize remediation on verified issues.

    Full report: blog.zast.ai/vulnerability%20r

    @wordfence @[email protected] @[email protected]

    #ApplicationSecurity #WordPressSecurity #AppSec #VulnerabilityResearch #AIForSecurity

  19. In tomorrow's OWASP 25th Anniversary Virtual Conference, two talks include mention of the OWASP Cornucopia card game.

    In "Stop Lecturing, Start Playing" at 11:00 CET Johan Sydseter will discuss how you can utilize games to scale your application security program. And in "Connecting the dots" at 14:00 Max Alejandro Gómez Sánchez Vergaray will share his experiences of creating an AppSec programme.

    #appsec #threatmodelling #software #applicationsecurity #owasp @sydseter

    owasp.glueup.com/event/owasp-2

  20. Attackers don’t need vulnerabilities when they can weaponize your protocols😳

    Recent DDoSia campaigns show how HTTP/2 abuse and slow-request tactics can disrupt systems without...a single exploit.

    For AppSec teams, it’s a reminder: resilience matters as much as code fixes.

    Full article from Dark Reading: darkreading.com/cyberattacks-d

    #appsec #applicationsecurity #cybersecurity #threatintel #infosec

  21. We’re excited to take part in The Elephant In AppSec Conference 2026 🐘🔐

    📅 January 14–15, 2026

    🌐 Virtual Event

    An AppSec event where strong opinions are encouraged, assumptions are challenged, and real-world experience takes center stage.

    Looking forward to engaging in honest conversations and sharing how RELIANOID supports modern Application Security through secure application delivery and resilient architectures.

    See you online!

    relianoid.com/about-us/events/

  22. Check out ˗ˏˋ ⭒ lnkd.in/gE2wUqgc ⭒ ˎˊ˗ to see my intro whilst you listen.

    I'm thus re-naming this work as "CVE Keeper - Security at x+1; rethinking vulnerability management beyond CVSS & scanners". I must also thank @andrewpollock for reviewing several of my verbose drafts. 🫡

    So, Security at x+1; rethinking vulnerability management beyond CVSS & scanners -

    Most vulnerability tooling today is optimized for disclosure and alert volume, not for making correct decisions on real systems. CVEs arrive faster than teams can evaluate them, scores are generic, context arrives late, and we still struggle to answer the only question that matters: does this actually put my system at risk right now?

    Over the last few years working close to CVE lifecycle automation, I’ve been designing an open architecture that treats vulnerability management as a continuous, system-specific reasoning problem rather than a static scoring task. The goal is to assess impact on the same day for 0-days using minimal upstream data, refine accuracy over time as context improves, reason across dependencies and compound vulnerabilities, and couple automation with explicit human verification instead of replacing it.

    This work explores:

    ⤇ 1• Same-day triage of newly disclosed and 0-day vulnerabilities
    ⤇ 2• Dependency-aware and compound vulnerability impact assessment
    ⤇ 3• Correlating classical CVSS with AI-specific threat vectors
    ⤇ 4• Reducing operational noise, unnecessary reboots, and security burnout
    ⤇ 5• Making high-quality vulnerability intelligence accessible beyond enterprise teams

    The core belief is simple: most security failures come from misjudged impact, not missed vulnerabilities. Accuracy, context, and accountability matter more than volume.

    I’m sharing this to invite feedback from folks working in CVE, OSV, vulnerability disclosure, AI security, infra, and systems research. Disagreement and critique are welcome. This problem affects everyone, and I don’t think incremental tooling alone will solve it.

    P.S.

    • Super appreciate everyone that's spent time reviewing my drafts and reading all my essays lol. I owe you 🫶🏻
    • ... and GoogleLM. These slides would have taken me forever to make otherwise.

    Take my CVE-data User Survey to allow me to tailor your needs into my design - lnkd.in/gcyvnZeE
    See more at - lnkd.in/gGWQfBW5
    lnkd.in/gE2wUqgc

    #VulnerabilityManagement #Risk #ThreatModeling #CVE #CyberSecurity #Infosec #VulnerabilityManagement #ThreatIntelligence #ApplicationSecurity #SecurityOperations #ZeroDay #RiskManagement #DevSecOps #CVE #CVEAnalysis #VulnerabilityDisclosure #SecurityData #CVSS #VulnerabilityAssessment #PatchManagement #AI #AIML #AISecurity #MachineLearning #AIThreats #AIinSecurity #SecureAI #OSS #Rust #ZeroTrust #Security

    linkedin.com/feed/update/urn:l

  23. 🎄✨ For those starting their holiday break, take the opportunity to watch this gem from our 2024 archives!

    🎥 "From code to security, Mastering the art of AppSec" by Justin Landry

    Dive into the world of application security with Justin Landry as he guides us from code to security. An essential masterclass for anyone interested in AppSec! 🔐💻

    👉 Watch now: youtube.com/watch?v=V4OO4fu5W2M

    #AppSec #Cybersecurity #ApplicationSecurity #InfoSec

  24. 🎄✨ Pour ceux qui commencent leurs vacances du temps des fêtes, profitez-en pour revoir cette vidéo de nos archives 2024!

    🎥 "From code to security, Mastering the art of AppSec" par Justin Landry
    Plongez dans l'univers de la sécurité applicative avec Justin Landry qui nous guide du code à la sécurité. Une masterclass essentielle pour quiconque s'intéresse à l'AppSec! 🔐💻

    👉 Regardez maintenant : youtube.com/watch?v=V4OO4fu5W2M

    #AppSec #Cybersecurity #ApplicationSecurity #InfoSec #Hacking