home.social

#owasptop10 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #owasptop10, aggregated by home.social.

fetched live
  1. حقن الكيانات الخارجية في XML ‏(XXE)  

    1. الهدف من الثغرةقراءة ملفات محلية حساسة، أو تنفيذ طلبات من الخادم (SSRF)، أو فحص خدمات داخلية، أو استنزاف موارد الخادم.2. السببمعالجة XML غير موثوق مع تمكين DTD أو الكيانات الخارجية أو XInclude، وبإعدادات محلل غير آمنة.3. المعالجةتعطيل DTD والكيانات الخارجية وتحميل DTD الخارجي وXInclude، […]

    cybercases8.wordpress.com/2026

  2. حقن أوامرSQL (SQL Injection)

    1. الهدف من الثغرةقراءة بيانات قاعدة البيانات أو تعديلها أو حذفها، وقد يُستخدم لتجاوز تسجيل الدخول أو تنفيذ وظائف غير مصرح بها.2. السببدمج مدخلات المستخدم مباشرة داخل استعلام SQL ديناميكي دون فصل البيانات عن بنية الاستعلام أو دون استخدام معاملات آمنة.3. المعالجةاستخدام […]

    cybercases8.wordpress.com/2026

  3. Security Misconfiguration(سوء الإعدادات الأمنية)

    الهدف من الثغرة:استغلال إعدادات افتراضية أو خاطئة في الخوادم، قواعد البيانات، أو الأطر البرمجية للوصول غير المصرح به.السبب:ترك إعدادات افتراضية (مثل كلمات مرور admin الافتراضية)، رسائل أخطاء تكشف تفاصيل النظام، أو خدمات غير ضرورية مفعّلة.طريقة المعالجة:تعطيل الخصائص […]

    cybercases8.wordpress.com/2026

  4. Cryptographic Failures(إخفاقات التشفير)

    الهدف من الثغرة:كشف بيانات حساسة (كلمات مرور، أرقام بطاقات، بيانات شخصية) بسبب ضعف أو غياب التشفير.السبب:استخدام خوارزميات تشفير قديمة أو ضعيفة (مثل MD5 أو SHA1 لكلمات المرور)، أو نقل البيانات دون HTTPS، أو تخزينها كنص صريح.طريقة المعالج:تشفير البيانات الحساسة أثناء النقل (TLS) […]

    cybercases8.wordpress.com/2026

  5. Broken AccessControl_كسر التحكم بالوصوال

    الهدف من الثغرة:تمكين المهاجم من الوصول إلى موارد أو وظائف لا يُفترض أن يصل إليها، مثل حسابات مستخدمين آخرين، لوحات تحكم الإدارة، أو بيانات حساسة. السبب:عدم تطبيق صلاحيات المستخدمين بشكل صحيح على مستوى الخادم؛ الاعتماد فقط على إخفاء الروابط أو الأزرار في الواجهة دون […]

    cybercases8.wordpress.com/2026

  6. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  7. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  8. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  9. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  10. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  11. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  12. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  13. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  14. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  15. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  16. Data breaches don’t start with zero-days—they start with missed basics. @mezoCode walks through the #OWASP API Security Top 10—each one with bad & good #Java code examples.

    Read the best practices: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASPTop10 @owasp @OWASPTop10 #JAVAPRO #API

  17. Data breaches don’t start with zero-days—they start with missed basics. @mezoCode walks through the #OWASP API Security Top 10—each one with bad & good #Java code examples.

    Read the best practices: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASPTop10 @owasp @OWASPTop10 #JAVAPRO #API

  18. OpenAI wprowadza Lockdown Mode – nowa strategia ochrony danych AI

    Czy wystarczy zaciągnąć hamulec ręczny, żeby AI przestało robić głupoty? OpenAI twierdzi, że tak – przynajmniej wtedy, gdy stawką są wrażliwe dane.

    Czytaj dalej:
    pressmind.org/openai-wprowadza

    #PressMindLabs #chatgptenterprise #elevatedrisk #lockdownmode #ochronadanych #owasptop10

  19. 💡 Tip: Antes de desplegar tu aplicación, revisa las 10 vulnerabilidades del OWASP Top 10. Prevenir es mucho más barato que reparar después de un ataque.

    #OWASPTop10 #SeguridadWeb #DesarrolloSeguro #Ciberseguridad #IngenieríaDeSoftware

  20. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  21. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  22. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  23. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  24. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  25. Broken object-level auth, SSRF, missing rate limits — Java APIs fail in predictable ways. This step-by-step guide by @mezoCode maps each #OWASP #API flaw to a working #Java solution.

    Essential read for secure backends: javapro.io/2025/11/12/masterin

    @owasp #OWASPTop10 #APIsecurity

  26. Broken object-level auth, SSRF, missing rate limits — Java APIs fail in predictable ways. This step-by-step guide by @mezoCode maps each #OWASP #API flaw to a working #Java solution.

    Essential read for secure backends: javapro.io/2025/11/12/masterin

    @owasp #OWASPTop10 #APIsecurity

  27. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  28. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  29. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  30. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  31. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  32. $4.45M. That’s the average cost of a breach. Most start with #API vulnerabilities. This guide by @mezoCode shows how to write secure #Java APIs with working #OWASPTop10 code fixes.

    Prevent costly mistakes - read: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASP @owasp @OWASPTop10

  33. $4.45M. That’s the average cost of a breach. Most start with #API vulnerabilities. This guide by @mezoCode shows how to write secure #Java APIs with working #OWASPTop10 code fixes.

    Prevent costly mistakes - read: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASP @owasp @OWASPTop10

  34. Still exposing sensitive data via #Java #APIs? @mezoCode breaks down real-world #OWASP API security flaws—from broken auth to SSRF—and how to fix them in clean, tested code.

    Actionable code for every risk: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASPTop10 @owasp @OWASPTop10

  35. Still exposing sensitive data via #Java #APIs? @mezoCode breaks down real-world #OWASP API security flaws—from broken auth to SSRF—and how to fix them in clean, tested code.

    Actionable code for every risk: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASPTop10 @owasp @OWASPTop10

  36. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  37. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  38. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  39. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  40. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...