home.social

#owasptop10 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #owasptop10, aggregated by home.social.

fetched live
  1. حقن الكيانات الخارجية في XML ‏(XXE)  

    1. الهدف من الثغرةقراءة ملفات محلية حساسة، أو تنفيذ طلبات من الخادم (SSRF)، أو فحص خدمات داخلية، أو استنزاف موارد الخادم.2. السببمعالجة XML غير موثوق مع تمكين DTD أو الكيانات الخارجية أو XInclude، وبإعدادات محلل غير آمنة.3. المعالجةتعطيل DTD والكيانات الخارجية وتحميل DTD الخارجي وXInclude، […]

    cybercases8.wordpress.com/2026

  2. حقن أوامرSQL (SQL Injection)

    1. الهدف من الثغرةقراءة بيانات قاعدة البيانات أو تعديلها أو حذفها، وقد يُستخدم لتجاوز تسجيل الدخول أو تنفيذ وظائف غير مصرح بها.2. السببدمج مدخلات المستخدم مباشرة داخل استعلام SQL ديناميكي دون فصل البيانات عن بنية الاستعلام أو دون استخدام معاملات آمنة.3. المعالجةاستخدام […]

    cybercases8.wordpress.com/2026

  3. Security Misconfiguration(سوء الإعدادات الأمنية)

    الهدف من الثغرة:استغلال إعدادات افتراضية أو خاطئة في الخوادم، قواعد البيانات، أو الأطر البرمجية للوصول غير المصرح به.السبب:ترك إعدادات افتراضية (مثل كلمات مرور admin الافتراضية)، رسائل أخطاء تكشف تفاصيل النظام، أو خدمات غير ضرورية مفعّلة.طريقة المعالجة:تعطيل الخصائص […]

    cybercases8.wordpress.com/2026

  4. Cryptographic Failures(إخفاقات التشفير)

    الهدف من الثغرة:كشف بيانات حساسة (كلمات مرور، أرقام بطاقات، بيانات شخصية) بسبب ضعف أو غياب التشفير.السبب:استخدام خوارزميات تشفير قديمة أو ضعيفة (مثل MD5 أو SHA1 لكلمات المرور)، أو نقل البيانات دون HTTPS، أو تخزينها كنص صريح.طريقة المعالج:تشفير البيانات الحساسة أثناء النقل (TLS) […]

    cybercases8.wordpress.com/2026

  5. Broken AccessControl_كسر التحكم بالوصوال

    الهدف من الثغرة:تمكين المهاجم من الوصول إلى موارد أو وظائف لا يُفترض أن يصل إليها، مثل حسابات مستخدمين آخرين، لوحات تحكم الإدارة، أو بيانات حساسة. السبب:عدم تطبيق صلاحيات المستخدمين بشكل صحيح على مستوى الخادم؛ الاعتماد فقط على إخفاء الروابط أو الأزرار في الواجهة دون […]

    cybercases8.wordpress.com/2026

  6. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  7. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  8. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  9. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  10. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  11. 📢 November OWASP Ottawa Meetup Alert📢

    Join us for an in-person #OWASPOttawa meetup next week at the University of Ottawa!

    We’ve got two fantastic speakers (Tanya Janca and Gabriel Kronfeld) lined up to dive deep into #DevSecOps and #OWASPTop10.

    Gabriel Kronfeld presents "A Brief overview of the OWASP Top 10"

    Tanya Janca presents "DevSecOps Worst Practices"

    RSVP link: meetup.com/owasp-ottawa/events

    #OWASP #ottawa #cybersecurity #networking

  12. 👉 #APIattacks have grown in triple digits in the last two years.

    After all, 71% of the internet traffic comes from APIs so APIs have become soft targets for hackers.

    Securing APIs is a simple workflow provided you find API specific vulnerabilities and protect them.

    In the upcoming webinar, join Vivek Gopalan, VP of Products at Indusface as he takes you through the fundamentals of API vulnerability scanning.

    Vivek will discuss how to :

    - Scan API endpoints for OWASP API Top 10 vulnerabilities
    - Perform API penetration testing for business logic vulnerabilities
    - Prioritize the most critical vulnerabilities with AcuRisQ
    - Workflow automation for this entire process

    Register now and start protecting your APIs today! bit.ly/3z7IPHf

    #vulnerabilityscanning #hacking #apiscanning #cybersecurity #vulnerabilities #owaspapi #owasptop10 #pentesting #apiendpoints #apisecurity #apptrana #indusface

  13. 👉 Join Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface, in a live #API attack simulation. 🔓

    In this session, they will cover:
    - An exploit of #OWASP API Top 10 vulnerability
    - A brute force #ATO (Account Takeover) attack on an API
    - A #DDoS attack on an API
    - Positive security model automation to prevent #APIattacks

    Don't miss out – register now! bit.ly/3WODUV8

    #authentication #authorization #apisecurity #hacking #owasptop10 #ddosattacks #apigateway #bruteforceattacks #cybersecurity #apptrana

  14. It is 2024 and here we have yet another critical SQL Injection (#SQLi) vulnerability in a commercial product by a *CyberSecurity* vendor - F5! (PaloAlto vuln was a couple of weeks ago)

    #OWASPTop10

    my.f5.com/manage/s/article/K00

  15. 👉 “We have an #API gateway, and the strong authentication & authorization keeps us secure.”

    This notion could cost you a #databreach, a compliance fine or even application downtime that may erode customer trust.

    In the upcoming webinar, Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface demonstrate how #APIs could be hacked.

    They'll cover:

    1. An exploit of #owaspapitop10 vulnerability
    2. A brute force account take-over (ATO) attack on API
    3. A #DDoS attack on an API
    4. How a #WAAP could bolster security over an API gateway

    📌 Save your seat now! bit.ly/3Mw4Inp

    #apiattacks #authentication #authorization #apisecurity #hacking #owasptop10 #ddosattacks #apigateway #bruteforceattacks #ATO #apptrana #indusface

  16. 🚀 🔍 #APIsecurity landscape is constantly changing, and keeping up is important.

    The trusted resource for API security, the #OWASP #API Top 10, has been updated for 2023.

    Get the latest insights and recommendations to protect your #APIs. See what's new compared to 2019: bit.ly/48z6WeV

    #owaspapi #owasptop10 #apiprotection #apivulnerabilities #ddosattacks #riskprotection #appsec #apptrana #indusface

  17. #Workshop erfolgreich abgeschlossen 🙌🥳

    Wieder 10 Leute beim "Hack It: Sichere Webanwendungen" bespaßt. ☺️

    #OWASPTop10 #JuiceShop

  18. OWASP Top 10 for Large Language Model Applications

    "The OWASP Top 10 for Large Language Model Applications project aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs)."

    owasp.org/www-project-top-10-f

    Review the draft Top 10 list version 0.1: owasp.org/www-project-top-10-f

    1) Prompt Injections

    2) Data Leakage

    3) Inadequate Sandboxing

    4) Unauthorized Code Execution

    5) SSRF Vulnerabilities

    6) Overreliance on LLM-generated Content

    7) Inadequate AI Alignment

    8) Insufficient Access Controls

    9) Improper Error Handling

    10) Training Data Poisoning

    The initiative is community-driven, collaborate :)

    #security #ai #data #llm #largelanguagemodel #artificialintelligence #owasp #training #OpenWorldwideApplicationSecurityProject #cybersecurity #community #owasptop10 #noprofit