home.social

#owasptop10 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #owasptop10, aggregated by home.social.

fetched live
  1. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  2. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  3. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  4. An #IDOR Vulnerability in the Vatican's 'Click to Pray' Mobile App Leaks Names, Emails, and Administrative Privileges Across the Globe:
    #OWASPTop10

    techstory.in/sacred-intentions

  5. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  6. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  7. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  8. Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026

    Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […]

    insicurezzadigitale.com/come-u

  9. Data breaches don’t start with zero-days—they start with missed basics. @mezoCode walks through the #OWASP API Security Top 10—each one with bad & good #Java code examples.

    Read the best practices: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASPTop10 @owasp @OWASPTop10 #JAVAPRO #API

  10. Data breaches don’t start with zero-days—they start with missed basics. @mezoCode walks through the #OWASP API Security Top 10—each one with bad & good #Java code examples.

    Read the best practices: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASPTop10 @owasp @OWASPTop10 #JAVAPRO #API

  11. OpenAI wprowadza Lockdown Mode – nowa strategia ochrony danych AI

    Czy wystarczy zaciągnąć hamulec ręczny, żeby AI przestało robić głupoty? OpenAI twierdzi, że tak – przynajmniej wtedy, gdy stawką są wrażliwe dane.

    Czytaj dalej:
    pressmind.org/openai-wprowadza

    #PressMindLabs #chatgptenterprise #elevatedrisk #lockdownmode #ochronadanych #owasptop10

  12. 💡 Tip: Antes de desplegar tu aplicación, revisa las 10 vulnerabilidades del OWASP Top 10. Prevenir es mucho más barato que reparar después de un ataque.

    #OWASPTop10 #SeguridadWeb #DesarrolloSeguro #Ciberseguridad #IngenieríaDeSoftware

  13. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  14. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  15. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  16. 🎉 OWASP London Training Days just got better! Join Fabio Cerullo for 3 days of Web App Security Essentials 🔥 Learn to identify, exploit, and fix critical vulnerabilities in hands-on labs, fully aligned with the OWASP Top 10 (2025)👉 londonowasptrainingdays2025.sc
    #webapplications #appsec #owasptop10

  17. Broken object-level auth, SSRF, missing rate limits — Java APIs fail in predictable ways. This step-by-step guide by @mezoCode maps each #OWASP #API flaw to a working #Java solution.

    Essential read for secure backends: javapro.io/2025/11/12/masterin

    @owasp #OWASPTop10 #APIsecurity

  18. Broken object-level auth, SSRF, missing rate limits — Java APIs fail in predictable ways. This step-by-step guide by @mezoCode maps each #OWASP #API flaw to a working #Java solution.

    Essential read for secure backends: javapro.io/2025/11/12/masterin

    @owasp #OWASPTop10 #APIsecurity

  19. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  20. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  21. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  22. There's a release candidate up for review via community survey of the OWASP Top 10 2025 edition. The previous edition was 2021. This lists current top network application security issues that developers should pay attention to. For 2025, Server-Side Request Forgery SSRF was merged into Broken Access Controls; added Mishandling of Exceptional Conditions based on Common Weakness Enumeration CWE trends. owasp.org/Top10/2025/0x00_2025 #OWASPTop10 #cybersecurity #Internet #web #software #engineering #tech

  23. $4.45M. That’s the average cost of a breach. Most start with #API vulnerabilities. This guide by @mezoCode shows how to write secure #Java APIs with working #OWASPTop10 code fixes.

    Prevent costly mistakes - read: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASP @owasp @OWASPTop10

  24. $4.45M. That’s the average cost of a breach. Most start with #API vulnerabilities. This guide by @mezoCode shows how to write secure #Java APIs with working #OWASPTop10 code fixes.

    Prevent costly mistakes - read: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASP @owasp @OWASPTop10

  25. Still exposing sensitive data via #Java #APIs? @mezoCode breaks down real-world #OWASP API security flaws—from broken auth to SSRF—and how to fix them in clean, tested code.

    Actionable code for every risk: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASPTop10 @owasp @OWASPTop10

  26. Still exposing sensitive data via #Java #APIs? @mezoCode breaks down real-world #OWASP API security flaws—from broken auth to SSRF—and how to fix them in clean, tested code.

    Actionable code for every risk: javapro.io/2025/11/12/masterin

    #SpringBoot #OWASPTop10 @owasp @OWASPTop10

  27. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  28. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  29. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  30. @owasp_de

    Unterstützt das und leitet das weiter!

    Es ist wahrscheinlicher, dass Euch ein Bug aus den #OWASPTop10 raushaut, als eine #AI oder ein #quantumcomputer

    Zahllose Beispiele ...

  31. 📢 November OWASP Ottawa Meetup Alert📢

    Join us for an in-person #OWASPOttawa meetup next week at the University of Ottawa!

    We’ve got two fantastic speakers (Tanya Janca and Gabriel Kronfeld) lined up to dive deep into #DevSecOps and #OWASPTop10.

    Gabriel Kronfeld presents "A Brief overview of the OWASP Top 10"

    Tanya Janca presents "DevSecOps Worst Practices"

    RSVP link: meetup.com/owasp-ottawa/events

    #OWASP #ottawa #cybersecurity #networking

  32. 📢 November OWASP Ottawa Meetup Alert📢

    Join us for an in-person #OWASPOttawa meetup next week at the University of Ottawa!

    We’ve got two fantastic speakers (Tanya Janca and Gabriel Kronfeld) lined up to dive deep into #DevSecOps and #OWASPTop10.

    Gabriel Kronfeld presents "A Brief overview of the OWASP Top 10"

    Tanya Janca presents "DevSecOps Worst Practices"

    RSVP link: meetup.com/owasp-ottawa/events

    #OWASP #ottawa #cybersecurity #networking

  33. 📢 November OWASP Ottawa Meetup Alert📢

    Join us for an in-person #OWASPOttawa meetup next week at the University of Ottawa!

    We’ve got two fantastic speakers (Tanya Janca and Gabriel Kronfeld) lined up to dive deep into #DevSecOps and #OWASPTop10.

    Gabriel Kronfeld presents "A Brief overview of the OWASP Top 10"

    Tanya Janca presents "DevSecOps Worst Practices"

    RSVP link: meetup.com/owasp-ottawa/events

    #OWASP #ottawa #cybersecurity #networking

  34. 📢 November OWASP Ottawa Meetup Alert📢

    Join us for an in-person #OWASPOttawa meetup next week at the University of Ottawa!

    We’ve got two fantastic speakers (Tanya Janca and Gabriel Kronfeld) lined up to dive deep into #DevSecOps and #OWASPTop10.

    Gabriel Kronfeld presents "A Brief overview of the OWASP Top 10"

    Tanya Janca presents "DevSecOps Worst Practices"

    RSVP link: meetup.com/owasp-ottawa/events

    #OWASP #ottawa #cybersecurity #networking

  35. 👉 #APIattacks have grown in triple digits in the last two years.

    After all, 71% of the internet traffic comes from APIs so APIs have become soft targets for hackers.

    Securing APIs is a simple workflow provided you find API specific vulnerabilities and protect them.

    In the upcoming webinar, join Vivek Gopalan, VP of Products at Indusface as he takes you through the fundamentals of API vulnerability scanning.

    Vivek will discuss how to :

    - Scan API endpoints for OWASP API Top 10 vulnerabilities
    - Perform API penetration testing for business logic vulnerabilities
    - Prioritize the most critical vulnerabilities with AcuRisQ
    - Workflow automation for this entire process

    Register now and start protecting your APIs today! bit.ly/3z7IPHf

    #vulnerabilityscanning #hacking #apiscanning #cybersecurity #vulnerabilities #owaspapi #owasptop10 #pentesting #apiendpoints #apisecurity #apptrana #indusface

  36. 👉 #APIattacks have grown in triple digits in the last two years.

    After all, 71% of the internet traffic comes from APIs so APIs have become soft targets for hackers.

    Securing APIs is a simple workflow provided you find API specific vulnerabilities and protect them.

    In the upcoming webinar, join Vivek Gopalan, VP of Products at Indusface as he takes you through the fundamentals of API vulnerability scanning.

    Vivek will discuss how to :

    - Scan API endpoints for OWASP API Top 10 vulnerabilities
    - Perform API penetration testing for business logic vulnerabilities
    - Prioritize the most critical vulnerabilities with AcuRisQ
    - Workflow automation for this entire process

    Register now and start protecting your APIs today! bit.ly/3z7IPHf

    #vulnerabilityscanning #hacking #apiscanning #cybersecurity #vulnerabilities #owaspapi #owasptop10 #pentesting #apiendpoints #apisecurity #apptrana #indusface

  37. 👉 Join Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface, in a live #API attack simulation. 🔓

    In this session, they will cover:
    - An exploit of #OWASP API Top 10 vulnerability
    - A brute force #ATO (Account Takeover) attack on an API
    - A #DDoS attack on an API
    - Positive security model automation to prevent #APIattacks

    Don't miss out – register now! bit.ly/3WODUV8

    #authentication #authorization #apisecurity #hacking #owasptop10 #ddosattacks #apigateway #bruteforceattacks #cybersecurity #apptrana

  38. 👉 Join Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface, in a live #API attack simulation. 🔓

    In this session, they will cover:
    - An exploit of #OWASP API Top 10 vulnerability
    - A brute force #ATO (Account Takeover) attack on an API
    - A #DDoS attack on an API
    - Positive security model automation to prevent #APIattacks

    Don't miss out – register now! bit.ly/3WODUV8

    #authentication #authorization #apisecurity #hacking #owasptop10 #ddosattacks #apigateway #bruteforceattacks #cybersecurity #apptrana

  39. It is 2024 and here we have yet another critical SQL Injection (#SQLi) vulnerability in a commercial product by a *CyberSecurity* vendor - F5! (PaloAlto vuln was a couple of weeks ago)

    #OWASPTop10

    my.f5.com/manage/s/article/K00

  40. It is 2024 and here we have yet another critical SQL Injection (#SQLi) vulnerability in a commercial product by a *CyberSecurity* vendor - F5! (PaloAlto vuln was a couple of weeks ago)

    #OWASPTop10

    my.f5.com/manage/s/article/K00

  41. It is 2024 and here we have yet another critical SQL Injection (#SQLi) vulnerability in a commercial product by a *CyberSecurity* vendor - F5! (PaloAlto vuln was a couple of weeks ago)

    #OWASPTop10

    my.f5.com/manage/s/article/K00

  42. It is 2024 and here we have yet another critical SQL Injection (#SQLi) vulnerability in a commercial product by a *CyberSecurity* vendor - F5! (PaloAlto vuln was a couple of weeks ago)

    #OWASPTop10

    my.f5.com/manage/s/article/K00

  43. 🔒 Elevate Your Web Application Security Game! 🔒

    Are you taking the necessary steps to safeguard your web applications against cyber threats? Dive into our latest insights on the OWASP Top 10 vulnerabilities and discover actionable strategies to fortify your defenses.

    relianoid.com/blog/relianoid-o