Skip Navigation
Snyk prices are getting very high. Has anyone moved away from them? Which alternative did you choose?

Found this interesting list: https://list.latio.tech/

On the open source side, there is https://www.dependencytrack.org/

2
[Crosspost from !appsec] Looking for a new training/certification. People who did OSWA (Web-200 by OffSec), how was it?
  • Oh nice, wasn't aware of this, definitely looks interesting, thanks! I am an OSCP holder as well.

  • [Crosspost from !appsec] Looking for a new training/certification. People who did OSWA (Web-200 by OffSec), how was it?
    www.offsec.com WEB-200: Foundational Web Application Assessments with Kali Linux | OffSec

    Learn the foundations of web application assessments. Exploit common web vulnerabilities, learn how to exfiltrate sensitive data from target web applications, and earn your OffSec Web Assessor (OSWA) certification.

    WEB-200: Foundational Web Application Assessments with Kali Linux | OffSec
    3
    Looking for a new training/certification. People who did OSWA (Web-200 by OffSec), how was it?
    www.offsec.com WEB-200: Foundational Web Application Assessments with Kali Linux | OffSec

    Learn the foundations of web application assessments. Exploit common web vulnerabilities, learn how to exfiltrate sensitive data from target web applications, and earn your OffSec Web Assessor (OSWA) certification.

    WEB-200: Foundational Web Application Assessments with Kali Linux | OffSec
    0
    Recommended AppSec conferences in Europe?

    cross-posted from: https://infosec.pub/post/8123190

    > Hello everyone, > > > I work in appsec, my manager would like to send us to a conference this year. We are based in Europe, and the company would like to across intercontinental travel. > > I have OWASP Global 2024 in Lisbon on my radar, as well as the BlackHat EU in London, is there any other conference you guys would recommend?

    0
    Recommended AppSec conferences in Europe?

    Hello everyone,

    I hope this post belongs here, otherwise I'll move it to !appsec@infosec.pub.

    I work in appsec, my manager would like to send us to a conference this year. We are based in Europe, and the company would like to across intercontinental travel.

    I have OWASP Global 2024 in Lisbon on my radar, as well as the BlackHat EU in London, is there any other conference you guys would recommend?

    0
    [tl;dr sec] #215 - Cloud Threat Landscape, Web LLM Security Labs, Azure Logs Primer
    tldrsec.com [tl;dr sec] #215 - Cloud Threat Landscape, Web LLM Security Labs, Azure Logs Primer

    A database of cloud security incidents, campaigns, and techniques, Portswigger's labs on testing LLMs in web apps, using Azure logs for detection

    [tl;dr sec] #215 - Cloud Threat Landscape, Web LLM Security Labs, Azure Logs Primer
    0
    Signing Requests using RSA Keys
    www.zaproxy.org Signing Requests using RSA Keys

    A new script in the community-scripts repository enables the signing of outgoing requests with RSA keys, addressing the challenge of testing applications that require this functionality.

    Signing Requests using RSA Keys
    0
    Stir Trek 2024: Call for Speakers
  • Why the downvotes? This is a call for speakers to a security conference

  • Stir Trek 2024: Call for Speakers
    sessionize.com Stir Trek 2024: Call for Speakers

    Stir Trek 2024 will take place at the AMC Easton Town Center 30 on Friday, May 3rd. We'll be at the same great location we have been for the past few ...

    Stir Trek 2024: Call for Speakers
    1
    OWASP Foundation - 2024 Global AppSec Lisbon Call for Trainers
    owasp.submittable.com OWASP Foundation - 2024 Global AppSec Lisbon CfT

    INTRODUCTION Application Security leaders, software engineers, and researchers from all over the world gather at Global AppSec conferences to drive visibility and evolution in the safety and security of the world’s software, as well as to network, collaborate, and share the newest innovations in...

    OWASP Foundation - 2024 Global AppSec Lisbon CfT
    0
    [tl;dr sec] #213 - AWS Secure Defaults, Damn Vulnerable LLM Agent, cdk-goat
    tldrsec.com [tl;dr sec] #213 - AWS Secure Defaults, Damn Vulnerable LLM Agent, cdk-goat

    Useful secure defaults + SCPs for your AWS account, a chatbot LLM ReAct agent for prompt injection practice, vulnerable by design AWS Cloud Development Kit infrastructure

    [tl;dr sec] #213  - AWS Secure Defaults, Damn Vulnerable LLM Agent, cdk-goat
    0
    Trustwave Transfers ModSecurity Custodianship to OWASP | OWASP Foundation
    owasp.org Trustwave Transfers ModSecurity Custodianship to OWASP | OWASP Foundation

    Trustwave Transfers ModSecurity Custodianship to OWASP on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.

    Trustwave Transfers ModSecurity Custodianship to OWASP | OWASP Foundation
    0
    Removed
    Black Hat USA 2023 slides
  • Nice resources

  • OWASP Top 10 for LLMs (v1.0)
  • Thank you!

  • Feedback open until 31 of August for CVSS 4.0
  • That's kind of legacy debt at some point. I understand why they still want to move towards evolving the standard

  • New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection
    thehackernews.com New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

    A recently patched flaw in OpenSSH (CVE-2023-38408) could allow remote attackers to run arbitrary commands on vulnerable hosts.

    New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection
    1
    Norway government ministries hit by cyber attack
    www.reuters.com Norway government ministries hit by cyber attack

    Twelve Norwegian government ministries have been hit by a cyber attack, the Norwegian government said on Monday, the latest attack to hit the public sector of Europe's largest gas supplier and NATO's northernmost member.

    Norway government ministries hit by cyber attack

    cross-posted from: https://lemmy.capebreton.social/post/82259

    > OSLO, July 24 (Reuters) - Twelve Norwegian government ministries have been hit by a cyber attack, the Norwegian government said on Monday, the latest attack to hit the public sector of Europe's largest gas supplier and NATO's northernmost member. > > "We identified a weakness in the platform of one of our suppliers. That weakness has now been shut," Erik Hope, head of the government agency in charge of providing services to ministries, told a news conference. > > The attack was identified due to "unusual" traffic on the supplier's platform, Hope said, declining to provide specifics. It was uncovered on July 12 and was being investigated by police. > > "It is too early to say who is back this and what is the extent of the impact (of the attack)," he said.

    0
    Security News @infosec.pub N7x @infosec.pub
    Kevin Mitnick Obituary - Las Vegas, NV
    www.dignitymemorial.com Kevin Mitnick Obituary - Las Vegas, NV

    Celebrate the life of Kevin Mitnick, leave a kind word or memory and get funeral service information care of King David Memorial Chapel & Cemetery.

    Kevin Mitnick Obituary - Las Vegas, NV

    RIP

    0
    Training Tuesday - Discussions for certs, training and learning-at-home
  • Finally done with my 120 CPEs for my CISSP. That was a long ride, happy to be done with it

  • N7x N7x @infosec.pub
    Posts 36
    Comments 10