πŸ”’ HIGH: CVE-2026-22729 in VMware Spring AI (1.0.x, 1.1.x) enables JSONPath injection, letting authenticated users bypass access controls and access sensitive docs. Patch or sanitize input! https://radar.offseq.com/threat/cve-2026-22729-vulnerability-in-vmware-spring-ai-96356f4f #OffSeq #SpringAI #CVE202622729 #AppSec
πŸ”‘ Securing your API keys is critical! Always store them securely (e.g., environment variables, secret managers), never hard-code in source code. Rotate keys regularly and limit their scope. Stay vigilant and protect your assets! #infosec #cybersecurity #appsec

Learn How AI can help in AppSec at OWASP BASC.

Tanu Jain will describe how LLMs can be used to deploy security frameworks at scale.

Check out more at www.basconf.org

#owasp #basconf #basc2026 #appsec

Have you heard? πŸ‘‚
Early bird pricing is OPEN for Global AppSec USA, coming to San Francisco this November!

Celebrate 25 years of OWASP and be part of an unforgettable AppSec experience. 🎟️
πŸ‘‰ https://owasp.glueup.com/event/owasp-global-appsec-usa-2026-167174/

#AppSec #OWASP #CyberSecurity #EarlyBird #SanFrancisco

Empower your teams to build with total confidence from the very first line of open source code. πŸ›‘οΈ

ActiveState Curated Catalogs deliver up to 99% reduction in CVEs by providing vetted components rebuilt in our SLSA Level 3 compliant infrastructure. Accelerate your development with a trusted foundation that eliminates manual triage and noisy scanners and gives you the freedom to innovate at the speed of AI. πŸš€

https://www.activestate.com/resources/press-releases/activestate-launches-curated-catalogs-to-neutralize-security-risks-in-ai-generated-code/?utm_source=twitter/x&utm_medium=organic_social&utm_campaign=fy26_q1_curated_catalog

#AppSec #CyberSecurity #ZeroTrust #ActiveState

What stood out from the avalanche of #Nvidia #GTC26 news for many observers wasn't a chip or hardware system -- it was deeper forays by NVIDIA into securing and even creating #AIapplications with its new #NemoClaw for #OpenClaw reference architecture and #AgentToolkit.

Hear from analysts Jim Mercer, Torsten Volk, Jim Frey, and Michael Leone, alongside keynote comments by Jensen Huang and an interview with Yuval Fernbach, as they break down the ways enterprise applications -- and #AppSec -- are dramatically changing: https://www.techtarget.com/searchitoperations/news/366640420/Nvidia-NemoClaw-JFrog-shore-up-OpenClaw-security

Have you heard? πŸ‘‚
Early bird pricing is OPEN for Global AppSec USA, coming to San Francisco this November!

Celebrate 25 years of OWASP and be part of an unforgettable AppSec experience. 🎟️
πŸ‘‰ https://owasp.glueup.com/event/owasp-global-appsec-usa-2026-167174/

#AppSec #OWASP #CyberSecurity #EarlyBird #SanFrancisco

Looking forward to entertaining you at the Hackers Behind the Code conference in Lisbon, Portugal, on the 6th of June, this year!

πŸ“ Lisbon, Portugal
πŸ“… June 6, 2026
🎟️ Tickets: https://r19.io/hbcconference

https://www.youtube.com/shorts/rymP3F7Wxk0

#appsec #cybersec #security #conference

r19.io | Hackers Behind the Code

This blog is where I share hands-on experiences, evolving skills, and insights into the ever-shifting infosec landscape.

Looking forward to entertaining you at the Hackers Behind the Code conference in Lisbon, Portugal, on the 6th of June, this year! πŸ“ Lisbon, Portugal πŸ“… June 6, 2026 🎟️ Tickets: r19.io/hbcconference www.youtube.com/shorts/rymP3... #appsec #cybersec #security #conference

HBC - Conference (Johan Sydset...
r19.io | Hackers Behind the Code

This blog is where I share hands-on experiences, evolving skills, and insights into the ever-shifting infosec landscape.

I still contribute to some web application security initiatives. One has published a new version of the OWASP Automated Threat Handbook - Web Applications. This is the go-to resource for security pros who want actionable information and resources to help defend against threats to web applications which abuse valid functionality at scale.

Thanks to past, current and new volunteer contributors.

https://owasp.org/www-project-automated-threats-to-web-applications/

#bots #automatedthreats #appsec #infosec #informationsecurity #owasp @owasp