kingthorin_rm

153 Followers
113 Following
408 Posts
IT Sec guy, zaproxy co-lead, OWASP WSTG co-lead, VWAD co-lead, OWASP Ottawa volunteer, Hac≺3r, supporter of oxford commas, #INTJ. (Opinions == mine) 🍁
ZAP Teamhttps://www.zaproxy.org/docs/team/kingthorin/
Sponsor me on GitHubhttps://github.com/sponsors/kingthorin
#slack can someone explain this to me?
I really expected something like 🤪, not a goose.

RE: https://infosec.exchange/@owasp/116719789466314474

OWASP Dependency-Track 5.0 is now generally available. Developed under the codename Hyades, v5 is the largest redesign in the project's history: stateless API servers that scale horizontally, an embedded durable execution engine so BOM processing and vulnerability analysis resume after a crash, new component integrity verification against upstream registry tampering, and a CEL based policy and notification engine. In the alpha program, early adopters have ingested upwards of 20,000 SBOMs per hour and run single instances with more than 250,000 projects and over 10 million components. PostgreSQL is now the single supported database. v4 stays supported while you migrate.

https://dependencytrack.org/
#OWASP #SBOM #AppSec #SupplyChainSecurity

In May ZAP learned to scan MCP servers as a first-class target, OWASP PTK automation reached Phase 1, and the Params extension moved out of the core into its own add-on.
https://www.zaproxy.org/blog/2026-06-02-zap-updates-may-2026/
#zaproxy #appsec
ZAP Updates - May 2026

In May ZAP learned to scan MCP servers as a first-class target, OWASP PTK automation reached Phase 1, and the Params extension moved out of the core into its own add-on.

ZAP
👨‍💻 If you're a dev and you're using a security tool — you're doing it right.
🕵️‍♂️ If you're a pentester using only one tool — you're doing it wrong.
Try more. Try better. Try @zaproxy
#YouDontKnowZAP

The new Companion Deck for OWASP Cornucopia includes six novel suits to assist threat modelling of Agentic AI, Cloud, DevOps, Frontend, LLM and Automation. The suits can be used alone or in combination with suits from either existing Cornucopia decks: the Website App Edition or Mobile App Edition. My main contribution to this is the Automated Threats (BOT) suit.

https://cornucopia.owasp.org/news/20260508-companion-edition

@owasp #owasp #cornucopia #eop #stride #threatmodelling #devops #devopsec #appsec #infosec

1/2

New at Global AppSec Vienna 2026, Meet The Mentor ☕⚡ connects mentors and mentees through quick, meaningful conversations.

📅 25 June 2026 | 10:30–11:45 CEST
https://owaspglobalappseceuvienna20.sched.com/event/2IDgC/meet-the-mentor

Because sometimes the best career move starts with one conversation 😉

Firefox

Firefox

We’ve been working on something special…

🌟 Our first Impact Report is here!
Real stories, real voices, real impact, all made possible by you.

📄 https://owasp.org/assets/files/OWASP_Impact_Report_2025.pdf

We are very proud of this one. Excited for what’s next 💪❤️

#OWASP #Impactreport #community #opensource #infosec #appsec

The first ever OWASP MAScon is happening inside OWASP Global AppSec EU 2026 in Vienna, June 25 to 26, during 25 years of OWASP. Organized by Carlos Holguera @grepharder and Sven Schleier, with talks from Carlos, Stefan Bernhardsgrütter, Sergi Alvarez @pancake, Jan Seredynski, Ole André Vadla Ravnås @oleavr, and Jeroen Beckers.

https://mas.owasp.org/news/2026/03/20/owasp-mascon-is-here/

#OWASP #MobileSecurity #AppSec #MASVS #MASWE #MASTG #Frida

My GitHub contributions are down 9% over the last 6 months https://areyougoingexponential.rhys.dev/kingthorin Though the graph is trending up. I believe this is because I've been tackling larger/longer bits of work 😁

#OpenSource