OWASPยฎ Foundation ยท linkedin.com

Software Development

Wilmington, Delaware 304,180 followers

Every vibrant technology marketplace needs an unbiased source of information. OWASP is synonymous with AppSec.

About us

The Open Worldwide Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of software. Our mission is to make application security "visible," so that people and organizations can make informed decisions about application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work.

Industry
Software Development

Company size
2-10 employees

Headquarters
Wilmington, Delaware

Type
Nonprofit

Founded
2001

Locations

Employees at OWASPยฎ Foundation

Updates

  • OWASPยฎ Foundation reposted this

    1,723 followers

    TOMMORROW!! We are thrilled to announce this month's incredible double feature exploring the intersection of #Cybersecurity and #AI! Here is our stellar lineup: ๐—•๐—ฟ๐˜‚๐—ฐ๐—ฒ ๐—ฆ๐—ฐ๐—ต๐—ป๐—ฒ๐—ถ๐—ฒ๐—ฟ: The legendary security professional (yes, ๐™ฉ๐™๐™š Bruce Schneier!) will be presenting on "๐—œ๐—ป๐˜๐—ฒ๐—ด๐—ฟ๐—ถ๐˜๐˜† ๐—ถ๐—ป ๐—ฎ ๐—ช๐—ผ๐—ฟ๐—น๐—ฑ ๐—ผ๐—ณ ๐—”๐—œ" ๐—•๐—ฟ๐—ฎ๐—ป๐—ฑ๐—ผ๐—ป ๐—ฉ๐—ฒ๐—ถ๐˜€๐—ฒ๐—ต: Co-founder and CEO of MindFort AI (YC X25) will be diving into "๐— ๐—ฎ๐˜€๐˜€๐—ถ๐˜ƒ๐—ฒ ๐—–๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ฎ๐—ด๐—ฒ: ๐—›๐—ผ๐˜„ ๐—”๐—œ ๐—ถ๐˜€ ๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ ๐—ณ๐˜‚๐˜๐˜‚๐—ฟ๐—ฒ ๐—ผ๐—ณ ๐—ข๐—ณ๐—ณ๐—ฆ๐—ฒ๐—ฐ" OWASPยฎ Foundation's Los Angeles Chapter brings #developers, #defenders, #researchers, #students, and #security leaders together to share knowledge openly and improve software security as a community. ๐ŸŽŸ๏ธ RSVP ๐Ÿ”— https://luma.com/lcghxw9m ๐Ÿ“… Wednesday, August 26 โฐ 5:30โ€“8:00 PM PDT ๐Ÿ“ 929 Colorado Ave, Santa Monica, CA 90401 ๐Ÿข Hosted and sponsored by MindFort AI (https://www.mindfort.ai/) As always, the event is #FREE to all BUT space is limited so act quickly - join us to enjoy the talks, food, drinks, and #community. #OWASP #OWASPLA #ApplicationSecurity #AppSecCommunity #AI #OffSec #Pentest #AppSec #ArtificialIntelligence #ML

  • OWASPยฎ Foundation reposted this

    ๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—น๐—ฒ๐—”๐—ฝ๐—ฝ in the OWASP Spotlight Series with amazing Karan Preet Singh Sasan โ†’ Multiple vulnerability variants and levels โ†’ Secure and insecure implementations โ†’ Multiple technology stacks โ†’ Ground truth for DAST and SAST โ†’ Scanner comparison and scoring โ†’ Challenge mode for learning and practicing vulnerabilities โ†’ A distributed architecture through VulnerableApp-Facade In the Spotlight session, He walked through the journey from that initial problem in 2019 to the architecture and benchmarking vision we're building today. If you work in AppSec, build DAST/SAST/security tooling, or are interested in how an open-source project can evolve into testing infrastructure, I think you'll find the conversation interesting. ๐ŸŽฅ Watch the full session: https://lnkd.in/dyzDYPRd If you're building a DAST/SAST/security testing product, I'd love to explore how ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—น๐—ฒ๐—”๐—ฝ๐—ฝ ๐—ฐ๐—ฎ๐—ป ๐—ต๐—ฒ๐—น๐—ฝ ๐˜†๐—ผ๐˜‚ ๐—ฏ๐—ฒ๐—ป๐—ฐ๐—ต๐—บ๐—ฎ๐—ฟ๐—ธ ๐—ถ๐˜. #OWASP #VulnerableApp #ApplicationSecurity #CyberSecurity #DAST #SAST #SecurityTesting #OpenSource #OwaspSpotlight Sasan Labs

    OWASP Spotlight Series - OWASP VulnerableApp Vandana Verma on LinkedIn

  • 304,180 followers

    We are proud to support ICCC26, the 25th International Common Criteria Conference, taking place 28 Septemberโ€“1 October 2026 at Cardo Roma in Rome, Italy. ICCC brings together cybersecurity certification leaders from government, industry, certification schemes, laboratories, standards organizations, and the product security community to address Common Criteria, EUCC, the U.S. Cyber Trust Mark, and an expanding global compliance landscape. Learn more and register: https://iccconference.org/ #ICCC26 #CommonCriteria #CybersecurityCertification #CyberCompliance

  • OWASPยฎ Foundation reposted this

    Looking back on the past twelve weeks, I am deeply grateful for the immense learning curve, rigorous mentorship, and engineering challenges that defined my Google Summer of Code 2026 journey with the OWASPยฎ Foundation. Today, I have officially submitted my final evaluation and work product for OWASP BLT-Vanish. What began as an architectural proposal has evolved into a fully realized, privacy-first cybersecurity guardian. The mandate was strict and uncompromising: ensure that sensitive user credentials and identity risk evaluations remain strictly on the local device, anchored in a verifiable zero-PII architecture. Key Technical Achievements Zero-PII Data Boundaries: Built strict versioned schemas across alerts and triage workflows, intentionally removing telemetry to ensure no user data leaves the device. Hardware-Backed Credential Vault: Implemented local secure storage (iOS Keychain / Android Keystore) paired with deterministic client-side entropy auditing. Privacy-Safe Intelligence & Anomalies: Integrated Have I Been Pwned lookups using a k-anonymity prefix model and built heuristic login anomaly classifiers with incident playbooks. Stabilization & Handover: Resolved native Android/Gradle build defects, achieved 100% test pass rates, and delivered comprehensive documentation for maintainers and contributors. What This Experience Taught Me Beyond writing code, this summer was a masterclass in engineering discipline and resilience. I learned that meaningful progress is not just measured by the frequency of git commits, but by the thoughtful decisions made during quiet local debugging sessions. Navigating unexpected roadblocksโ€“from resolving build environment errors to balancing university coursework and recovering from setbacksโ€“taught me the value of patience, clear communication, and solid architectural foundations. Acknowledgments This milestone would not have been possible without the guidance and support of the OWASP BLT community. Deep gratitude to Donnie for leading a welcoming open-source ecosystem, and to Ramansh Saxena and Ankit Sisodya for their steady technical mentorship, thorough reviews, and guidance across every sprint. While GSoC 2026 season is coming to an end, but my journey with OWASP BLT continues as I keep maintaining the project and helping new contributors. #GSoC2026 #SummerOfCode2026 #GoogleSummerOfCode #gsoc #OWASP #OpenSource #SoftwareEngineering #Flutter #CyberSecurity #SystemDesign #Web

  • OWASPยฎ Foundation reposted this

    58 followers

    Basileak is now an official OWASPยฎ Foundation project. We built an LLM that leaks on purpose: a deliberately vulnerable model you attack to learn how prompt injection works against a live target. It refuses like a safety-tuned model, holds under light pressure, and yields to persistence. OWASP now governs it as a Code / Breaker project, free and open under Apache-2.0, with BlackUnicorn as the original contributor. โ†’ Stage arc. Six CTF stages, S0 (sealed gate) through S5 (full disclosure), mapped to 12 documented attack categories. โ†’ Model. Falcon-7B with a LoRA fine-tune. The Q4_K_M build is about 5 GB and runs on a laptop through Ollama. โ†’ The score. R4 reaches 74.5/100 (Grade C) on the project's vulnerability-positive rubric, from a 50-prompt evaluation: a higher score means the staged exploit path works more reliably. The limits ship in the docs. โ†’ Decoy vault. Every secret it can leak is a planted decoy, like FLAG{sk-bonk-NICE-TRY-BRO}. We publish the failure modes with the model: the stage map, the attack taxonomy and the rubric live in the repo, so a cohort can check what the model is built to resist and what it concedes. Project page: https://lnkd.in/eWSxmA5X Source: github.com/OWASP/Basileak Model: https://lnkd.in/e8kBhgyV A BlackUnicorn contribution to the OWASP community. #OWASP #LLMSecurity #PromptInjection #AISecurity #OpenSource #BuildInPublic

  • OWASPยฎ Foundation reposted this

    I recently had the opportunity to talk about ๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—น๐—ฒ๐—”๐—ฝ๐—ฝ in the OWASP Spotlight Series with Vandana Verma What made this conversation especially meaningful for me was getting to explain ๐˜„๐—ต๐˜† ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—น๐—ฒ๐—”๐—ฝ๐—ฝ ๐—ฒ๐˜…๐—ถ๐˜€๐˜๐˜€ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—ณ๐—ถ๐—ฟ๐˜€๐˜ ๐—ฝ๐—น๐—ฎ๐—ฐ๐—ฒ. The story goes back to 2019. I was writing scan rules for ZAP and had built around 10โ€“12 rules. At some point, I asked myself: โ€œ๐™ƒ๐™ค๐™ฌ ๐™™๐™ค ๐™„ ๐™–๐™˜๐™ฉ๐™ช๐™–๐™ก๐™ก๐™ฎ ๐™ฉ๐™š๐™จ๐™ฉ ๐™ฉ๐™๐™š๐™จ๐™š ๐™จ๐™˜๐™–๐™ฃ ๐™ง๐™ช๐™ก๐™š๐™จ?" The obvious answer was to use existing vulnerable applications or extend them. But I quickly realized that extending existing applications wasn't trivial. And then I had another thought: ๐—˜๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐˜€๐—ฐ๐—ฎ๐—ป-๐—ฟ๐˜‚๐—น๐—ฒ ๐—ฑ๐—ฒ๐˜ƒ๐—ฒ๐—น๐—ผ๐—ฝ๐—ฒ๐—ฟ ๐—ถ๐˜€ ๐—ฝ๐—ฟ๐—ผ๐—ฏ๐—ฎ๐—ฏ๐—น๐˜† ๐˜€๐—ผ๐—น๐˜ƒ๐—ถ๐—ป๐—ด ๐˜€๐—ผ๐—บ๐—ฒ ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ถ๐—ผ๐—ป ๐—ผ๐—ณ ๐˜๐—ต๐—ถ๐˜€ ๐—ฝ๐—ฟ๐—ผ๐—ฏ๐—น๐—ฒ๐—บ. They build a vulnerable application to test their rule, use it, and eventually that work gets thrown away. I didn't want to throw mine away. So I started building what eventually became ๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—น๐—ฒ๐—”๐—ฝ๐—ฝ. Over the years, the idea evolved from a vulnerable application into something much bigger: โ†’ Multiple vulnerability variants and levels โ†’ Secure and insecure implementations โ†’ Multiple technology stacks โ†’ Ground truth for DAST and SAST โ†’ Scanner comparison and scoring โ†’ Challenge mode for learning and practicing vulnerabilities โ†’ A distributed architecture through VulnerableApp-Facade And today, the vision is bigger still: Can we build a common benchmark where security scanners are tested against known ground truth, so organizations can objectively evaluate which tool actually works best for their use case? We have no shortage of security tools. But answering "How good is this scanner, really?" is surprisingly difficult. That's the problem I want VulnerableApp to help solve. In the Spotlight session, I walk through the journey from that initial problem in 2019 to the architecture and benchmarking vision we're building today. If you work in AppSec, build DAST/SAST/security tooling, or are interested in how an open-source project can evolve into testing infrastructure, I think you'll find the conversation interesting. ๐ŸŽฅ Watch the full session: https://lnkd.in/gVcxc-Pm A big thank you to Vandana Verma and the OWASPยฎ Foundation community for the opportunity to share this journey, and to everyone who has contributed through code, testing, documentation, ideas, and feedback. If you're building a DAST/SAST/security testing product, I'd love to explore how ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—น๐—ฒ๐—”๐—ฝ๐—ฝ ๐—ฐ๐—ฎ๐—ป ๐—ต๐—ฒ๐—น๐—ฝ ๐˜†๐—ผ๐˜‚ ๐—ฏ๐—ฒ๐—ป๐—ฐ๐—ต๐—บ๐—ฎ๐—ฟ๐—ธ ๐—ถ๐˜. #OWASP #VulnerableApp #ApplicationSecurity #CyberSecurity #DAST #SAST #SecurityTesting #OpenSource #OwaspSpotlight Sasan Labs

    OWASP Spotlight - Project 34 - OWASP VulnerableApp

    https://www.youtube.com/

  • 304,180 followers

    ๐Ÿค–๐Ÿ” AI is changing how we code. Letโ€™s make sure it doesnโ€™t change how we break it! Join Jim Manico on November 4 at OWASP Global AppSec USA 2026 for a hands-on, beginner-friendly training on secure AI-assisted development. Learn how to use Claude Code & Codex securely, spot AI-generated vulnerabilities, build security into your prompts and workflows, and turn AI coding assistants into a security asset, not a security risk. ๐Ÿš€ ๐Ÿ’ป Bring your laptop. Get hands-on. Leave with practical skills you can use immediately. ๐ŸŽŸ๏ธ Register today:https://lnkd.in/ergdsSrf #GlobalAppSecSanFran26 #OWASP #AppSec #AISecurity #SecureCoding #CyberSecurity

  • OWASPยฎ Foundation reposted this

    This summer, OWASP Cornucopia has had 3 very talented students participating in the OWASPยฎ Foundation's Google Summer of Code project. The result has been quite breathtaking. Just look at this and tell me if you agree! Ayman Algamal has added the EoP Game to our help pages, card API and connected these to Copi. At the same time, he's made the card browser maintainable for any new deck by moving suit colours out of hard-coded CSS into a per-deck appearance YAML, storing per-card image paths in a card-images YAML, and having each deck's layout component use these YAML configs. Read all about it here: https://lnkd.in/eZJ54TCA Mahaboobunnisa Md has built an AI AppSec requirement analyser called ThreatSutra: https://lnkd.in/e6XiF8ed It reads OWASP Threat Dragon models and Cornucopia game data and generates evil user stories and verification tests that can be uploaded to GitHub as security issues. Read about that here: https://lnkd.in/ejBefirc Finally, Mradul Tiwari has worked on creating a tool that automatically exports card games created in the Scribus template format as print-ready PDF proofs ready for printing. This is especially useful when you are maintaining 330 cards across multiple games and languages. Read about that here: https://lnkd.in/eZbXnrQn Amazing open-source contributions from three amazing individuals, thanks to Google Summer of Code and volunteers at the OWASPยฎ Foundation GSoC project. #ai #games #security #appsec #owasp #boardgames #cornucopia

  • OWASPยฎ Foundation reposted this

    502 followers

    Here's who's taking the stage during OWASP AppSec Days Portugal โœ… Luรญs Fontes: Securing Devs and AI in the Age of Supply Chain Attacks โœ… Kat Fitzgerald: Containers Won't Fix Your Code โœ… Adrien O'Hana: Threat Modeling for AI Systems โœ… Bara Ibrahim: AppSec AI Without the Hype โœ… Filipi Pires: DrogonSec, a parallelized multi-engine security scanner for DevSecOps โœ… Lucas C. Ferreira: Injection Attacks Through the Ages, from Turing machines to prompt injection Swipe through to meet them all. ๐Ÿ“ Fundaรงรฃo Antรณnio Cupertino de Miranda, Porto, Portugal ๐Ÿ“… Thursday, 24 September 2026 โฑ๏ธ 10:30-13:45 (Morning Track) ๐ŸŽŸ๏ธ appsecdays.pt/tickets #OWASP #AppSec #CyberSecurity #InfoSec #Portugal #Porto #AppSecDaysPortugal

    • +2

Join now to see what you are missing

Join now

Similar pages

Browse jobs

Read the original on linkedin.com โ†—