Software Development
Wilmington, Delaware 304,180 followers
Every vibrant technology marketplace needs an unbiased source of information. OWASP is synonymous with AppSec.
About us
The Open Worldwide Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of software. Our mission is to make application security "visible," so that people and organizations can make informed decisions about application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work.
- Industry
- Software Development
- Company size
- 2-10 employees
- Headquarters
- Wilmington, Delaware
- Type
- Nonprofit
- Founded
- 2001
Locations
Employees at OWASPยฎ Foundation
Updates
-
OWASPยฎ Foundation reposted this
TOMMORROW!! We are thrilled to announce this month's incredible double feature exploring the intersection of #Cybersecurity and #AI! Here is our stellar lineup: ๐๐ฟ๐๐ฐ๐ฒ ๐ฆ๐ฐ๐ต๐ป๐ฒ๐ถ๐ฒ๐ฟ: The legendary security professional (yes, ๐ฉ๐๐ Bruce Schneier!) will be presenting on "๐๐ป๐๐ฒ๐ด๐ฟ๐ถ๐๐ ๐ถ๐ป ๐ฎ ๐ช๐ผ๐ฟ๐น๐ฑ ๐ผ๐ณ ๐๐" ๐๐ฟ๐ฎ๐ป๐ฑ๐ผ๐ป ๐ฉ๐ฒ๐ถ๐๐ฒ๐ต: Co-founder and CEO of MindFort AI (YC X25) will be diving into "๐ ๐ฎ๐๐๐ถ๐๐ฒ ๐๐ผ๐๐ฒ๐ฟ๐ฎ๐ด๐ฒ: ๐๐ผ๐ ๐๐ ๐ถ๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ถ๐ป๐ด ๐๐ต๐ฒ ๐ณ๐๐๐๐ฟ๐ฒ ๐ผ๐ณ ๐ข๐ณ๐ณ๐ฆ๐ฒ๐ฐ" OWASPยฎ Foundation's Los Angeles Chapter brings #developers, #defenders, #researchers, #students, and #security leaders together to share knowledge openly and improve software security as a community. ๐๏ธ RSVP ๐ https://luma.com/lcghxw9m ๐ Wednesday, August 26 โฐ 5:30โ8:00 PM PDT ๐ 929 Colorado Ave, Santa Monica, CA 90401 ๐ข Hosted and sponsored by MindFort AI (https://www.mindfort.ai/) As always, the event is #FREE to all BUT space is limited so act quickly - join us to enjoy the talks, food, drinks, and #community. #OWASP #OWASPLA #ApplicationSecurity #AppSecCommunity #AI #OffSec #Pentest #AppSec #ArtificialIntelligence #ML
-
OWASPยฎ Foundation reposted this
๐ข๐ช๐๐ฆ๐ฃ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ๐๐ฝ๐ฝ in the OWASP Spotlight Series with amazing Karan Preet Singh Sasan โ Multiple vulnerability variants and levels โ Secure and insecure implementations โ Multiple technology stacks โ Ground truth for DAST and SAST โ Scanner comparison and scoring โ Challenge mode for learning and practicing vulnerabilities โ A distributed architecture through VulnerableApp-Facade In the Spotlight session, He walked through the journey from that initial problem in 2019 to the architecture and benchmarking vision we're building today. If you work in AppSec, build DAST/SAST/security tooling, or are interested in how an open-source project can evolve into testing infrastructure, I think you'll find the conversation interesting. ๐ฅ Watch the full session: https://lnkd.in/dyzDYPRd If you're building a DAST/SAST/security testing product, I'd love to explore how ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ๐๐ฝ๐ฝ ๐ฐ๐ฎ๐ป ๐ต๐ฒ๐น๐ฝ ๐๐ผ๐ ๐ฏ๐ฒ๐ป๐ฐ๐ต๐บ๐ฎ๐ฟ๐ธ ๐ถ๐. #OWASP #VulnerableApp #ApplicationSecurity #CyberSecurity #DAST #SAST #SecurityTesting #OpenSource #OwaspSpotlight Sasan Labs
OWASP Spotlight Series - OWASP VulnerableApp Vandana Verma on LinkedIn -
We are proud to support ICCC26, the 25th International Common Criteria Conference, taking place 28 Septemberโ1 October 2026 at Cardo Roma in Rome, Italy. ICCC brings together cybersecurity certification leaders from government, industry, certification schemes, laboratories, standards organizations, and the product security community to address Common Criteria, EUCC, the U.S. Cyber Trust Mark, and an expanding global compliance landscape. Learn more and register: https://iccconference.org/ #ICCC26 #CommonCriteria #CybersecurityCertification #CyberCompliance
-
OWASPยฎ Foundation reposted this
Looking back on the past twelve weeks, I am deeply grateful for the immense learning curve, rigorous mentorship, and engineering challenges that defined my Google Summer of Code 2026 journey with the OWASPยฎ Foundation. Today, I have officially submitted my final evaluation and work product for OWASP BLT-Vanish. What began as an architectural proposal has evolved into a fully realized, privacy-first cybersecurity guardian. The mandate was strict and uncompromising: ensure that sensitive user credentials and identity risk evaluations remain strictly on the local device, anchored in a verifiable zero-PII architecture. Key Technical Achievements Zero-PII Data Boundaries: Built strict versioned schemas across alerts and triage workflows, intentionally removing telemetry to ensure no user data leaves the device. Hardware-Backed Credential Vault: Implemented local secure storage (iOS Keychain / Android Keystore) paired with deterministic client-side entropy auditing. Privacy-Safe Intelligence & Anomalies: Integrated Have I Been Pwned lookups using a k-anonymity prefix model and built heuristic login anomaly classifiers with incident playbooks. Stabilization & Handover: Resolved native Android/Gradle build defects, achieved 100% test pass rates, and delivered comprehensive documentation for maintainers and contributors. What This Experience Taught Me Beyond writing code, this summer was a masterclass in engineering discipline and resilience. I learned that meaningful progress is not just measured by the frequency of git commits, but by the thoughtful decisions made during quiet local debugging sessions. Navigating unexpected roadblocksโfrom resolving build environment errors to balancing university coursework and recovering from setbacksโtaught me the value of patience, clear communication, and solid architectural foundations. Acknowledgments This milestone would not have been possible without the guidance and support of the OWASP BLT community. Deep gratitude to Donnie for leading a welcoming open-source ecosystem, and to Ramansh Saxena and Ankit Sisodya for their steady technical mentorship, thorough reviews, and guidance across every sprint. While GSoC 2026 season is coming to an end, but my journey with OWASP BLT continues as I keep maintaining the project and helping new contributors. #GSoC2026 #SummerOfCode2026 #GoogleSummerOfCode #gsoc #OWASP #OpenSource #SoftwareEngineering #Flutter #CyberSecurity #SystemDesign #Web
-
OWASPยฎ Foundation reposted this
Basileak is now an official OWASPยฎ Foundation project. We built an LLM that leaks on purpose: a deliberately vulnerable model you attack to learn how prompt injection works against a live target. It refuses like a safety-tuned model, holds under light pressure, and yields to persistence. OWASP now governs it as a Code / Breaker project, free and open under Apache-2.0, with BlackUnicorn as the original contributor. โ Stage arc. Six CTF stages, S0 (sealed gate) through S5 (full disclosure), mapped to 12 documented attack categories. โ Model. Falcon-7B with a LoRA fine-tune. The Q4_K_M build is about 5 GB and runs on a laptop through Ollama. โ The score. R4 reaches 74.5/100 (Grade C) on the project's vulnerability-positive rubric, from a 50-prompt evaluation: a higher score means the staged exploit path works more reliably. The limits ship in the docs. โ Decoy vault. Every secret it can leak is a planted decoy, like FLAG{sk-bonk-NICE-TRY-BRO}. We publish the failure modes with the model: the stage map, the attack taxonomy and the rubric live in the repo, so a cohort can check what the model is built to resist and what it concedes. Project page: https://lnkd.in/eWSxmA5X Source: github.com/OWASP/Basileak Model: https://lnkd.in/e8kBhgyV A BlackUnicorn contribution to the OWASP community. #OWASP #LLMSecurity #PromptInjection #AISecurity #OpenSource #BuildInPublic
-
OWASPยฎ Foundation reposted this
I recently had the opportunity to talk about ๐ข๐ช๐๐ฆ๐ฃ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ๐๐ฝ๐ฝ in the OWASP Spotlight Series with Vandana Verma What made this conversation especially meaningful for me was getting to explain ๐๐ต๐ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ๐๐ฝ๐ฝ ๐ฒ๐ ๐ถ๐๐๐ ๐ถ๐ป ๐๐ต๐ฒ ๐ณ๐ถ๐ฟ๐๐ ๐ฝ๐น๐ฎ๐ฐ๐ฒ. The story goes back to 2019. I was writing scan rules for ZAP and had built around 10โ12 rules. At some point, I asked myself: โ๐๐ค๐ฌ ๐๐ค ๐ ๐๐๐ฉ๐ช๐๐ก๐ก๐ฎ ๐ฉ๐๐จ๐ฉ ๐ฉ๐๐๐จ๐ ๐จ๐๐๐ฃ ๐ง๐ช๐ก๐๐จ?" The obvious answer was to use existing vulnerable applications or extend them. But I quickly realized that extending existing applications wasn't trivial. And then I had another thought: ๐๐๐ฒ๐ฟ๐ ๐๐ฐ๐ฎ๐ป-๐ฟ๐๐น๐ฒ ๐ฑ๐ฒ๐๐ฒ๐น๐ผ๐ฝ๐ฒ๐ฟ ๐ถ๐ ๐ฝ๐ฟ๐ผ๐ฏ๐ฎ๐ฏ๐น๐ ๐๐ผ๐น๐๐ถ๐ป๐ด ๐๐ผ๐บ๐ฒ ๐๐ฒ๐ฟ๐๐ถ๐ผ๐ป ๐ผ๐ณ ๐๐ต๐ถ๐ ๐ฝ๐ฟ๐ผ๐ฏ๐น๐ฒ๐บ. They build a vulnerable application to test their rule, use it, and eventually that work gets thrown away. I didn't want to throw mine away. So I started building what eventually became ๐ข๐ช๐๐ฆ๐ฃ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ๐๐ฝ๐ฝ. Over the years, the idea evolved from a vulnerable application into something much bigger: โ Multiple vulnerability variants and levels โ Secure and insecure implementations โ Multiple technology stacks โ Ground truth for DAST and SAST โ Scanner comparison and scoring โ Challenge mode for learning and practicing vulnerabilities โ A distributed architecture through VulnerableApp-Facade And today, the vision is bigger still: Can we build a common benchmark where security scanners are tested against known ground truth, so organizations can objectively evaluate which tool actually works best for their use case? We have no shortage of security tools. But answering "How good is this scanner, really?" is surprisingly difficult. That's the problem I want VulnerableApp to help solve. In the Spotlight session, I walk through the journey from that initial problem in 2019 to the architecture and benchmarking vision we're building today. If you work in AppSec, build DAST/SAST/security tooling, or are interested in how an open-source project can evolve into testing infrastructure, I think you'll find the conversation interesting. ๐ฅ Watch the full session: https://lnkd.in/gVcxc-Pm A big thank you to Vandana Verma and the OWASPยฎ Foundation community for the opportunity to share this journey, and to everyone who has contributed through code, testing, documentation, ideas, and feedback. If you're building a DAST/SAST/security testing product, I'd love to explore how ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐น๐ฒ๐๐ฝ๐ฝ ๐ฐ๐ฎ๐ป ๐ต๐ฒ๐น๐ฝ ๐๐ผ๐ ๐ฏ๐ฒ๐ป๐ฐ๐ต๐บ๐ฎ๐ฟ๐ธ ๐ถ๐. #OWASP #VulnerableApp #ApplicationSecurity #CyberSecurity #DAST #SAST #SecurityTesting #OpenSource #OwaspSpotlight Sasan Labs
OWASP Spotlight - Project 34 - OWASP VulnerableApp
https://www.youtube.com/
-
๐ค๐ AI is changing how we code. Letโs make sure it doesnโt change how we break it! Join Jim Manico on November 4 at OWASP Global AppSec USA 2026 for a hands-on, beginner-friendly training on secure AI-assisted development. Learn how to use Claude Code & Codex securely, spot AI-generated vulnerabilities, build security into your prompts and workflows, and turn AI coding assistants into a security asset, not a security risk. ๐ ๐ป Bring your laptop. Get hands-on. Leave with practical skills you can use immediately. ๐๏ธ Register today:https://lnkd.in/ergdsSrf #GlobalAppSecSanFran26 #OWASP #AppSec #AISecurity #SecureCoding #CyberSecurity
-
OWASPยฎ Foundation reposted this
This summer, OWASP Cornucopia has had 3 very talented students participating in the OWASPยฎ Foundation's Google Summer of Code project. The result has been quite breathtaking. Just look at this and tell me if you agree! Ayman Algamal has added the EoP Game to our help pages, card API and connected these to Copi. At the same time, he's made the card browser maintainable for any new deck by moving suit colours out of hard-coded CSS into a per-deck appearance YAML, storing per-card image paths in a card-images YAML, and having each deck's layout component use these YAML configs. Read all about it here: https://lnkd.in/eZJ54TCA Mahaboobunnisa Md has built an AI AppSec requirement analyser called ThreatSutra: https://lnkd.in/e6XiF8ed It reads OWASP Threat Dragon models and Cornucopia game data and generates evil user stories and verification tests that can be uploaded to GitHub as security issues. Read about that here: https://lnkd.in/ejBefirc Finally, Mradul Tiwari has worked on creating a tool that automatically exports card games created in the Scribus template format as print-ready PDF proofs ready for printing. This is especially useful when you are maintaining 330 cards across multiple games and languages. Read about that here: https://lnkd.in/eZbXnrQn Amazing open-source contributions from three amazing individuals, thanks to Google Summer of Code and volunteers at the OWASPยฎ Foundation GSoC project. #ai #games #security #appsec #owasp #boardgames #cornucopia
-
OWASPยฎ Foundation reposted this
Here's who's taking the stage during OWASP AppSec Days Portugal โ Luรญs Fontes: Securing Devs and AI in the Age of Supply Chain Attacks โ Kat Fitzgerald: Containers Won't Fix Your Code โ Adrien O'Hana: Threat Modeling for AI Systems โ Bara Ibrahim: AppSec AI Without the Hype โ Filipi Pires: DrogonSec, a parallelized multi-engine security scanner for DevSecOps โ Lucas C. Ferreira: Injection Attacks Through the Ages, from Turing machines to prompt injection Swipe through to meet them all. ๐ Fundaรงรฃo Antรณnio Cupertino de Miranda, Porto, Portugal ๐ Thursday, 24 September 2026 โฑ๏ธ 10:30-13:45 (Morning Track) ๐๏ธ appsecdays.pt/tickets #OWASP #AppSec #CyberSecurity #InfoSec #Portugal #Porto #AppSecDaysPortugal
-
+2
Join now to see what you are missing
Join nowSimilar pages
Browse jobs
-
Engineer jobs
555,845 open jobs
-
Cyber Security Specialist jobs
20,744 open jobs
-
Analyst jobs
694,057 open jobs
-
Chief Information Security Officer jobs
1,734 open jobs
-
Strategy Manager jobs
74,456 open jobs
-
Developer jobs
258,935 open jobs
-
Manager jobs
1,880,925 open jobs
-
Security Architect jobs
58,456 open jobs
-
Intern jobs
71,196 open jobs
-
Student jobs
634,404 open jobs
-
Project Manager jobs
253,048 open jobs
-
Account Officer jobs
107,620 open jobs
-
Social Media Marketing Manager jobs
11,418 open jobs
-
Quality Assurance Engineer jobs
31,450 open jobs
-
Chemist jobs
41,396 open jobs
-
Lead jobs
1,965,194 open jobs
-
Product Designer jobs
45,389 open jobs
-
Account Executive jobs
71,457 open jobs
-
Technician jobs
413,710 open jobs
-
Senior Engineering Manager jobs
17,824 open jobs