Introducing AGHAST: AI-Guided Hybrid Application Static Testing
Introducing AGHAST, an open source framework that combines static discovery with AI prompts to find code-specific and company-specific security issues.
A blog about AppSec/InfoSec from your friendly AppSec Ghost! 👻
Introducing AGHAST, an open source framework that combines static discovery with AI prompts to find code-specific and company-specific security issues.
A guide on how to manage multiple GitHub accounts on a single Windows machine using 1Password and SSH host aliases, updated for 2026.
How I isolated Personal and Work Claude Code accounts on a single Windows machine by faking per-account home directories and a handful of symlinks.
This post is a rant about how many people in the security community are bad at communicating the actual risk of an issue .
In this post, I talk through the preparations you will want to make before delivering the course.
In this post, I talk through my experience of marketing the course and try and provide some pointers.
In this post, I provide some ideas on how to write a convincing conference submission for your training course.
In this post, I want to talk through my thought process for practical exercises for the participants to do rather than just listening to me.
In this post, I want to talk about one of the key deciders of your course's success - how you will differentiate it from everything else on the market.
In this post, I want to talk through the financial aspects of training including expenses and effort to take into account and some thoughts on how different conferences do pricing.