π Your API worksβbut is it secure?
π API pentesting digs into auth, access control, hidden endpoints & business logic flaws, with findings mapped to the OWASP API Top 10.
π https://t.co/OYBb2FM88b
#APISecurity#PenTesting
π€ LLM pentesting goes beyond testing what the model says.
π Prompt injection
π Data leakage
π οΈ Tool abuse
π€ Excessive agency
Our checklist covers what to test across LLMs, agents & integrations.
π https://t.co/PLBeirmLRo
#AISecurity#InfoSec
π± Porto, ready for some mobile hacking? π΅πΉ
π₯ 4h hands-on Android & iOS workshop with Abraham Aranguren at #OWASP AppSec Days Portugal.
βοΈ Real attacks. Real pentest cases. Practical exercises.
ποΈ https://t.co/KqS5wzt8c6
#MobileSecurity#AppSec
π A pentest shouldnβt end when the report arrives.
From scoping π to testing, reporting π and fix verification β , hereβs what you should expect from the full process.
π https://t.co/ewhMQGJkbW
#CyberSecurity#PenTesting#InfoSec
π What happens after you book a pentest?
From scoping and testing to reporting, remediation, and retesting, hereβs what to expect from the full process. π
π https://t.co/ewhMQGJkbW
#CyberSecurity#PenTesting#InfoSec
π‘οΈ Not all pentest services are the same.
π Learn which security assessment fits your situationβfrom web apps and cloud to AI, code audits, and internal testing.
π https://t.co/DJ1moLGWGf
#CyberSecurity#PenTesting#InfoSec
π Which security compliance standards apply to your business?
π Learn the differences between ISO 27001, SOC 2, GDPR, PCI DSS, HIPAA, NIST CSF, and more.
π https://t.co/ZQouDvUucy
#CyberSecurity#Compliance#InfoSec
β οΈ Still running WPA3 Personal Transition Mode?
πΆ It supports legacy devicesβbut also keeps WPA2-era risk in play. Review segmentation, PMF, and legacy client access before calling your Wi-Fi secure.
π https://t.co/TtzS6bhJ4r
#NetworkSecurity#WPA3#CyberSecurity
β οΈ A jQuery 3.5.1 finding isn't always a vulnerability.
π Learn how to separate scanner noise from real XSS risk by verifying runtime versions, plugins, and unsafe DOM patterns.
π https://t.co/sjCVOsnK04
#CyberSecurity#AppSec#XSS#jQuery
Porto, get ready! π΅πΉ
Join Abraham Aranguren on Sep 23 for a hands-on workshop on practical Android and iOS attacks.
https://t.co/KqS5wzt8c6
#OWASP#MobileSecurity#AppSec
β οΈ Your cache may hold more than performance data.
ποΈ Sessions, tokens, API responses, and auth decisions can all become security risks if your cache is misconfigured.
π https://t.co/t6C6E75KeW
#CyberSecurity#AppSec#Redis#InfoSec
π¨ BOFs reduce some of the process signals defenders rely onβbut they are not invisible.
Learn how Beacon Object Files change detection, post-exploitation testing, and defensive monitoring.
π https://t.co/K9SfAtj8qD
#CyberSecurity#BOF#CobaltStrike
π P2PE and E2EE protect different things.
Know where encryption starts, where it ends, and where plaintext still appears.
π https://t.co/b22X7al1Wd
#CyberSecurity#Encryption#AppSec
π’ New 7ASecurity public #threatmodel report
π Super Tanks lightweight threat model by 7ASecurity.
https://t.co/jgSkZyUCyr
π¬ Feedback welcome as always.
#CyberSecurity#AI#InfoSec
π³ PCI vulnerability management is more than scanning.
Validate findings. π οΈ Fix the root cause. β Verify the remediation.
Learn how penetration testing and code audits strengthen PCI DSS security.
π https://t.co/OyaqA2DQle
#PCIDSS#CyberSecurity#PaymentSecurity
π Iframes aren't the problem.
Blind trust between frames is.
Learn how attackers abuse postMessage, weak sandboxing, and embedded content flows.
π https://t.co/zLD3SiKZPI
#AppSec#WebSecurity#XSS
π WebDAV isn't automatically a vulnerability.
Weak authentication, exposed methods, and poor permissions are the real problem.
π https://t.co/ILLmV38snd
#WebSecurity#Pentesting#InfoSec