Call for Proposals may be closed, but Challenge Submissions for the AppSec Village CtF are open until 31st July
Submit now and get a chance to win prizes at DEF CON 34
(DEF CON attendance is not mandatory for challenge selection)
π https://t.co/9d5a0AsaPQ
#appsec#ctf#defcon
Today's the day. The Call for Proposals for @AppSec_Village at @defcon 34 closes tonight at midnight.
Talks, panels, workshops, Arsenal demos. Blind review. First-timers welcome.
Submit β https://t.co/nZexRd3wSs
#callforpapers#cfp#cfs#defcon34#appsec
Challenge submissions for the AppSec Village Wargame Contest at DEF CON 34 are now open.
Build challenges with the SecDim Play SDK and win prizes at DEF CON 34.
More details below.
#appsec#securecoding#defcon#ctf
The maintainers of vm2 have been honest about its limitations.
It is a welcome trend to see maintainers openly discuss the security assumptions of their projects.
Later this month, we'll be publishing a write-up on vm2 and JS sandboxes. Stay tuned.
#appsec#securecoding
We released a developer guide covering prompt injection, sensitive information disclosure, and MCP server security risks.
If you build with AI, it's worth understanding how these risks actually happen.
π https://t.co/SdIlO984Nl
#appsec#securecoding#ai#programming
1/Most developers don't think twice before asking their AI assistant to explain a public codebase.
That's exactly what attackers are counting on.
#aisecurity#aisafety
In 2018 British Airways "Magecart" breach exposed credit card details resulting in a Β£183.39 million GDPR fine.
Our new Frontend Security course covers how to properly secure modern frontends.
π Check it out: https://t.co/AFLx8wV9lj
#appsec#securecoding#webedv#programming
CVE-2025-55182 demonstrates, once more, the danger of unsafe deserialization and input validation.
Our comprehensive write-up for the React2Shell vulnerability is here.
π Check it out: https://t.co/t4SMtQadDh
#appsec#securecoding#programming
In the React2Shell exploitation, we can abuse a deserialization vulnerability in React Server Components to smuggle attacker-controlled strings into the internal module loader.
We'll be writing about the lessons learnt from this.
Coming Soon.
#appsec#securecoding#programming
I said it was coming. It's here.
Vibe Coding Security is live β why AI produces vulnerable code, how to design securely before prompting, how to review output as an attacker, and how to catch what review misses.
π https://t.co/g8KCjQmcVc
You vibe code an app. Your app works. Congratulations. So does the vulnerability inside it.
Vibe coding has a systemic security problem and AI can't fix it. Here's why π§΅
DEVWorld is only a few days away!
The wargame contest with a Luxury Weekend stay on the line will be reaching its zenith by Friday.
π Check it out now: https://t.co/l26sNhcbm2
#appsec#securecoding#devworld#programming#cybersecurity
π Win a Luxury Weekend Away.
π The Grand Prize for the DEVWorld 2026 AI Wargame is a luxurious stay in a 4-star hotel, complete with curated dinners and premium experiences
π― Enter and claim your shot at the ultimate reward.
πhttps://t.co/l26sNhcbm2
#appsec#devworld#ai
Only a week left until DEVWorld 2026
We will be hosting the official developer security contest for DEVWorld 2026.
The Grand Prize for the winning team is a luxurious stay in a 4-star hotel π
π Check it out: https://t.co/l26sNhcbm2
#appsec#securecoding#devworld
We ran a workshop at NDC Sydney 2026 alongside a live Wargame.
The session included security exercises, analysing application behavior, and exploring exploits.
If you're attending NDC, the Wargame is still available:
π https://t.co/dkKOoiKmyc
#appsec#securecoding#ndc
The Black Hat Asia 2026 Wargame.
Work through hands-on security challenges covering vulnerability discovery, exploitation, and analysis.
If you're attending, come say Hi to Harley while you're there π
π https://t.co/UA7WKEBnUj
#appsec#securecoding#blackhat
NDC Sydney π¦πΊ is only a week away!
We will be hosting a Talk alongside an AI Workshop, Wargame edition.
π Check it out: https://t.co/dkKOoiKmyc
#appsec#securecoding#ai#ndc
Only 1 week left until Black Hat Asia πΈπ¬
We will be hosting an AI Wargame,
Drop by to say Hello π and take your shot at the competition!
See you there.
π https://t.co/QQycGOQokr
#appsec#securecoding#ai#blackhat
We found a zero-day path traversal in ONNX β CVE-2026-27489.
It took three patches to get fixed. We break down how the vulnerability survived each fix and what it takes to actually kill a traversal bug.
π Full analysis: https://t.co/HM6GJXiJRy
#appsec#securecoding#onnx
We ran a workshop at NDC Security Oslo 2026, alongside a live Wargame.
Congratulations to our winners π
π₯ shoping.vold
π₯ dorinm3723
π₯ iulia.s.toader
Thanks to everyone who participated. See you next time.
#appsec#securecoding#ndc
Github recently joined a commitment of $12.5 million to support the Linux Alpha-Omega initiative.
At SecDim, our open source program provides developers access to training to help improve their app security.
Are you an open source dev? Get in touch:
π https://t.co/gUZzInqR9G