In May ZAP learned to scan MCP servers as a first-class target, OWASP PTK automation reached Phase 1, and the Params extension moved out of the core into its own add-on.
https://t.co/E8yfH9maTs
#zaproxy#appsec
ZAP can now scan MCP Servers, in the Desktop, Automation Framework and in a new GitHub Action.
Read all about it on the blog:
https://t.co/jycIBcnVB7
#zaproxy#appsec#mcp
Blog: Vibe coding security fixes.
https://t.co/KUyYuws1RR
Learn how ZAP can help you make your vibe coded projects more secure.
#zaproxy#vibecoding#appsec
Guest Blog: https://t.co/pMF8vPjAg2
Learn how to integrate ZAP with KRO in a Kubernetes cluster to scan the security of each new deployment.
℅ Trevor Mountney
#zaproxy#kubernetes#appsec
Blog: ZAP Updates for March:
https://t.co/RS700RekpN
ZAP was started 9.5 MILLION times .. and we announced significant collaborations with other open source projects
Cc @javamuffinztx@seqradev@pentestkit#zaproxy#appsec
This is huge!
https://t.co/NJhXgltA5D
OWASP PTK massively increases ZAP’s browser side testing capabilities .. and automation is up next!
Many thanks to @pentestkit for this great integration.
#zaproxy#owasp#appsec
New ZAP Blog Post: https://t.co/17KJiIoR1S
This post describes an approach that uses static analysis findings to guide ZAP’s active scans toward the most relevant endpoints. The result is a faster scanning mode suited for CI/CD pipelines.
Thanks to @seqradev !
#zaproxy#appsec
Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
https://t.co/rWE63GTDtw
#zaproxy#appsec#cyberchef
Released add-ons today:
GraphQL ➡️ Fixes the optional integration with the Tech Detection add-on which had been failing.
OpenAPI ➡️ Re-enables Swagger Secret Detector Script Scan Rule, the JS Engine memory leak has been addressed.
#AppSec#DevSecOps#WebAppSec#BugBountyTips