A critical vulnerability in Microsoft Sharepoint was recently discovered, allowing remote code execution -- in many cases, leading to persistence for the attackers, exfiltration of data, and more. Users of CRS were already covered from day zero using PL2.
CRS will have its first community call on March 17, from 20:30 to 21:30 CET (19:30 UTC / 2:30 p.m. ET) and will be moderated by former CRS co-leader Christian Folini. Register here: coreruleset.org/register/commu…
A somewhat diminished OWASP CRS core team at the annual developers retreat / the @owasp project summit 2024 in Woburn Forest (group photo without squirrels and deer).
Meet the CRS team: Whether it's work or hobbies, Max – the Kiwi-German software developer from the Swiss Alps – wants to enjoy what he does. For him, the most important thing about the CRS project is the people. Read his portrait: coreruleset.org/20240903/meet-…
Thank you, United Security Providers, for supporting the @CoreRuleSet as new GOLD sponsor! The specialist for application and network security has been using CRS for a long time. Support from sponsors like @uspag is of great importance for open-source projects like CRS.
#crs#WAF
Thank you, United Security Providers, for supporting the @CoreRuleSet as new GOLD sponsor! The specialist for application and network security has been using CRS for a long time. Support from sponsors like @uspag is of great importance for open-source projects like CRS.
#crs#WAF
The CRS project has released version 4.6.0 for CRS 4 and version 3.3.6 for CRS 3.
The new releases tackle two multipart file upload bypass methods. All users are requested to update to the new releases.
Read more and get the new releases: coreruleset.org/20240829/crs-v…
Congratulations to @CoreRuleSet co-lead Felipe Zipitría, winner of this year's WASPY Award! "Project Person of the Year" – you earned it.
Don't know Felipe? Read here: coreruleset.org/20231130/meet-…
Congrats to the other winners Martin Knobloch and Shruti Kulkarni. And thanks to @owasp!
Congratulations to @CoreRuleSet co-lead Felipe Zipitría, winner of this year's WASPY Award! "Project Person of the Year" – you earned it.
Don't know Felipe? Read here: coreruleset.org/20231130/meet-…
Congrats to the other winners Martin Knobloch and Shruti Kulkarni. And thanks to @owasp!
The registration for the #OWASP CRS (@CoreRuleSet) community summit on Wednesday June 26 in Lisbon is open.
Free tickets, food and drinks throughout the day.
coreruleset.org/20240604/regis…
This is next door to the OWASP AppSec conference happening the same week.
The registration for the #OWASP CRS / @CoreRuleSet Community Summit in Lisbon on Wednesday June 26 is open.
This is next to the OWASP AppSec conference the same week and just across the street.
coreruleset.org/20240604/regis…
Meet the CRS team: Programming and entrepreneurship run in Jozef Sudolsky's family. When not working for his company or the @CoreRuleSet, he's in the gym or his garden. His office is his daughter's playroom. Read the portrait: coreruleset.org/20240507/meet-…#waf#crs#itsecurity#owasp
From the last @CoreRuleSet meeting: The team doesn't think it has the resources to maintain a fully hardened Apache/ModSecurity/CRS container. We'll fix a few things but probably leave a lot of the non-hardened settings on default. Agenda and decisions: github.com/coreruleset/co…
This is a bit of a portrait of the #OWASP#WAF projects I am co-leading.
Translation should be easy if you do not read German.
CC @CoreRuleSet, @ModSecurity
This is a bit of a portrait of the #OWASP#WAF projects I am co-leading.
Translation should be easy if you do not read German.
CC @CoreRuleSet, @ModSecurity
3K Followers 999 FollowingAuthor of the #ModSecurity Handbook 2ed, forme OWASP @CoreRuleSet project co-lead and trainer. Program chair @SwissCyberStorm and board National Cyber Strategy
213K Followers 532 FollowingWe improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
6 Followers 127 FollowingRecr uiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/JYFjIQii5d
775 Followers 595 FollowingCTO @sunstarmedia. Web applications developer (since '97) with a focus on ColdFusion/CFML, MSSQL & security/anti-abuse. Occasional blogger.
1K Followers 7K FollowingCyber Defence Consultancy, part of Microsoft for Startups Founders Hub, provides innovative and cutting-edge cybersecurity technology solutions.
540 Followers 7K FollowingFounder @cyberdefencecon | Cyber, Cloud & AI Security Advisor | Member of the NIST AI Cybersecurity COI | PeopleCert ITIL Ambassador | Published Author
50 Followers 114 FollowingFull-time father, Linux blogger and enthusiast , Neither a lefty nor a righty in my views about the world's politics or general views.
3K Followers 999 FollowingAuthor of the #ModSecurity Handbook 2ed, forme OWASP @CoreRuleSet project co-lead and trainer. Program chair @SwissCyberStorm and board National Cyber Strategy
213K Followers 532 FollowingWe improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
15K Followers 5 FollowingOfficial announcements (low vol) for ZAP by @Checkmarx - the worlds most popular web app scanner. Free and open source. https://t.co/pxO8zZ6usH
3K Followers 131 FollowingArea 41 security conference - 6-7.June 2024 - the technical security conference in the center of europe: Switzerland powered by DC4131
36K Followers 6K FollowingCircumstances do not determine state of being. State of being determines your circumstances. Tweets are my own not my employer. red/purple teaming, some DFIR
2K Followers 31 FollowingThe official Twitter home for the OSSEC Project. OSSEC is an open source host-based intrusion detection system. Visit us at https://t.co/f9JFQIAWhM.