One PUT Request to Own Tomcat: CVE-2025-24813 RCE is in the Wild

A devastating new remote code execution (RCE) vulnerability, CVE-2025-24813, is now actively exploited in the wild. Attackers need just one PUT API request to take over vulnerable Apache Tomcat servers. The exploit, ...
OWASP Top 10 Risk & Mitigations for LLMs and Gen AI Apps 2025

OWASP Top 10 Risk & Mitigations for LLMs and Gen AI Apps 2025

| | owasp
The rapid advancement of AI, particularly in large language models (LLMs), has led to transformative capabilities in numerous industries. However, with great power comes significant security challenges. The OWASP Top... The post ...
OWASP Mobile Top 10 Vulnerabilities [2024 Updated]

OWASP Mobile Top 10 Vulnerabilities [2024 Updated]

With over 6.8 billion smartphone users worldwide and mobile apps accounting for 70% of digital interactions, securing mobile applications is more critical than ever. In 2023 alone, mobile app vulnerabilities... The post ...
Tanya Janca on Secure Coding, AI in Security, and Her New Book!

Tanya Janca on Secure Coding, AI in Cybersecurity, and Her New Book

Join us for an insightful episode of the Shared Security Podcast as Tanya Janca returns for her fifth appearance. Discover the latest on her new book about secure coding, exciting updates in ...
™

How to Comply with the OWASP MASVS Standard

Appdome How to Comply with the OWASP MASVS Standard The OWASP MASVS (Mobile Application Security Verification Standard) is a standard that establishes mobile app security requirements for developers to build secure mobile ...
2024 OWASP Mobile Top Ten Risks

2024 OWASP Mobile Top Ten Risks

What is OWASP MASVS? In case you didn't notice, the OWASP Mobile Top 10 List was just updated, for the first time since 2016! This is important for developers since this list ...
2024 OWASP Mobile Top Ten Risks

2024 OWASP Mobile Top Ten Risks

In case you didn't notice, the OWASP Mobile Top 10 List was just updated, for the first time since 2016! This is important for developers since this list represents the list of ...

What is API Security Testing?

| | API security, owasp
In short, API security testing involves the systematic assessment of APIs to identify vulnerabilities, coding errors, and other weaknesses that could be exploited by malicious actors. Application Programming Interfaces, or APIs, provide ...