Open WAF Day Vienna 2026 recap is up 🇦🇹 Talks on the new Coraza/Envoy connector, blazing-fast WAF log analysis, Coraza Center + GitOps, life after Ingress NGINX, and CRS-powered adaptive honeypots. Thanks to everyone who joined us!
📖 coreruleset.org/20260629/open-…#OWASP#WAF#AppSec
Part 2 of the CRS 3→4 migration series: configuration. Don't reuse your old crs-setup.conf — variables were renamed, split, and added. Post includes a full checklist and an interactive migration tool.
coreruleset.org/20260406/migra…#OWASP#CRS#WAF#AppSec
Migrating from OWASP CRS 3.3 to 4.25 LTS? Part 1 of a 7-part series is out — covering what changed, what breaks, and how to plan your upgrade. ~500 changes, new plugin architecture, RE2/Hyperscan compat, and more.
coreruleset.org/20260330/migra…
🔒 Security Advisory: OWASP CRS file upload extension checks could be bypassed using whitespace padding in filenames (e.g. shell. php). CVE-2026-33691, Moderate severity.
Upgrade to CRS v4.25.0 or v3.3.9.
Thanks @HackingRepo for the report!
github.com/coreruleset/co…
OWASP CRS v4.25.0 LTS is out! First Long-Term Support for CRS 4 — stable foundation with security patches through Q3 2027. Formal backport policy, lessons from 3.3 applied, and crslang on the horizon.
coreruleset.org/20260321/annou…
🔥 OWASP CRS is evolving! Introducing #CRSLang — a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors.
Check it out 👉 coreruleset.org/20260122/intro…#WAF#AppSec#OWASP#ModSecurity
🎉 Introducing seclang_parser - a unified ANTLR-based parser for SecLang! One grammar, multiple languages (Go & Python), endless possibilities for WAF tooling: linters, IDE integration, config management & more.
🔗 coreruleset.org/20260122/intro…
CRS3→CRS4 migration made easy! 🚀
🧩 New GPL plugin lets you:
• Run CRS4 in monitor mode over CRS3
• Weed out false positives
• Gradually enable blocking or sampling
github.com/netnea/netnea-…#OWASP#CRS#Security
CRS will have its second community call on September 22, from 20:30 to 21:30 CEST (18:30 UTC / 2:30 p.m. ET) and will be moderated by former CRS co-leader Christian Folini. Check more details and register here: luma.com/8yc1p543
A critical vulnerability in Microsoft Sharepoint was recently discovered, allowing remote code execution -- in many cases, leading to persistence for the attackers, exfiltration of data, and more. Users of CRS were already covered from day zero using PL2.
CRS will have its first community call on March 17, from 20:30 to 21:30 CET (19:30 UTC / 2:30 p.m. ET) and will be moderated by former CRS co-leader Christian Folini. Register here: coreruleset.org/register/commu…
A somewhat diminished OWASP CRS core team at the annual developers retreat / the @owasp project summit 2024 in Woburn Forest (group photo without squirrels and deer).
Meet the CRS team: Whether it's work or hobbies, Max – the Kiwi-German software developer from the Swiss Alps – wants to enjoy what he does. For him, the most important thing about the CRS project is the people. Read his portrait: coreruleset.org/20240903/meet-…
We are excited to announce United Security Providers as Gold Sponsor of @CoreRuleSet. USP has been using CRS for a long time as an important component of its web access management solution. Support from sponsors is of great importance for the CRS project. coreruleset.org/20240903/unite…
3K Followers 981 FollowingAuthor of the #ModSecurity Handbook 2ed, forme OWASP @CoreRuleSet project co-lead and trainer. Program chair @SwissCyberStorm and board National Cyber Strategy
219K Followers 526 FollowingWe improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
129 Followers 1K FollowingAll opinions expressed are my own or Richard Feynman's. I do work in tech, but I'm also a theatre kid; we are each more than one thing. Keep the good
696 Followers 1K FollowingRandom medley of tweets about InfoSec, Chiang Mai // Thailand, American Sports, stupid memes, and Chicano Culture. Tweets are my views, not employers!
3K Followers 3K FollowingFocus on Linux/Kubernetes Attack/Detection/Forensics/Incident Response/Threat Hunting/Active Defense. Learning hard every single day.
1K Followers 2K FollowingFounder & CEO @LevoIncHQ
On a mission to help enterprises adopt AI securely. The digital world needs better security.
#AISecurity #AppSec #APISecurity
1 Followers 123 FollowingRecr uiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/JYFjIQii5d
3K Followers 981 FollowingAuthor of the #ModSecurity Handbook 2ed, forme OWASP @CoreRuleSet project co-lead and trainer. Program chair @SwissCyberStorm and board National Cyber Strategy
219K Followers 526 FollowingWe improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
15K Followers 5 FollowingOfficial announcements (low vol) for ZAP by @Checkmarx - the worlds most popular web app scanner. Free and open source. https://t.co/pxO8zZ6usH
3K Followers 130 FollowingArea 41 security conference - 6-7.June 2024 - the technical security conference in the center of europe: Switzerland powered by DC4131
36K Followers 6K FollowingCircumstances do not determine state of being. State of being determines your circumstances. Tweets are my own not my employer. red/purple teaming, some DFIR
2K Followers 31 FollowingThe official Twitter home for the OSSEC Project. OSSEC is an open source host-based intrusion detection system. Visit us at https://t.co/f9JFQIAWhM.