<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>OWASP on Aby George</title><link>https://abygeorgea.com/categories/owasp/</link><description>Recent content in OWASP on Aby George</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 01 Jul 2025 08:25:31 +1000</lastBuildDate><atom:link href="https://abygeorgea.com/categories/owasp/index.xml" rel="self" type="application/rss+xml"/><item><title>Dependency and Secrets Scanning: Closing the Gap ZAP Doesn't Cover</title><link>https://abygeorgea.com/blog/2025/07/01/dependency-and-secrets-scanning-in-cicd/</link><pubDate>Tue, 01 Jul 2025 08:25:31 +1000</pubDate><guid>https://abygeorgea.com/blog/2025/07/01/dependency-and-secrets-scanning-in-cicd/</guid><description>Wiring dependency vulnerability scanning and secrets scanning into CI, catching supply chain and credential leak risks that API level testing never sees.</description></item><item><title>Automating Security Regression with OWASP ZAP in CI/CD</title><link>https://abygeorgea.com/blog/2025/06/17/automating-security-scans-with-owasp-zap/</link><pubDate>Tue, 17 Jun 2025 08:25:31 +1000</pubDate><guid>https://abygeorgea.com/blog/2025/06/17/automating-security-scans-with-owasp-zap/</guid><description>Wiring OWASP ZAP&amp;#39;s baseline and full scans into a CI pipeline, and triaging findings without drowning the team in false positives.</description></item><item><title>Testing Authentication and Excessive Data Exposure in REST APIs</title><link>https://abygeorgea.com/blog/2025/06/03/testing-authentication-and-data-exposure-in-apis/</link><pubDate>Tue, 03 Jun 2025 08:25:31 +1000</pubDate><guid>https://abygeorgea.com/blog/2025/06/03/testing-authentication-and-data-exposure-in-apis/</guid><description>Practical test cases for broken authentication and excessive data exposure, two of the more common OWASP API Security risks in Java REST APIs.</description></item><item><title>Testing for Broken Object Level Authorization (BOLA)</title><link>https://abygeorgea.com/blog/2025/05/20/testing-broken-object-level-authorization/</link><pubDate>Tue, 20 May 2025 08:25:31 +1000</pubDate><guid>https://abygeorgea.com/blog/2025/05/20/testing-broken-object-level-authorization/</guid><description>Writing practical test cases for Broken Object Level Authorization, the top ranked OWASP API Security risk, against a Java REST API.</description></item><item><title>Inside the OWASP API Security Top 10</title><link>https://abygeorgea.com/blog/2025/05/06/owasp-api-security-top-10-overview/</link><pubDate>Tue, 06 May 2025 08:25:31 +1000</pubDate><guid>https://abygeorgea.com/blog/2025/05/06/owasp-api-security-top-10-overview/</guid><description>Why the OWASP API Security Top 10 exists as a separate list from the general OWASP Top 10, and what it covers at a glance.</description></item></channel></rss>