Introducing AGHAST: AI-Guided Hybrid Application Static Testing
Introducing AGHAST, an open source framework that combines static discovery with AI prompts to find code-specific and company-specific security issues.
Introducing AGHAST, an open source framework that combines static discovery with AI prompts to find code-specific and company-specific security issues.
A guide on how to manage multiple GitHub accounts on a single Windows machine using 1Password and SSH host aliases, updated for 2026.
How I isolated Personal and Work Claude Code accounts on a single Windows machine by faking per-account home directories and a handful of symlinks.
This post is a rant about how many people in the security community are bad at communicating the actual risk of an issue .
Part of series: So you want to train at Black Hat (or other conferences)?
In this post, I talk through the preparations you will want to make before delivering the course.
Part of series: So you want to train at Black Hat (or other conferences)?
In this post, I talk through my experience of marketing the course and try and provide some pointers.
Part of series: So you want to train at Black Hat (or other conferences)?
In this post, I provide some ideas on how to write a convincing conference submission for your training course.
Part of series: So you want to train at Black Hat (or other conferences)?
In this post, I want to talk through my thought process for practical exercises for the participants to do rather than just listening to me.
Part of series: So you want to train at Black Hat (or other conferences)?
In this post, I want to talk about one of the key deciders of your course’s success - how you will differentiate it from everything else on the market.
Part of series: So you want to train at Black Hat (or other conferences)?
In this post, I want to talk through the financial aspects of training including expenses and effort to take into account and some thoughts on how different ...
Part of series: So you want to train at Black Hat (or other conferences)?
In this post I will give you some personal background about how I got into delivering public training courses and why.
This post discusses the recent changes in Semgrep, the creation of the Opengrep fork, and the implications for the open-source community.
Part of series: So you want to train at Black Hat (or other conferences)?
In this post I introduce this blog series and give you an overview of what it is about and why I wanted to write it.
In this post, I revisit my experiments with passkeys to see what has changed, what has improved, and what has stayed the same.
In this post, I highlight the crucial role of situational awareness in AppSec and how AppSec architects can leverage internal systems to gather vital informa...
Part of series: Fun with SQL injection in Prisma ORM!
Product Security continues to be hard. Sometimes even when you think you have the solution, reality bites back.
Part of series: Fun with SQL injection in Prisma ORM!
Product Security is hard. There are a huge number of different things you think about at the same time, while still being able to identify the most serious a...
Having an opportunity recently to consider recommending passkeys, I decided to experiment with a real life implementation.
A summary of five product security talks that are worth attending at Black Hat USA 2023.
A look at five interesting courses from Black Hat USA 2023, including one by the author.
A guide on how to manage multiple GitHub accounts on a single Linux/WSL machine, updated for 2023.
In 2022 I prepared a talk, aimed at non-security people working on building software such as developers and DevOps engineers. The aim was to introduce them t...
I am delivering training courses on how to build effective processes around application security scanning tools as part of my work for Bounce Security. The c...
A guide on how to set up and manage multiple GitHub accounts on a single Linux/WSL machine.
I recently had the privilege of attending and speaking at the OWASP AppSec USA 2018 conference in San Jose, California, one of OWASP’S global events. This w...
There are some great security technologies out there to act as a defensive layer in front of your application. However, if you want an efficient application ...
I recently used the very excellent OWASP Juice Shop application developed by the very excellent Björn Kimminich to run an internal Capture the Flag event (CT...
Some completely unofficial answers to questions about OWASP and the AppSecEU 2018 debacle based purely on publicly available information.
Whilst most people were preparing for the festive season, in a shock move OWASP decided to suddenly claw back its flagship conference from the hugely success...
For various reasons, this year was the first year I made it to OWASP AppSec Israel, the national Application Security conference here in Israel. Not only tha...
It looks like this standard will not go into widespread adoption but I think we can learn a lesson about InfoSec cost/benefit and the risks of expecting all ...
If you care about AppSec, you have until 30th August to have your say on what new items should be in RC2 and until 18th September to provide additional data ...
My thoughts on how daily reporting can both enhance and damage the security testing process.
Would MS17–010 have received enough attention without WannaCry?
Having made my long term thoughts on the OWASP Top 10 process clear, I want to talk about the list as it stands at the moment and how I think it should be fo...
Jeff Williams, OWASP Top 10 Co-Author and Contrast Security CTO, has responded but I am not convinced he has alleviated concerns.
The OWASP Top 10 has become web app critical infrastructure but do people understand how it is produced?