ZAP Updates - July 2025
Authentication improvements, Edge support, timing rule changes, Docker news, and a new scan rule.
www.zaproxy.org/blog/2025-08...
#zaproxy #appsec
@psiinon.bsky.social
ZAP Project Lead
ZAP Updates - July 2025
Authentication improvements, Edge support, timing rule changes, Docker news, and a new scan rule.
www.zaproxy.org/blog/2025-08...
#zaproxy #appsec
Yesterday there were more than 25K ZAP scans run using old versions of ZAP. These are no longer being maintained.
Update your ZAP installs now!
#zaproxy #appsec
We will be deleting all of the ZAP Docker images from the Software Security Project Docker Hub within the next 2 weeks. If you are still pulling images from there then please switch to one of the maintained options: www.zaproxy.org/download/#do...
28.07.2025 10:17 β π 5 π 2 π¬ 1 π 0There is a new "ZAP is Out of Date" scan rule - learn more about it via this blog post
www.zaproxy.org/blog/2025-07...
#zaproxy #appsec
We've recently made some requested changes to the naming and implementation of scan rules which used Time Based attacks. @kingthorin.bsky.social has written about it here: www.zaproxy.org/blog/2025-07...
#zaproxy #appsec
Here's an idea.
Corporation tax currently taxes profits.
Instead tax profits divided by the total wage bill of all those who's pay is below the median pay for the company.
www.bbc.co.uk/news/article...
None of the major browsers are currently flagging the latest ZAP downloads as suspiciousπ
Thank you to whoever sorted that out!
ZAP now has full support for Microsoft Edge π
www.zaproxy.org/blog/2025-07...
#zaproxy #appsec
As promised, here is the first set of documentation for all of the authentication improvements the team has been working on
www.zaproxy.org/blog/2025-07...
#zaproxy #appsec
ZAP updates for June:
A new Intro video, lots of authentication work, and more news on the ZAP browser extensions.
www.zaproxy.org/blog/2025-07...
#zaproxy #appsec
All of the main browsers flag ZAP as dangerous/potential malware, and there doesnt see to be anything we can do about it.
We've updated the Download page www.zaproxy.org/download/
Still unsure of what ZAP does?
See this video..
youtu.be/yywD8ebNn6o
#zaproxy #dast #appsec
Introducing the Top 10 @owasp.org Top 10s!
github.com/psiinon/owas...
Mega add-on update alert!
We've just upload loads of add-ons, so update your ZAP instances ASAP.
Lots of authentication improvements have been included, more details coming soon ...
We have started to document how to configure ZAP against well known vulnerable apps: www.zaproxy.org/docs/testapps/ Let @psiinon.bsky.social know if you have any feedback or specific requests
10.06.2025 15:06 β π 8 π 3 π¬ 0 π 1Looks like its this github.com/seleniumbase...
06.06.2025 10:48 β π 0 π 0 π¬ 0 π 0The latest version of Chrome no longer loads extension added via @seleniumhq.bsky.social π
Has anyone else seen this, or have a workaround?
www.zaproxy.org/docs/getting...
#zaproxy #appsec
Heres what the ZAP team have been working on during April www.zaproxy.org/blog/2025-05...
06.05.2025 14:24 β π 7 π 2 π¬ 0 π 0We just released v17.3.0! It brings Juice Shop to #Angular 19, fixes the non-default theme colors, and adds a convenient search filter to the language selection! Full release notes: github.com/juice-shop/j...
22.04.2025 22:24 β π 11 π 6 π¬ 0 π 0I've just added github.com/al-sultani/p... to github.com/psiinon/open...
29.04.2025 08:28 β π 2 π 0 π¬ 0 π 0ZAP just won an award! Thanks DefectDojo!
www.zaproxy.org/blog/2025-04...
#zaproxy #appsec #award
113 years ago tonight, the Titanic struck an iceberg, as a result of hubris, greed and denial. It wouldnβt happen now, of course, as all the icebergs seem to be melting. For the same reasons.
14.04.2025 08:43 β π 74 π 19 π¬ 3 π 0Now that the performance of #owasp #wrongsecrets is restored (200rps on a Heroku free Dyno) feel free to use #zap against it ;-).
13.04.2025 06:47 β π 1 π 1 π¬ 0 π 0I have created a free, downloadable, secure coding guideline (22 pages), from my new book, Alice and Bob Learn Secure Coding. You can download it, and sign up for my newsletter, at the link below. Feel free to adopt it at work!
newsletter.shehacksp...
Big thanks to
@psiinon.bsky.social @kingthorin.bsky.social and all
@zaproxy.org contribs for your work on #ZAP #zaproxy. Amazing #infosec #Pentesting tool. Huge thanks to @checkmarxzero.bsky.social & @crashappsec.bsky.social for supporting this important project. #WebAppSec #AppSec
New ZAP blog post c/o Jemimah O www.zaproxy.org/blog/2025-04...
#zaproxy #appsec
Brexit was the UK shooting itself in the foot.
We're about to see what happens after the USA has just shot itself in both feet.
π―YOUR INPUT IS NEEDED!π―
@OWASP ASVS version 5.0 release candidate is ready for review.
The final version is planned for the end of May. We want your feedback before then!
Can devs understand it? How about testers? Anything missing?
Dive into GitHub and let us know!
1/2
The monthly ZAP Update Blog Post: www.zaproxy.org/blog/2025-04...
#zaproxy #appsec