Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
www.zaproxy.org/blog/2026-02...
#zaproxy #appsec #cyberchef
Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
www.zaproxy.org/blog/2026-02...
#zaproxy #appsec #cyberchef
New Blog Post: Detecting Circular Type References in GraphQL Schemas
www.zaproxy.org/blog/2026-02...
#zaproxy #appsec #graphql
New blog post: www.zaproxy.org/blog/2026-02...
Highlights of 2025 and our initial plans for 2026, including more 3rd Party tool integrations, enhanced exploring and, yes, AI integration!
#zaproxy #appsec #ai
We have made a good start on #AI integration in @zaproxy.org
We know some of you will be very anti-AI, so this will be optional and opt-in.
We have lots of plans, but feedback also appreciated - what integrations would you really like to see .. or not see?
www.zaproxy.org/blog/2026-01...
#zaproxy #owasp #appsec
New โGetting Further with ZAP Scriptingโ pages: www.zaproxy.org/docs/getting...
Looking for something more? Let @psiinon.bsky.social know!
Dear Open Source contributors: If your AI spent X mins on "enhancement" or "refactorings" but the project maintainer needs >X mins to fix guideline violations and broken code, you didnโt contributeโyou drained time and motivation from Open Source maintainers.
infosec.exchange/@bkimminich/...
ZAP 2.17.0 is now available!
It includes performance improvements, a significant reduction in โduplicateโ alerts reported, and new Insights which give you key information about scans.
www.zaproxy.org/blog/2025-12...
#zaproxy #appsec
New blog post: #React2Shell Detection with ZAP
www.zaproxy.org/blog/2025-12...
#zaproxy #appsec
The latest version of the retirejs add-on includes a test for CVE-2025-66478 which is marked as "critical" so update now to detect this vulnerability.
04.12.2025 12:26 โ ๐ 4 ๐ 2 ๐ฌ 0 ๐ 0
ZAP Updates for November 2025:
www.zaproxy.org/blog/2025-12...
2.17.0 is coming soon, along with Insights and fixes for some issues that caused ZAP to log 50 million errors in one day!
#zaproxy #appsec
New ZAP blog post - read how Telmon Maluleka is enhancing ZAP with AI for Bug Bounty Hunting
www.zaproxy.org/blog/2025-11...
ZAP logged 50 MILLION errors yesterday ๐ฎ Read the blog for more details!
www.zaproxy.org/blog/2025-11...
#zaproxy #appsec
Todayโs weekly is the 2.17 Release Candidate! github.com/zaproxy/zapr...
Feedback appreciated
The ZAP services may well be unavailable due to the ongoing Cloudflare problems.
See www.cloudflarestatus.com for more information.
ZAP Updates for October:
www.zaproxy.org/blog/2025-11...
#zaproxy #appsec
We have just published a new ZAP weekly release, to fix a bug which could cause invalid JSON reports to be generated. If you are using the most recent weekly we recommend you update ASAP.
29.10.2025 14:50 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Sorry, we messed up!
A new scan rule triggered the ZAP Check for Updates call even if you used the "silent" mode.
For more details see www.zaproxy.org/blog/2025-10...
ZAP updates for September:
www.zaproxy.org/blog/2025-10...
#zaproxy #appsec
New blog post: Alert De-Duplification
www.zaproxy.org/blog/2025-09...
#zaproxy #appsec
๐ฅ Want to level up your ZAP game?
The @zaproxy.org team has an awesome library of how-tos, demos, and deep dives โ all free.
From beginner basics to advanced scripting, itโs all here:
๐ zaproxy.org/videos/
#YouDontKnowZAP
The ZAP team has forked and will maintain WAVSEP going forwards. This blog post explains why.
www.zaproxy.org/blog/2025-09...
#zaproxy #appsec #wavsep
You can now configure ZAP Scan Policies using Alert Tags:
www.zaproxy.org/blog/2025-09...
#zaproxy #appsec
ZAP Updates - August 2025:
www.zaproxy.org/blog/2025-09...
Microsoft Online Login Support, forking wavsep and much, much more!
#zaproxy #appsec
All of the translated ZAP help files on the Marketplace have been updated. Thanks to the Crowdin translators for their hard work!
crowdin.com/project/zap-...
We have a new #evangelists channel on the ZAP Slack: www.zaproxy.org/slack/
For an invite go to www.zaproxy.org/slack/invite
Join up and help spread the word about #zaproxy !
All of the ZAP Docker images in the Software Security Project Docker Hub org have now been deleted.
If you were pulling from this org then please switch to the zaproxy org or use GHCR as per www.zaproxy.org/download/#do...
#zaproxy #appsec
ZAP Updates - July 2025
Authentication improvements, Edge support, timing rule changes, Docker news, and a new scan rule.
www.zaproxy.org/blog/2025-08...
#zaproxy #appsec
Yesterday there were more than 25K ZAP scans run using old versions of ZAP. These are no longer being maintained.
Update your ZAP installs now!
#zaproxy #appsec
We will be deleting all of the ZAP Docker images from the Software Security Project Docker Hub within the next 2 weeks. If you are still pulling images from there then please switch to one of the maintained options: www.zaproxy.org/download/#do...
28.07.2025 10:17 โ ๐ 5 ๐ 2 ๐ฌ 1 ๐ 0