Josh Grossman (tghosth ๐Ÿ‘ป)'s Avatar

Josh Grossman (tghosth ๐Ÿ‘ป)

@joshcgrossman.com.bsky.social

Friendly AppSec Ghost ๐Ÿ‘ป https://appsecg.host

1,239 Followers  |  431 Following  |  138 Posts  |  Joined: 01.07.2023  |  1.9516

Latest posts by joshcgrossman.com on Bluesky

Post image Post image Post image

Excited to be back delivering my course again at Black Hat USA!

05.08.2025 00:28 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Making your preparations | Bounce Security Introduction

In "Making your preparations" I discuss some of the preparations you might need in the run-up to the course including materials and visa considerations.

Although visas are one of the last things I mention, it might be one of the first things to consider.
www.bouncesecurity.c...

17.07.2025 11:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Selling and Marketing your course | Bounce Security Introduction

In "Selling and Marketing your course", I talk about possibly the hardest part of the whole process, getting people to sign-up! I don't have all the answers but hopefully I have some ideas and thoughts that will be useful to you.
www.bouncesecurity.c...

17.07.2025 11:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

The final two parts of my blog series about delivering training at conferences have now been released!

You can check them out on the @BounceSecurity website now!

17.07.2025 11:30 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Most passkey implementations are tripping over themselves to fall back to sending you an email OTP as fast as possible...

Passkeys are for UX, not for security

02.07.2025 05:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
OWASP Cornucopia - Threat modeling for everyone everywhere - Don't gamble with your security play games with it OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, ...

cornucopia.owasp.org

@sydseter.com is probably one of the local experts :)

24.06.2025 18:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Black Hat Black Hat

Sign-up here:
www.blackhat.com/us-25/traini...

More information about the course:
www.bouncesecurity.com/training/acc...

24.06.2025 09:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Pulled last year's class workbook out so that I can prepare the updated version for this year.

You still have time to sign up for my updated course at @blackhatofficial.bsky.social #BHUSA, in person in Las Vegas, August 4-5.

24.06.2025 09:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
So, you want to train at Black Hat (or other conferences)? An Introduction | Bounce Security Efficient, Value-Driven Product Security

You can find the whole series here:
www.bouncesecurity.c...

12.06.2025 11:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

So you have a great training course with super-cool interactivity, now you have to get it accepted.

In my next blogpost, I talk about writing a proposal which appeals to both the review board and also your potential attendees.

Check it out here:
www.bouncesecurity.c...

12.06.2025 11:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image Post image Post image

Last week, I was honoured to received a Distinguished Lifetime Member award from OWASP at Global AppSec EU Barcelona 2025.

I wrote more about it here:
www.linkedin.com/pos...

11.06.2025 18:24 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

So @ElarLang just published version 5.0.0 of OWASP ASVS, live on stage at @OWASP Global AppSec EU Barcelona 2025!

30.05.2025 10:06 โ€” ๐Ÿ‘ 12    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
Post image

In October, 2021, we released 4.0.3 of the OWASP ASVS Standard. This release marked the start of the Vanilla Ice (or 5.0 as everyone else called it) release.

A major rethink about how we use the standard and with feedback from the community.

30.05.2025 09:38 โ€” ๐Ÿ‘ 7    ๐Ÿ” 2    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Video thumbnail

Last week to save before prices go up on 23rd May!

Unless you Accelerate your AppSec Programme, you are going to get left behind..

Join me @blackhatofficial.bsky.social #BHUSA this summer in Las Vegas (4-5 Aug) for a practical guide on how to build bridges with developers and build securely!

19.05.2025 12:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Welcome @blackhatofficial.bsky.social ๐Ÿ™‚

You should probably report this account for impersonation though...

bsky.app/profile/blac...

13.05.2025 19:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

The #BHUSA Early Registration Rate ends May 23rd! Register today to lock-in the lowest rate before it increases. Register here >> bit.ly/4jnXIa5

#BHUSA #Cybersecurity

12.05.2025 18:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

The #BHUSA 2025 Early Registration rate ends MAY 23! Secure your spot today at the lowest rates available>> bit.ly/4l9aYRH

08.05.2025 16:08 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Planning the Practical | Bounce Security Introduction

Link to the new post is here and don't forget to check out my other posts in this series "So you want to train at Black Hat (or other conferences)?"

www.bouncesecurity.c...

#BlackHat #Training #OWASP #AppSec

13.05.2025 08:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Want to make your security training course memorable? ๐ŸŽฏ

My latest post dives into creative ways to get students' hands dirty, from cloud-hosted labs to simulated stakeholder exercises. Learn how to make practical exercises the highlight of your course, not just an afterthought.

13.05.2025 08:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Finding your niche/selling point | Bounce Security Introduction

My blog series on developing training courses continues with a post about how to find the topic you are passionate about and that will also attract attendees:

www.bouncesecurity.c...

21.04.2025 12:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The bat-shit insane stories coming out of the US government this week is quite something

09.04.2025 23:56 โ€” ๐Ÿ‘ 18    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

You can see the previous posts in this series here:

01.04.2025 06:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

So, you've decided you want to deliver training courses at a conference?

In the next post in my series about my experiences, I want to talk about money. I don't think it should be your main motivation but you probably can't ignore it!

Check it out:
www.bouncesecurity.c...

01.04.2025 06:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
ASVS/CONTRIBUTING.md at master ยท OWASP/ASVS Application Security Verification Standard. Contribute to OWASP/ASVS development by creating an account on GitHub.

You can find out details in our contribution guide:
github.com/OWASP/ASV...

Alternatively, get in contact with us via OWASP Slack:
owasp.slack.com/arch...

Have your say now! Submit early to avoid disappointment ๐Ÿ˜€


2/2

31.03.2025 15:40 โ€” ๐Ÿ‘ 5    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ“ฏYOUR INPUT IS NEEDED!๐Ÿ“ฏ

@OWASP ASVS version 5.0 release candidate is ready for review.

The final version is planned for the end of May. We want your feedback before then!

Can devs understand it? How about testers? Anything missing?

Dive into GitHub and let us know!

1/2

31.03.2025 15:40 โ€” ๐Ÿ‘ 7    ๐Ÿ” 5    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

I will be publishing the next post in this series tomorrow so look out for it!

31.03.2025 12:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image

This year should hopefully be the 3rd year that I train at @BlackHatEvents #BHUSA and also at @OWASP #AppSecEU?

But how did I get to this stage?

The short answer is a lot of thought and hard work.

And the long answer?

Well I thought I'd write some thoughts down...

๐Ÿงต 1/x

24.03.2025 11:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 2
Post image

๐Ÿš€ Join Us as a Volunteer for OWASP AppSecIL!๐Ÿš€

Weโ€™re gearing up for the OWASP Israel Conference in June 2025, and we need YOUR help to make it a success!

If youโ€™re passionate about cybersecurity, networking, and community-driven events, this is your chance to get involved.
1/5

26.03.2025 16:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
What is my motivation? What should your motivation be? | Bounce Security Efficient, Value-Driven Product Security

In the second post, I talk about my motivation behind getting to this stage. This wasn't an any easy process and it took a lot of work to get to the required level.

If this is something you are considering doing, you need to be ready to commit.

www.bouncesecurity.c...

๐Ÿงต4/x

24.03.2025 11:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
So, you want to train at Black Hat (or other conferences)? An Introduction | Bounce Security Efficient, Value-Driven Product Security

In the first post I explain a little more about the rationale behind the series and the sorts of topics I will be covering.

Feel free to reach out to me if you have questions on specific topics or other ideas ๐Ÿ˜€

www.bouncesecurity.c...

๐Ÿงต3/x

24.03.2025 11:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@joshcgrossman.com is following 20 prominent accounts