CGISecurity Logo
  • Announcing WASC Web Hacking Incident Database (WHID) Mail-list

    Ryan Barnett (Leader of the WASC Web Hacking Incidents Database Project) has announced a new mailing list where users can subscribe to hear about the latest hacking incidents. From his email to The Web Security Mailing List "Greetings everyone,I wanted to let everyone know that we have setup a mail-list for those of you who…

  • WASC Party at RSA

    The Web Application Security Consortium (in which I am a co founder) is throwing a party at RSA this year in San Francisco. Here's the formal announcement.   "Take a Break @ RSA and Meet-up with Your Peers at the WASC Meet UP Join your Web application security peers for lunch at  Jillian's@Metreon. Take a…

  • Tracking and understanding security related defects: Useful data points for shaping your SDLC program

    In addition to CGISecurity, I also run a website called QASEC.com where I post SDLC related content. I've just published a lightweight article discussing tips and tricks for tracking software level vulnerabilities in larger organizations. Abstract:"If you work in infosec for a large organization it can be difficult to easily track the state of every…