Category: Mix

[tl;dr sec] #303 - MCP Security Scanners, Attacking GitLab CI/CD, AI SOC Benchmarks
30
Oct
2025

[tl;dr sec] #303 – MCP Security Scanners, Attacking GitLab CI/CD, AI SOC Benchmarks

I hope you’ve been doing well! Fight Robots Fight! New #PeakBayArea experience: this week I attended a TechCrunch Disrupt-adjacent event…

Business Logic Abuse — Exploiting the Rules of the Game — API Security
29
Oct
2025

Business Logic Abuse — Exploiting the Rules of the Game — API Security

As Cybersecurity Awareness Month continues, we wanted to dive even deeper into the attack methods affecting APIs. We’ve already reviewed…

29
Oct
2025

Humans Need Entropy | Daniel Miessler

I’ve had several thoughts on the Karpathy and Dwarkesh conversation that took place in late October 2025. But the one…

The API vulnerabilities nobody talks about: excessive data exposure
28
Oct
2025

The API vulnerabilities nobody talks about: excessive data exposure

TLDR: Excessive Data Exposure (leaking internal data via API responses) is the silent, pervasive threat that is more dangerous than…

Cyber Awareness Month: Vulnerabilities beware this Halloween
27
Oct
2025

Cyber Awareness Month: Vulnerabilities beware this Halloween

We couldn’t let Cybersecurity Awareness Month slip by without posting a bit of a fun blog on the topic, with…

[tl;dr sec] #302 - LLM Honeypot Catches Threat Actor, Supply Chain Compromise Survey, AI-powered Malware
23
Oct
2025

[tl;dr sec] #302 – LLM Honeypot Catches Threat Actor, Supply Chain Compromise Survey, AI-powered Malware

CAB This week Semgrep had our Customer Advisory Board (CAB), where I got to hang out with and learn from…

New API testing category now available 
23
Oct
2025

New API testing category now available 

Our API scanner can test for dozens of vulnerability types like prompt injections and misconfigurations. We’re excited to share today…

Intigriti partners with Shield to empower security within healthcare
23
Oct
2025

Intigriti partners with Shield to empower security within healthcare

Antwerp, Belgium, Oct. 23, 2025.  Intigriti, a global crowdsourced security provider, is delighted to announce its latest partnership with non-profit Shield…

Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI | Blog
22
Oct
2025

Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI | Blog

Amelia Coen | 22 October 2025 at 13:15 UTC In her latest video, CyberMaddy dives into the world of AI-driven…

Hacking smarter with Burp AI: NahamSec puts Burp AI to the test | Blog
22
Oct
2025

Burp AI takes on a vulnerable web app: watch Tib3rius put Burp’s new agentic capabilities to the test | Blog

Amelia Coen | 22 October 2025 at 12:59 UTC What happens when you set Burp AI loose on a deliberately…

AWS Outage: Lessons Learned —
22
Oct
2025

AWS Outage: Lessons Learned —

What can we learn from the recent AWS outage, and how can we apply those lessons to our own infrastructure?…

Key API Security Takeaways from the Postman 2025 State of API Report — API Security
21
Oct
2025

Key API Security Takeaways from the Postman 2025 State of API Report — API Security

API security has never been more important because modern APIs are operational necessities. Unfortunately, many organizations are failing to adapt…