Subscribe
Sign in
Home
Archive
About
Latest
Top
Why you can’t tell your applications are “OWASP certified”
..but still you have the tools to make them much more secure
Jan 17, 2024
•
Davide Ariu
Share this post
Unboxed AppSec
Why you can’t tell your applications are “OWASP certified”
Copy link
Facebook
Email
Notes
More
About the Common Vulnerability Scoring System (a.k.a. CVSS) 4.0
What’s new with the new version of the vulnerability risk severity calculator
Jan 2, 2024
•
Davide Ariu
1
Share this post
Unboxed AppSec
About the Common Vulnerability Scoring System (a.k.a. CVSS) 4.0
Copy link
Facebook
Email
Notes
More
October 2023
Well beyond the OWASP Top 10: the OWASP Application Security Verification Standard
Reasons why the Top 10 does not suffice to verify applications' security and to adopt ASVS instead.
Oct 24, 2023
•
Davide Ariu
Share this post
Unboxed AppSec
Well beyond the OWASP Top 10: the OWASP Application Security Verification Standard
Copy link
Facebook
Email
Notes
More
Your vulnerability must be not my vulnerability
An overview of the OWASP Software Component Verification Standard for the prevention of software supply chain attacks.
Oct 12, 2023
•
Davide Ariu
2
Share this post
Unboxed AppSec
Your vulnerability must be not my vulnerability
Copy link
Facebook
Email
Notes
More
The rise and fall of ModSecurity and the OWASP Core Rule Set (thanks, respectively, to robust and adversarial machine learning)
Adversarial ModSecurity: Countering Adversarial SQL Injections with Robust Machine Learning
Oct 3, 2023
•
Davide Ariu
1
Share this post
Unboxed AppSec
The rise and fall of ModSecurity and the OWASP Core Rule Set (thanks, respectively, to robust and adversarial machine learning)
Copy link
Facebook
Email
Notes
More
September 2023
Evaluating AppSec solutions: from theory to practice
How to benchmark properly your *AST tools
Sep 26, 2023
•
Davide Ariu
Share this post
Unboxed AppSec
Evaluating AppSec solutions: from theory to practice
Copy link
Facebook
Email
Notes
More
Six Areas to monitor to improve Your Vulnerability Management Programme
All ready-to-use KPIs you need to start effective monitoring and continuous improvement.
Sep 19, 2023
•
Davide Ariu
Share this post
Unboxed AppSec
Six Areas to monitor to improve Your Vulnerability Management Programme
Copy link
Facebook
Email
Notes
More
“Follow the trend lines, not the headlines”.
Indicators to look at in a vulnerability management-related decision-making process.
Sep 12, 2023
•
Davide Ariu
Share this post
Unboxed AppSec
“Follow the trend lines, not the headlines”.
Copy link
Facebook
Email
Notes
More
Vulnerability Management: a CSIRT perspective
What Vulnerability Management is about (explained with the support of the CSIRT Services Framework)
Sep 5, 2023
•
Davide Ariu
Share this post
Unboxed AppSec
Vulnerability Management: a CSIRT perspective
Copy link
Facebook
Email
Notes
More
May 2023
Why isn’t CVSS a Good indicator for a Vulnerability Management Program?
Vulnerability management is one of the cornerstones of a cyber risk mitigation strategy.
May 30, 2023
•
Davide Ariu
Share this post
Unboxed AppSec
Why isn’t CVSS a Good indicator for a Vulnerability Management Program?
Copy link
Facebook
Email
Notes
More
(a) Vulnerability is what happens to you while you are busy making other plans
About the lifetime of vulnerabilities in software development projects
May 16, 2023
•
Davide Ariu
Share this post
Unboxed AppSec
(a) Vulnerability is what happens to you while you are busy making other plans
Copy link
Facebook
Email
Notes
More
About the insecurity of Content Management System Plugins
YODA is a name that evokes pleasant memories for many...
May 16, 2023
•
Davide Ariu
Share this post
Unboxed AppSec
About the insecurity of Content Management System Plugins
Copy link
Facebook
Email
Notes
More
Share
Copy link
Facebook
Email
Notes
More
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts