Welcome to my blog about (ethical) hacking and information security! Please see the about page for more information.
Recent Posts
OWASP Dependency-Track v5.0.3 released
OWASP Dependency-Track keeps track of what’s inside your software. Feed it an SBOM and it flags known vulnerabilities and policy violations component by component, then plugs into whatever security and dev tooling you already run.
OWASP DockSec v2026.7.4 and v2026.7.5 Released
DockSec is an OWASP Lab Project that bridges the gap between complex Docker security scan results and actionable fixes.
OWASP CVE Lite CLI Graduates to Lab Project Status
OWASP CVE Lite CLI is a fast, open source dependency vulnerability scanner for JavaScript and TypeScript projects.
oproxy v0.1.10 released
oproxy is an open-source local proxy server for inspecting, replaying, and modifying HTTP, HTTPS, and SOCKS5 traffic. Built in Rust with a JavaScript frontend, it supports request breakpoints, traffic rules, Lua scripting, mock responses, DNS overrides, and an AI assistant via any OpenAI-compatible model.
Bruno v3.5.2 released
If you’re testing APIs and want to stay away from cloud-synced tools, Bruno is worth a look - an open-source client that stores collections as plain files on disk instead of locking them into an account.