@7aSecurityi
iAccount based inIndia
About this account
- Account based in
- India
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Quality Pentests & Code Audits - https://nitter.cf/t.co/azFFi8B79m Top notch Security Training: https://nitter.cf/t.co/fzKW1Zbpfk OWASP OWTF - https://nitter.cf/t.co/v6tlQiacBK
Dublin, Ireland
Joined February 2015
- Tweets1.4K
- Following368
- Followers2K
- Likes741
π¨ OWASP's LLM Top 10 changed for 2026.
π€ Prompt injection
π Data exposure
β‘ Excessive agency
β οΈ Model poisoning
Knowing the risks isn't enough. Can your AI actually withstand them?
π 7asecurity.com/blog/2026/09/β¦
#AISecurity #OWASP #LLM
π’ New 7ASecurity public #SecurityAudit report
π Bayanat audited by 7ASecurity: 43 findings & recommendations, all resolved & verified. β
π 7asecurity.com/blog/2026/09/β¦
π¬ Feedback welcome
#CyberSecurity #OpenSourceSecurity #AppSec #InfoSec #Bayanat
π€ AI red teaming β AI pentesting.
π Pentesting finds vulnerabilities.
π― Red teaming tests whether an attacker can achieve a goal without getting caught.
Which does your AI system need?
π 7asecurity.com/blog/2026/09/β¦
#AISecurity #RedTeam
π Your API worksβbut is it secure?
π API pentesting digs into auth, access control, hidden endpoints & business logic flaws, with findings mapped to the OWASP API Top 10.
π 7asecurity.com/blog/2026/09/β¦
#APISecurity #PenTesting
π’ New 7ASecurity public #SecurityAudit report
π Incus audited by 7ASecurity: 14 vulnerabilities found, all resolved & verified. β
7asecurity.com/blog/2026/09/β¦
π¬ Feedback welcome
@sovtechagency
#CyberSecurity #OpenSourceSecurity #ContainerSecurity #infosec #Incus
βοΈ Cloud pentesting isn't just network testing in the cloud.
π IAM, storage, serverless functions & trust relationships can expose attack paths scanners miss.
π 7asecurity.com/blog/2026/08/β¦
#CloudSecurity #PenTesting #InfoSec
π€ LLM pentesting goes beyond testing what the model says.
π Prompt injection
π Data leakage
π οΈ Tool abuse
π€ Excessive agency
Our checklist covers what to test across LLMs, agents & integrations.
π 7asecurity.com/blog/2026/08/β¦
#AISecurity #InfoSec
π± Porto, ready for some mobile hacking? π΅πΉ
π₯ 4h hands-on Android & iOS workshop with Abraham Aranguren at #OWASP AppSec Days Portugal.
βοΈ Real attacks. Real pentest cases. Practical exercises.
ποΈ appsecdays.pt/trainings/mobiβ¦
#MobileSecurity #AppSec
π A pentest shouldnβt end when the report arrives.
From scoping π to testing, reporting π and fix verification β
, hereβs what you should expect from the full process.
π 7asecurity.com/blog/2026/08/β¦
#CyberSecurity #PenTesting #InfoSec
π What happens after you book a pentest?
From scoping and testing to reporting, remediation, and retesting, hereβs what to expect from the full process. π
π 7asecurity.com/blog/2026/08/β¦
#CyberSecurity #PenTesting #InfoSec
π‘οΈ Not all pentest services are the same.
π Learn which security assessment fits your situationβfrom web apps and cloud to AI, code audits, and internal testing.
π 7asecurity.com/blog/2026/07/β¦
#CyberSecurity #PenTesting #InfoSec
π Which security compliance standards apply to your business?
π Learn the differences between ISO 27001, SOC 2, GDPR, PCI DSS, HIPAA, NIST CSF, and more.
π 7asecurity.com/blog/2026/07/β¦
#CyberSecurity #Compliance #InfoSec
β οΈ Still running WPA3 Personal Transition Mode?
πΆ It supports legacy devicesβbut also keeps WPA2-era risk in play. Review segmentation, PMF, and legacy client access before calling your Wi-Fi secure.
π 7asecurity.com/blog/2026/07/β¦
#NetworkSecurity #WPA3 #CyberSecurity
β οΈ A jQuery 3.5.1 finding isn't always a vulnerability.
π Learn how to separate scanner noise from real XSS risk by verifying runtime versions, plugins, and unsafe DOM patterns.
π 7asecurity.com/blog/2026/07/β¦
#CyberSecurity #AppSec #XSS #jQuery
Porto, get ready! π΅πΉ
Join Abraham Aranguren on Sep 23 for a hands-on workshop on practical Android and iOS attacks.
appsecdays.pt/trainings/mobiβ¦
#OWASP #MobileSecurity #AppSec
β οΈ Your cache may hold more than performance data.
ποΈ Sessions, tokens, API responses, and auth decisions can all become security risks if your cache is misconfigured.
π 7asecurity.com/blog/2026/07/β¦
#CyberSecurity #AppSec #Redis #InfoSec
π¨ BOFs reduce some of the process signals defenders rely onβbut they are not invisible.
Learn how Beacon Object Files change detection, post-exploitation testing, and defensive monitoring.
π 7asecurity.com/blog/2026/07/β¦
#CyberSecurity #BOF #CobaltStrike
π P2PE and E2EE protect different things.
Know where encryption starts, where it ends, and where plaintext still appears.
π 7asecurity.com/blog/2026/07/β¦
#CyberSecurity #Encryption #AppSec
π’ New 7ASecurity public #threatmodel report
π Super Tanks lightweight threat model by 7ASecurity.
7asecurity.com/blog/2026/07/β¦
π¬ Feedback welcome as always.
#CyberSecurity #AI #InfoSec
π³ PCI vulnerability management is more than scanning.
Validate findings. π οΈ Fix the root cause. β
Verify the remediation.
Learn how penetration testing and code audits strengthen PCI DSS security.
π 7asecurity.com/blog/2026/06/β¦
#PCIDSS #CyberSecurity #PaymentSecurity