Skip to content

The digital town square for the concert band community.

Connect with local ensembles, trade repertoire insights, and keep the pulse of the wind band world.

  • 0 Votes
    1 Posts
    0 Views
    OWASP FoundationO
    Join Sven Schleier’s 2-day mobile app security training either remotely or in Vienna! Learn Android & iOS testing (OWASP MASTG), dynamic/static analysis, Frida, reverse engineering, cloud labs, and live CTFs No device needed, just your laptop. Level up your skills#appsec #mobilesecurity
  • 0 Votes
    1 Posts
    0 Views
    SolomonS
    protobuf.js RCE can trigger arbitrary JS execution when apps load attacker influenced schemas. Patch to 8.0.1 or 7.5.5.🟑 Tycoon 2FA crews are leaning into device code phishing to steal sessions and bypass MFA. Reinforce user training and conditional access.#CyberSecurity #ThreatIntel #AppSec #IdentitySecuritysolomonneas.dev/intel
  • 0 Votes
    1 Posts
    0 Views
    BillS
    On Mr. B. Schneier has a few words about #Mythos.https://www.schneier.com/blog/archives/2026/04/mythos-and-cybersecurity.html#anthropic #appsec
  • 0 Votes
    1 Posts
    0 Views
    BSidesLuxembourgB
    New Talk Dropped for BSides Luxembourg 2026!🧰 𝗧𝗨π—₯π—‘π—žπ—˜π—¬ π—–π—’π——π—˜ – π—˜π—‘π—›π—”π—‘π—–π—œπ—‘π—š π—¦π—˜π—–π—₯π—˜π—§π—¦ π— π—”π—‘π—”π—šπ—˜π— π—˜π—‘π—§ π—œπ—‘ π—Ÿπ—”π—₯π—šπ—˜ π—¦π—–π—”π—Ÿπ—˜ 𝗒π—₯π—šπ—”π—‘π—œπ—­π—”π—§π—œπ—’π—‘π—¦ β€” Diogo Lemos Dive into a Talk (40 min) on building scalable secrets detection systems that actually reduce noise, improve triage, and integrate into real-world CI/CD pipelines.Secrets leakage remains one of the most persistent problems in modern software development, not because tools don’t exist, but because they fail at scaleβ€”producing too many false positives and too little actionable context. This session explores how a real-world turnkey platform was designed to solve this gap using open-source tooling, smarter validation, and CI/CD-native workflows.Through architecture insights and live demonstrations, learn how scanning strategies, confidence scoring, and automation can transform secrets detection from a noisy checkbox into a reliable security process. The talk also highlights practical lessons from deploying and scaling such a system in production environments.Diogo Lemos is an Application Security Engineer with experience at Checkmarx, Flutter Entertainment, and OLX, specializing in scalable AppSec programs, automation, and cloud security. He actively contributes to open-source security tooling and speaks internationally on practical SAST, SCA, and secrets management solutions. Conference Dates: 6–8 May 2026 | 09:00–18:00 14, Porte de France, Esch-sur-Alzette, Luxembourg️ Tickets: https://2026.bsides.lu/tickets/ Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/ View full schedule & build your agenda: https://hackertracker.app/schedule?conf=BSIDESLUX2026 #BSidesLuxembourg2026 #SecretsManagement #AppSec #DevSecOps #SAST #CyberSecurity
  • 0 Votes
    1 Posts
    0 Views
    BSidesLuxembourgB
    Added to the BSides Luxembourg 2026 Lineup️ 𝗒𝗨𝗧 𝗒𝗙 π—¦π—˜π—–π—¨π—₯π—œπ—§π—¬ π—˜π—«π—–π—˜π—£π—§π—œπ—’π—‘: π—ͺ𝗛𝗔𝗧 𝗧𝗒 𝗗𝗒 π—ͺπ—œπ—§π—›π—’π—¨π—§ 𝗔𝗑 π—˜π—«π—£π—˜π—₯𝗧 𝗧𝗒 π—¦π—˜π—–π—¨π—₯π—˜ 𝗬𝗒𝗨π—₯ 𝗦𝗒𝗙𝗧π—ͺ𝗔π—₯π—˜ β€” Lisi Hocke ( @lisihocke ) Take control in this Talk (40 min) and learn how development teams can build secure software even without dedicated security experts.Security shouldn’t be a blocker waiting on experts. This session shows how everyday engineering activitiesβ€”like planning features, collaborating across teams, and maintaining codeβ€”can be leveraged to significantly improve your product’s security posture without slowing down delivery.Discover how to integrate threat modeling into regular workflows, catch vulnerabilities earlier through collaboration, and use production insights to detect malicious behavior. This talk empowers teams to shift from dependency on security teams to building β€œsecure enough” systems through practical, developer-driven approaches.Lisi Hocke (@lisihocke ) is a security engineer focused on product security, with a passion for quality, collaboration, and continuous learning. A strong advocate for whole-team approaches, she shares her experiences to help teams build resilient and secure software while delivering real value. Conference Dates: 6–8 May 2026 | 09:00–18:00 14, Porte de France, Esch-sur-Alzette, Luxembourg️ Tickets: https://2026.bsides.lu/tickets/ Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/ View full schedule & build your agenda: https://hackertracker.app/schedule?conf=BSIDESLUX2026 #BSidesLuxembourg2026 #SecureDevelopment #AppSec #DevSecOps #SoftwareSecurity #CyberSecurity
  • 0 Votes
    1 Posts
    0 Views
    Gary McGrawC
    A good posting reality check on Anthropic's mythos hyperbole around #swsec #appsec#MLsec adjacent https://blog.vidocsecurity.com/blog/we-reproduced-anthropics-mythos-findings-with-public-models
  • 0 Votes
    1 Posts
    0 Views
    OWASP BostonO
    Only 5 days left to buy your ticket to the premier application security conference. Enjoy a full day of learning and skill-building with 18 talks and 4 workshops led by industry experts. Plus, get a shot at winning some great raffle prizes. Purchase at www.basconf.org β€” your ticket will be refunded when you check in at the event!#appsec #basconf #owasp #basc2026