Skip to content

Are your endpoints Zap safe ? #11

Description

@mosesnjoroge

Abstract

Modern applications are rarely monolithic — front end and back end are typically decoupled, and that architectural split meaningfully expands the attack surface compared to a tightly coupled structure. Add AI coding agents into the mix and it becomes easy to miss security edge cases, particularly on hobby or side projects where enterprise SAST/DAST tooling is out of reach.

This talk introduces OWASP ZAP, a free and open-source dynamic application security testing (DAST) tool that actively probes your running endpoints for common vulnerabilities. The case I'll make is simple: a ZAP scan should be a standard pre-PR step in every developer's workflow, not an afterthought reserved for security teams.

About the author

Moses Njoroge a software developer and the creator of Olyx, an AI governance platform. Being a two person team security testing has been paramount and an essential part of our CI/CD workflow to increase development velocity in a safe sandbox.

website:https://olyxai.io/
LinkedIn: /in/moses-n-a78b46127

Intended audience

all levels

Length

6 minutes (lightning talk)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions