ZAP

ZAP by Checkmarx zaproxy.org/

New Blog Post: Detecting Circular Type References in GraphQL Schemas
zaproxy.org/blog/2026-02-06-de
#zaproxy #appsec #graphql

New blog post: zaproxy.org/blog/2026-02-02-za
Highlights of 2025 and our initial plans for 2026, including more 3rd Party tool integrations, enhanced exploring and, yes, AI integration!
#zaproxy #appsec #ai

New “Getting Further with ZAP Scripting” pages: zaproxy.org/docs/getting-furth
Looking for something more? Let @psiinon know!

ZAP 2.17.0 is now available!
It includes performance improvements, a significant reduction in “duplicate” alerts reported, and new Insights which give you key information about scans.
zaproxy.org/blog/2025-12-15-za
#zaproxy #appsec

The latest version of the retirejs add-on includes a test for CVE-2025-66478 which is marked as "critical" so update now to detect this vulnerability.

ZAP Updates for November 2025:
zaproxy.org/blog/2025-12-03-za
2.17.0 is coming soon, along with Insights and fixes for some issues that caused ZAP to log 50 million errors in one day!
#zaproxy #appsec

New ZAP blog post - read how Telmon Maluleka is enhancing ZAP with AI for Bug Bounty Hunting
zaproxy.org/blog/2025-11-28-en
#zaproxy #appsec #bugbounty

ZAP logged 50 MILLION errors yesterday 😮 Read the blog for more details!
zaproxy.org/blog/2025-11-25-50
#zaproxy #appsec

Today’s weekly is the 2.17 Release Candidate! github.com/zaproxy/zaproxy/rel
Feedback appreciated

The ZAP services may well be unavailable due to the ongoing Cloudflare problems.
See cloudflarestatus.com/ for more information.

We have just published a new ZAP weekly release, to fix a bug which could cause invalid JSON reports to be generated. If you are using the most recent weekly we recommend you update ASAP.

Sorry, we messed up!
A new scan rule triggered the ZAP Check for Updates call even if you used the "silent" mode.
For more details see zaproxy.org/blog/2025-10-21-za

ZAP Blog: How to solve the Caido Labs using ZAP
zaproxy.org/blog/2025-10-15-so
c/o 5ubterranean_

The ZAP team has forked and will maintain WAVSEP going forwards. This blog post explains why.

zaproxy.org/blog/2025-09-08-za

#zaproxy #appsec #wavsep

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst