<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>vulnerability-scanner</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/165/feed"/>
    <updated>2026-08-03T01:36:13+00:00</updated>
    <id>https://links.biapy.com/guest/tags/165/feed</id>
            <entry>
            <id>https://links.biapy.com/links/13435</id>
            <title type="text"><![CDATA[Kritt]]></title>
            <link rel="alternate" href="https://kritt.ai/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13435"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Orchestrate AI agents to find real vulnerabilities in code.

An open-source, self-hosted security research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment.

- [Kritt @ GitHub](https://github.com/Kritt-ai/open-kritt).]]>
            </summary>
            <updated>2026-07-27T12:30:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13387</id>
            <title type="text"><![CDATA[rnsec]]></title>
            <link rel="alternate" href="https://www.rnsec.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13387"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Lightweight &amp;amp; Fast Security Scanner for React Native &amp;amp; Expo.

A zero-configuration security scanner for React Native and Expo applications that detects vulnerabilities, hardcoded secrets, and security misconfigurations with a single command.

- [rnsec @ GitHub](https://github.com/adnxy/rnsec).]]>
            </summary>
            <updated>2026-07-23T15:42:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13383</id>
            <title type="text"><![CDATA[Visa Vulnerability Agentic Harness]]></title>
            <link rel="alternate" href="https://github.com/visa/visa-vulnerability-agentic-harness" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13383"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Agentic SAST Pipeline.

VVAH is Visa&amp;#039;s open-source harness for autonomous vulnerability discovery, remediation, and validation using frontier AI models, built on learnings from Project Glasswing (Anthropic&amp;#039;s initiative for AI-assisted vulnerability research).]]>
            </summary>
            <updated>2026-07-23T11:12:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13291</id>
            <title type="text"><![CDATA[Nox]]></title>
            <link rel="alternate" href="https://kernelstub.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13291"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Modular Go framework for attack surface management, reconnaissance, and vulnerability scanning. 

NOX is a modular, Go based attack surface management and vulnerability scanning framework. It ships with 300 built in modules covering OSINT, subdomain enumeration, DNS, port scanning, web fingerprinting, and deep active vulnerability testing across injection, authentication, authorization, client side, cloud, API, and business logic vulnerability classes.

- [Nox @ GitHub](https://github.com/kernelstub/Nox).]]>
            </summary>
            <updated>2026-07-15T07:50:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13281</id>
            <title type="text"><![CDATA[ZAP Vulnerability Scanner]]></title>
            <link rel="alternate" href="https://github.com/JAAFAR12781/zap-vulnerability-scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13281"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Most web security tools like OWASP ZAP are powerful but complex. A developer without a cybersecurity background struggles to configure them correctly. My goal was to wrap ZAP&amp;#039;s API into a simple Python CLI tool that anyone can run with a single command.

Related contents:

- [How I Built an Automated Web Vulnerability Scanner with Python and OWASP ZAP @ Jaafar Soufiane&amp;#039;s dev.to](https://dev.to/jaafar12781/how-i-built-an-automated-web-vulnerability-scanner-with-python-and-owasp-zap-l35).]]>
            </summary>
            <updated>2026-07-15T06:54:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13247</id>
            <title type="text"><![CDATA[badkeys]]></title>
            <link rel="alternate" href="https://badkeys.info/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13247"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Tool to find common vulnerabilities in cryptographic public keys.

- [badkeys @ GitHub](https://github.com/badkeys/badkeys).]]>
            </summary>
            <updated>2026-07-09T07:02:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13246</id>
            <title type="text"><![CDATA[gh-workflow-hardener]]></title>
            <link rel="alternate" href="https://github.com/indoor47/gh-workflow-hardener" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13246"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[GitHub Actions security scanner: pin actions to SHAs, detect script injection, audit permissions. Fix supply chain vulnerabilities. 

Secure your GitHub Actions workflows against supply chain attacks. Detects unpinned actions (the tj-actions attack vector), dangerous permissions, and script injection — all in one scan.]]>
            </summary>
            <updated>2026-07-09T07:00:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13216</id>
            <title type="text"><![CDATA[Datadog Static AI Security Testing (SAIST) tool]]></title>
            <link rel="alternate" href="https://github.com/DataDog/datadog-saist?utm_source=devopsbulletin.com" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13216"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[This project is an AI-Native SAST tool. Unlike traditional SAST tools that rely solely on parsing and analysis rules, this project uses LLM (e.g. Claude from Anthropic, GPT from OpenAI or Gemini from Google) to find vulnerabilities.]]>
            </summary>
            <updated>2026-07-06T07:12:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13193</id>
            <title type="text"><![CDATA[KICS]]></title>
            <link rel="alternate" href="https://docs.kics.io/latest/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13193"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project.

-  [KICS @ GitHub](https://github.com/Checkmarx/kics/).

Related contents:

- [Top 7 Terraform Scanning Tools You Should Know in 2026 @ Spacelift](https://spacelift.io/blog/terraform-scanning-tools).]]>
            </summary>
            <updated>2026-07-03T07:55:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13102</id>
            <title type="text"><![CDATA[CVE Lite CLI]]></title>
            <link rel="alternate" href="https://owasp.org/cve-lite-cli/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13102"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Scan. Understand. Fix.
Free, local-first JS/TS vulnerability scanner.

 Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance. 

Most security tools are built around pipelines, not developers. CVE Lite CLI scans your lockfile locally in seconds, explains the dependency path, and tells you what to update before you push.

- [CVE Lite CLI @ GitHub](https://github.com/OWASP/cve-lite-cli).

Related contents:

- [Cet outil open source traque les conseils de sécurité que l&amp;#039;IA vous a refilés et qui ne valent plus rien @ Korben :fr:](https://korben.info/cet-outil-open-source-traque-les-conseils-de-securite-que-lia-vous-a-refiles-et-qui-ne-valent-plus-rien.html).]]>
            </summary>
            <updated>2026-06-24T09:34:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13099</id>
            <title type="text"><![CDATA[helmsniff]]></title>
            <link rel="alternate" href="https://github.com/VahidR/helmsniff" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13099"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Go CLI tool that scans rendered Kubernetes/Helm manifests and produces a CSV &amp;amp; JSON report of security misconfigurations.]]>
            </summary>
            <updated>2026-06-23T12:48:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13077</id>
            <title type="text"><![CDATA[AISLE]]></title>
            <link rel="alternate" href="https://aisle.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13077"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI-Native Vulnerability Management.

AISLE finds, fixes, and verifies vulnerabilities autonomously – proven on the world&amp;#039;s most audited codebases. Deploy anywhere: cloud, on-prem, or fully air-gapped.

Related contents:

- [&amp;quot;Mythos&amp;quot; at Home, and It&amp;#039;s Called AISLE @ AISLE](https://aisle.com/blog/mythos-at-home-and-its-called-aisle).]]>
            </summary>
            <updated>2026-06-22T07:31:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12854</id>
            <title type="text"><![CDATA[Bumblebee]]></title>
            <link rel="alternate" href="https://github.com/perplexityai/bumblebee" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12854"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.

 Related contents:

- [Perplexity Is Open-Sourcing Bumblebee @ Perplexity](https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee).
- [Perplexity open-sources Bumblebee security scanner @ AI News](https://www.testingcatalog.com/perplexity-open-sources-bumblebee-security-scanner/).]]>
            </summary>
            <updated>2026-05-26T12:45:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12843</id>
            <title type="text"><![CDATA[testssl.sh]]></title>
            <link rel="alternate" href="https://testssl.sh/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12843"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Testing TLS/SSL encryption anywhere on any port .

testssl.sh is a free command line tool which checks a server&amp;#039;s service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws and more. 

- [testssl.sh @ GitHub](https://github.com/testssl/testssl.sh).

Related contents:

- [Testssl.sh : auditer la configuration SSL/TLS de vos serveurs Web @ IT-Connect :fr:](https://www.it-connect.fr/testsslsh-auditer-la-configuration-ssl-tls-de-vos-serveurs-web/).]]>
            </summary>
            <updated>2026-05-25T09:24:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12804</id>
            <title type="text"><![CDATA[DockSec]]></title>
            <link rel="alternate" href="https://github.com/OWASP/DockSec" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12804"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI-Powered Docker Security Analyzer.

AI-powered Docker security scanner that explains vulnerabilities in plain English]]>
            </summary>
            <updated>2026-05-21T11:59:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12800</id>
            <title type="text"><![CDATA[🧿 Entra CA Insight]]></title>
            <link rel="alternate" href="https://github.com/emiliensocchi/entra-ca-insight" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12800"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Discover gaps in Entra Conditional Access policies before attackers do.]]>
            </summary>
            <updated>2026-05-21T11:53:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12779</id>
            <title type="text"><![CDATA[RedAI]]></title>
            <link rel="alternate" href="https://github.com/kpolley/redai" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12779"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI-driven vulnerability discovery and live validation.

A terminal workbench for AI-driven vulnerability discovery and live validation.]]>
            </summary>
            <updated>2026-05-15T15:26:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12721</id>
            <title type="text"><![CDATA[Deepsec]]></title>
            <link rel="alternate" href="https://github.com/vercel-labs/deepsec/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12721"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents.

deepsec an agent-powered vulnerability scanner that you can run in your own infrastructure, optimized to perform on-demand review of all code in existing large-scale repos.

Related contents:

- [Introducing deepsec: The security harness for finding vulnerabilities in your codebase @ Vercel](https://vercel.com/blog/introducing-deepsec-find-and-fix-vulnerabilities-in-your-code-base).
- [Vercel’s deepsec Brings AI-Powered Security Scanning Into the Development Workflow @ devops.com](https://devops.com/vercels-deepsec-brings-ai-powered-security-scanning-into-the-development-workflow/).]]>
            </summary>
            <updated>2026-05-15T08:00:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12662</id>
            <title type="text"><![CDATA[MSSQLHound]]></title>
            <link rel="alternate" href="https://github.com/SpecterOps/MSSQLHound" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12662"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Go (formerly PowerShell) collector for adding MSSQL attack paths to BloodHound with OpenGraph.

A collector for adding MSSQL attack paths to BloodHound with OpenGraph by Chris Thompson at SpecterOps. Available as both a PowerShell script and a cross-platform Go binary (with concurrent collection, SOCKS5 proxy support, and streaming output).

Related contents:

- [MSSQLHound Now Available in Go @ SpecterOps](https://specterops.io/blog/2026/04/23/mssqlhound-now-available-in-go/).]]>
            </summary>
            <updated>2026-04-30T11:27:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12659</id>
            <title type="text"><![CDATA[DorkEye]]></title>
            <link rel="alternate" href="https://xploits3c.github.io/DorkEye/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12659"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated Google Dorking Tool. Generates and runs advanced search queries for exposed files. It also test Vulns, Analyzes and extracts metadata.

- [DorkEye @ GitHub](https://github.com/xPloits3c/DorkEye).]]>
            </summary>
            <updated>2026-04-30T11:23:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12643</id>
            <title type="text"><![CDATA[DockSec]]></title>
            <link rel="alternate" href="https://github.com/docksec-security/DockSec" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12643"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI-Powered Docker Security Analyzer.
AI-powered Docker security scanner that explains vulnerabilities in plain English.

DockSec is an OWASP Incubator Project that combines traditional Docker security scanners (Trivy, Hadolint, Docker Scout) with AI to provide context-aware security analysis.

Related contents:

- [Dockerfile Practices are a DevOps Tax Before They are a Security Concern @ Cloud Native Now](https://cloudnativenow.com/contributed-content/dockerfile-practices-are-a-devops-tax-before-they-are-a-security-concern/).
- [\#67 - Newsletter du 27 Avril 2026 @ RudeOps :fr:](https://www.rudeops.com/newsletters/2026-04-27).]]>
            </summary>
            <updated>2026-04-29T06:20:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12608</id>
            <title type="text"><![CDATA[Clauditor]]></title>
            <link rel="alternate" href="https://github.com/gabrielsoltz/clauditor" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12608"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security configuration scanner for Claude Code.

Clauditor audits your Claude Code settings and repository configuration to detect security misconfigurations.]]>
            </summary>
            <updated>2026-04-23T13:53:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12396</id>
            <title type="text"><![CDATA[JamfHound]]></title>
            <link rel="alternate" href="https://github.com/SpecterOps/JamfHound" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12396"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[JamfHound is a python3 project designed to collect and identify attack paths in Jamf Pro tenants based on existing object permissions by outputting data as JSON for ingestion into BloodHound. 

Related contents:

- [JamfHound v1.1 Update: SSO Attack Paths and Okta Additions @ Specter OPS](https://specterops.io/blog/2026/03/31/jamfhound-v1-1-update-sso-attack-paths-and-okta-additions/).]]>
            </summary>
            <updated>2026-04-03T13:50:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12393</id>
            <title type="text"><![CDATA[VICE]]></title>
            <link rel="alternate" href="https://github.com/Webba-Creative-Technologies/vice" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12393"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security auditing CLI for web applications.

VICE is a security auditing CLI tool that finds vulnerabilities in your web applications. It has two modes:

Remote scan gives it a URL. It crawls your site with a real browser, extracts secrets from JS bundles, tests your login for brute force and SQL injection, scans your VPS ports, checks your Supabase RLS, and more. Like an attacker would, but on your own systems.

Local audit points it at your project directory. It reads your source code, checks your .env files, runs npm audit, analyzes your Supabase migrations for missing RLS, finds SQL injections and XSS in your code, and tells you exactly what to fix.]]>
            </summary>
            <updated>2026-04-03T13:26:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12299</id>
            <title type="text"><![CDATA[VulHunt]]></title>
            <link rel="alternate" href="https://vulhunt.re/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12299"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Hunt Vulnerabilities in Binaries with VulHunt.

VulHunt goes beyond signature matching and version inference. Write Lua rules that leverage dataflow analysis, code pattern matching, and decompilation to detect known and unknown vulnerabilities in POSIX binaries and UEFI firmware.

- [VulHunt @ GitHub](https://github.com/vulhunt-re/vulhunt).]]>
            </summary>
            <updated>2026-03-26T13:35:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12297</id>
            <title type="text"><![CDATA[Pius]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/pius" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12297"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Attack Surface Discovery &amp;amp; OSINT Reconnaissance Tool.

Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registries. 

Pius is an open-source attack surface discovery tool written in Go. Given a company name, it maps the complete external attack surface: domains, subdomains, and IP ranges (CIDRs). Pius queries certificate transparency logs, all five regional Internet registries (ARIN, RIPE, APNIC, AFRINIC, LACNIC), passive DNS databases, WHOIS/RDAP, BGP tables, and more through 24 discovery plugins.]]>
            </summary>
            <updated>2026-03-26T13:28:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12235</id>
            <title type="text"><![CDATA[Trajan]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/trajan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12235"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Trajan scans CI/CD pipelines for security vulnerabilities that attackers use to compromise software supply chains. It supports GitHub Actions, GitLab CI, Azure DevOps, Jenkins, and JFrog.]]>
            </summary>
            <updated>2026-03-23T14:22:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12158</id>
            <title type="text"><![CDATA[bagel]]></title>
            <link rel="alternate" href="https://boostsecurityio.github.io/bagel/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12158"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Bagel is a cross-platform CLI that inspects developer workstations and produces a structured report of security findings. It allows developers to understand their attack surface and what could be of interest to a malicious actor.

- [bagel @ GitHub](https://github.com/boostsecurityio/bagel).

Related contents:

- [Bagel : scanner la posture sécurité de votre poste développeur @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/outils/bagel/).
- [Detecting and removing dangerous secrets on dev workstations before Shai-Hulud does @ Recyclebin.zip](https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel/).]]>
            </summary>
            <updated>2026-06-18T11:38:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12039</id>
            <title type="text"><![CDATA[HTTP Header Security Test - HTTP Observatory]]></title>
            <link rel="alternate" href="https://developer.mozilla.org/en-US/observatory" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12039"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Launched in 2016, the HTTP Observatory enhances web security by analyzing compliance with best security practices. It has provided insights to over 6.9 million websites through 47 million scans. 

Related contents:

- [De F à A+ sur HTTP Observatory : sécuriser les headers de mon blog Hugo @ Zwindler&amp;#039;s Reflection :fr:](https://blog.zwindler.fr/2026/02/20/securite-headers-http-observatory-hugo/).]]>
            </summary>
            <updated>2026-03-06T07:26:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11968</id>
            <title type="text"><![CDATA[MCP Hammer]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/MCPHammer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11968"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[MCP security testing framework for evaluating Model Context Protocol server vulnerabilities.

A Model Context Protocol (MCP) server built with FastMCP that provides various tools including Claude AI integration, text injection capabilities, and server information utilities. It is definitely super secure, you should definitely send confidential data through it, and definitely take everything it says as fact.

Related contents:

- [MCP Server Security: The Hidden AI Attack Surface @ Praetorian](https://www.praetorian.com/blog/mcp-server-security-the-hidden-ai-attack-surface).]]>
            </summary>
            <updated>2026-03-02T06:48:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11928</id>
            <title type="text"><![CDATA[Caterpillar]]></title>
            <link rel="alternate" href="https://caterpillar.alice.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11928"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Caterpillar is a security scanning library for AI agent skill files (e.g., Claude Code skills) for dangerous or malicious behavior.

Security scanner for AI agent skills. Scans for malicious patterns before you install.

- [Caterpillar @ GitHub](https://github.com/alice-dot-io/caterpillar).]]>
            </summary>
            <updated>2026-02-26T11:14:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11905</id>
            <title type="text"><![CDATA[Augustus]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/augustus" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11905"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[LLM Vulnerability Scanner.

Test large language models against 210+ adversarial attacks covering prompt injection, jailbreaks, encoding exploits, and data extraction.

Related contents:

- [Digest \#202: Terraform Claude Skills, FinOps FOCUS 1.2, AI Fatigue for Cloud Engineers, and MCP for Web Data Extraction @ DevOps Bulletin](https://www.devopsbulletin.com/p/digest-202-terraform-claude-skills).]]>
            </summary>
            <updated>2026-02-24T07:13:40+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11819</id>
            <title type="text"><![CDATA[Skill Scanner]]></title>
            <link rel="alternate" href="https://github.com/cisco-ai-defense/skill-scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11819"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security Scanner for Agent Skills.

A security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. Combines pattern-based detection (YAML + YARA), LLM-as-a-judge, and behavioral dataflow analysis for comprehensive threat detection.

Related contents:

- [Personal AI Agents like OpenClaw Are a Security Nightmare @ Cisco Blogs](https://blogs.cisco.com/ai/personal-ai-agents-like-openclaw-are-a-security-nightmare).]]>
            </summary>
            <updated>2026-02-16T06:07:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11624</id>
            <title type="text"><![CDATA[Brakeman]]></title>
            <link rel="alternate" href="https://brakemanscanner.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11624"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Brakeman Security Scanner. Secure Your Rails Applications

Brakeman is a free vulnerability scanner designed for Ruby on Rails applications. Statically analyze Rails application code to find security issues at any stage of development.

- [Brakeman @ GitHub](https://github.com/presidentbeef/brakeman).]]>
            </summary>
            <updated>2026-01-26T16:46:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11576</id>
            <title type="text"><![CDATA[aura-inspector]]></title>
            <link rel="alternate" href="https://github.com/google/aura-inspector" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11576"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[aura-inspector is a Swiss Army knife of Salesforce Experience Cloud testing. It facilitates in discovering misconfigured Salesforce Experience Cloud applications as well as automates much of the testing process. Some of it&amp;#039;s functionality includes:

Related contents:

- [Erreur 403 | \#60](https://newsletter.erreur403.fr/p/erreur-403-60).
- [ShinyHunters claims more high-profile victims in latest Salesforce customers data heist @ The Register](https://www.theregister.com/2026/03/09/shinyhunters_claims_more_highprofile_victims/).]]>
            </summary>
            <updated>2026-03-12T10:49:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11574</id>
            <title type="text"><![CDATA[Heimdall]]></title>
            <link rel="alternate" href="https://github.com/DenizParlak/heimdall" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11574"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AWS Attack Path Scanner.
Discover privilege escalation paths across 10+ AWS services.

Heimdall is an AWS security scanner that discovers privilege escalation paths attackers could exploit to gain admin access.

Related contents:

- [Erreur 403 | \#60](https://newsletter.erreur403.fr/p/erreur-403-60).]]>
            </summary>
            <updated>2026-01-23T07:24:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11573</id>
            <title type="text"><![CDATA[Gixy-Next]]></title>
            <link rel="alternate" href="https://gixy.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11573"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[NGINX Configuration Security &amp;amp; Hardening Scanner.

Gixy-Next (Gixy) is an open-source NGINX configuration security scanner and hardening tool that statically analyzes your nginx.conf to detect security misconfigurations, hardening gaps, and common performance pitfalls before they reach production. It is an actively maintained fork of Yandex&amp;#039;s Gixy. Gixy-Next&amp;#039;s source code is available on GitHub.

- [Gixy-Next @ GitHub](https://github.com/MegaManSec/Gixy-Next).

Related contents:

- [Erreur 403 | \#60](https://newsletter.erreur403.fr/p/erreur-403-60).]]>
            </summary>
            <updated>2026-01-23T07:23:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11392</id>
            <title type="text"><![CDATA[Tailsnitch]]></title>
            <link rel="alternate" href="https://github.com/Adversis/tailsnitch" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11392"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A security auditor for Tailscale configurations. Scans your tailnet for misconfigurations, overly permissive access controls, and security best practice violations.]]>
            </summary>
            <updated>2026-01-06T13:04:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11357</id>
            <title type="text"><![CDATA[react2shell-scanner]]></title>
            <link rel="alternate" href="https://github.com/assetnote/react2shell-scanner?utm_source=tldrdevops" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11357"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 &amp;amp; CVE-2025-66478).

A command-line tool for detecting CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server Components.]]>
            </summary>
            <updated>2026-01-05T07:29:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11107</id>
            <title type="text"><![CDATA[Web Cache Vulnerability Scanner]]></title>
            <link rel="alternate" href="https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11107"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning and web cache deception.

The scanner supports many different web cache poisoning and web cache deception techniques, includes a crawler to identify further URLs to test, and can adapt to a specific web cache for more efficient testing. It is highly customizable and can be easily integrated into existing CI/CD pipelines.]]>
            </summary>
            <updated>2025-11-27T07:13:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11074</id>
            <title type="text"><![CDATA[cnspec]]></title>
            <link rel="alternate" href="https://mondoo.com/cnspec" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11074"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Source Cloud Security Scanner.

An open source, cloud-native security to protect everything from build to runtime.

cnspec assesses your entire infrastructure&amp;#039;s security and compliance. It finds vulnerabilities and misconfigurations across public and private cloud environments, Kubernetes clusters, containers, container registries, servers, endpoints, SaaS products, infrastructure as code, APIs, and more.

A powerful policy as code engine, cnspec is built upon Mondoo&amp;#039;s security data fabric. It comes configured with default security policies that run right out of the box. It&amp;#039;s both fast and simple to use!

- [cnspec @ GitHub](https://github.com/mondoohq/cnspec).]]>
            </summary>
            <updated>2025-11-24T10:37:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11029</id>
            <title type="text"><![CDATA[Sirius]]></title>
            <link rel="alternate" href="https://github.com/SiriusScan/Sirius" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11029"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sirius is an open-source comprehensive vulnerability scanner that leverages community-driven security intelligence and automated penetration testing capabilities.]]>
            </summary>
            <updated>2025-11-21T06:29:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10947</id>
            <title type="text"><![CDATA[MCP Scanner]]></title>
            <link rel="alternate" href="https://github.com/cisco-ai-defense/mcp-scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10947"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Scan MCP servers for potential threats &amp;amp; security findings.

A Python tool for scanning MCP (Model Context Protocol) servers and tools for potential security findings. The MCP Scanner combines Cisco AI Defense inspect API, YARA rules and LLM-as-a-judge to detect malicious MCP tools.

Related contents:

- [Securing the AI agent supply chain with Cisco’s open-source MCP Scanner @ Cisco Blogs](https://blogs.cisco.com/ai/securing-the-ai-agent-supply-chain-with-ciscos-open-source-mcp-scanner).]]>
            </summary>
            <updated>2025-11-13T06:36:22+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10841</id>
            <title type="text"><![CDATA[Deep Eye 🔍]]></title>
            <link rel="alternate" href="https://github.com/zakirkun/deep-eye" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10841"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An advanced AI-driven vulnerability scanner and penetration testing tool that integrates multiple AI providers (OpenAI, Grok, OLLAMA, Claude) with comprehensive security testing modules for automated bug hunting, intelligent payload generation, and professional reporting.

Related contents:

- [Deep Eye - Le scanner de vulns multi-IA @ Korben :fr:](https://korben.info/deep-eye-scanner-vulnerabilites-ai-openai-claude-g.html).]]>
            </summary>
            <updated>2025-11-03T08:55:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10451</id>
            <title type="text"><![CDATA[NPM Supply Chain Security Scanner]]></title>
            <link rel="alternate" href="https://github.com/Drasrax/npm-shai-hulud-scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10451"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Comprehensive detection tool for NPM supply chain attacks, specifically designed to identify and prevent the Shai-Hulud worm that compromised 500+ packages including CrowdStrike npm packages in 2025. 

Related contents:

- [Malicious NPM packages: Are you exposed? @ sysdig](https://www.sysdig.com/blog/malicious-npm-packages-are-you-exposed).
- [Un scanner pour lutter contre l&amp;#039;attaque Shai-Hulud @ Korben :fr:](https://korben.info/npm-shai-hulud-scanner-attaque-supply-chain.html).]]>
            </summary>
            <updated>2025-09-29T13:04:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10397</id>
            <title type="text"><![CDATA[bomber]]></title>
            <link rel="alternate" href="https://devops-kung-fu.github.io/bomber/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10397"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Scans Software Bill of Materials (SBOMs) for security vulnerabilities.

bomber is an application that scans SBOMs for security vulnerabilities.

- [bomber @ GitHub](https://github.com/devops-kung-fu/bomber).]]>
            </summary>
            <updated>2025-09-25T12:39:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10154</id>
            <title type="text"><![CDATA[Harbor Guard]]></title>
            <link rel="alternate" href="https://harborguard.co/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10154"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Securing containers, one scan at a time.

 Harbor Guard is a comprehensive container security scanning platform that provides an intuitive web interface for managing and visualizing security assessments of Docker images.

- [Harbor Guard @ GitHub](https://github.com/HarborGuard/HarborGuard).]]>
            </summary>
            <updated>2025-09-12T07:43:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10051</id>
            <title type="text"><![CDATA[vulners-lookup]]></title>
            <link rel="alternate" href="https://github.com/vulnersCom/vulners-lookup" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10051"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Chrome extension that highlights CVE identifiers and displays critical information directly on any webpage. No need to navigate elsewhere. 

- [Vulners Lookup @ Chrome web store](https://chromewebstore.google.com/detail/vulners-lookup/pkhbdkfenifidcejinfbgjdalelamaao).

Related contents:

- [Vulners Lookup transforme votre navigateur en catalogue de vulnérabilités @ Korben :fr:](https://korben.info/vulners-lookup-extension-chrome-cve-vulnerabilites.html).]]>
            </summary>
            <updated>2025-09-08T11:23:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10036</id>
            <title type="text"><![CDATA[ChopChop]]></title>
            <link rel="alternate" href="https://github.com/michelin/ChopChop" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10036"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[ChopChop is a command-line tool for dynamic application security testing on web applications, initially written by the Michelin CERT.

Its goal is to scan several endpoints and identify exposition of services/files/folders through the webroot. Checks/Signatures are declared in a config file (by default: chopchop.yml), fully configurable, and especially by developers.]]>
            </summary>
            <updated>2025-09-08T08:17:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/56</id>
            <title type="text"><![CDATA[Buttercup]]></title>
            <link rel="alternate" href="https://github.com/trailofbits/buttercup" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/56"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Buttercup is a Cyber Reasoning System (CRS) developed by Trail of Bits for the DARPA AIxCC (AI Cyber Challenge). Buttercup finds and patches software vulnerabilities in open-source code repositories like example-libpng. It starts by running an AI/ML-assisted fuzzing campaign (built on oss-fuzz) for the program. When vulnerabilities are found, Buttercup analyzes them and uses a multi-agent AI-driven patcher to repair the vulnerability.

Related contents:

- [Buttercup - L&amp;#039;IA qui trouve et patche automatiquement les failles de sécurité @ Korben :fr:](https://korben.info/buttercup-trouve-patche-automatiquement-failles-securite.html).]]>
            </summary>
            <updated>2025-09-04T08:40:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/355</id>
            <title type="text"><![CDATA[Opengrep]]></title>
            <link rel="alternate" href="https://www.opengrep.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/355"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🔎 Static code analysis engine to find security issues in code. 
Opengrep, a fork of Semgrep, under the LGPL 2.1 license.

Opengrep is an ultra-fast static analysis tool for searching code patterns with the power of semantic grep. Analyze large code bases at the speed of thought with intuitive pattern matching and customizable rules. Find and fix security vulnerabilities, fast – ship more secure code.

Opengrep supports 30+ languages, including:

Apex · Bash · C · C++ · C# · Clojure · Dart · Dockerfile · Elixir · HTML · Go · Java · JavaScript · JSX · JSON · Julia · Jsonnet · Kotlin · Lisp · Lua · OCaml · PHP · Python · R · Ruby · Rust · Scala · Scheme · Solidity · Swift · Terraform · TypeScript · TSX · YAML · XML · Generic (ERB, Jinja, etc.)

- [Opengrep @ GitHub](https://github.com/opengrep/opengrep).
- [Opengrep Rules @ GitHub](https://github.com/opengrep/opengrep-rules).]]>
            </summary>
            <updated>2026-01-21T08:58:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/567</id>
            <title type="text"><![CDATA[OWASP Nettacker]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-nettacker/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/567"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management.

OWASP Nettacker project was created to automate information gathering, vulnerability scanning and in general to aid penetration testing engagements. Nettacker is able to run various scans using a variety of methods and generate scan reports(in HTML/TXT/JSON/CSV format) for applications and networks, including discovering open ports, services, bugs, vulnerabilities, misconfigurations, default credentials, subdomains, etc. Nettacker can be run as a command-line utility (including running as a Docker container), API, Web GUI mode or as Maltego transforms.

- [OWASP Nettacker @ GitHub](https://github.com/OWASP/Nettacker).]]>
            </summary>
            <updated>2025-08-28T17:32:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/751</id>
            <title type="text"><![CDATA[Vuls]]></title>
            <link rel="alternate" href="https://vuls.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/751"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Agentless Vulnerability Scanner for Linux/FreeBSD.

 Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices.

- [Vuls @ GitHub](https://github.com/future-architect/vuls).]]>
            </summary>
            <updated>2025-08-28T18:03:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/937</id>
            <title type="text"><![CDATA[MCP-Shield]]></title>
            <link rel="alternate" href="https://github.com/riseandignite/mcp-shield" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/937"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security scanner for MCP servers

MCP-Shield scans your installed MCP (Model Context Protocol) servers and detects vulnerabilities like tool poisoning attacks, exfiltration channels and cross-origin escalations.]]>
            </summary>
            <updated>2025-08-28T18:34:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1180</id>
            <title type="text"><![CDATA[glpwnme]]></title>
            <link rel="alternate" href="https://github.com/Orange-Cyberdefense/glpwnme" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1180"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[GLPI vulnerabilities checking tool.

glpwnme is a tool used to check for vulnerabilities on running instance of glpi.

Related contents:

- [🔍 Lors de mes audits et tests d’intrusion, je tombe très souvent sur des environnements GLPI… et bien souvent, c’est mal géré ! @ Hamza Kondah&amp;#039;s  LinkedIn :fr:](https://www.linkedin.com/posts/kondah_lors-de-mes-audits-et-tests-dintrusion-activity-7309983476911407105-MdfI/).]]>
            </summary>
            <updated>2025-08-28T19:12:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1198</id>
            <title type="text"><![CDATA[FuzzySully :fr:]]></title>
            <link rel="alternate" href="https://github.com/ANSSI-FR/fuzzysully" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1198"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fuzzowski-based OPCUA fuzzer.

Fuzzing should never be conducted on production equipment or systems. This testing technique can cause unexpected behavior, system crashes, data corruption, or security vulnerabilities. Always perform fuzzing in a controlled, isolated environment to ensure the safety and stability of production systems.

FuzzySully is an OPC UA fuzzer built upon Fuzzowski. It is a specialized testing tool designed to identify vulnerabilities and bugs in OPC UA (Open Platform Communications Unified Architecture) implementations. These fuzzers typically operate by generating and sending a large number of malformed or unexpected messages to an OPC UA server or client, with the goal of triggering unexpected behavior or crashes.

Related contents:

- [L’ANSSI partage en open source un outil de test du protocole industriel OPC UA @ Agence nationale de la sécurité des systèmes d&amp;#039;information :fr:](https://cyber.gouv.fr/actualites/lanssi-partage-en-open-source-un-outil-de-test-du-protocole-industriel-opc-ua?ref=veillecyber.fr).]]>
            </summary>
            <updated>2025-08-28T19:15:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1350</id>
            <title type="text"><![CDATA[OASIS]]></title>
            <link rel="alternate" href="https://github.com/psyray/oasis" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1350"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Ollama Automated Security Intelligence Scanner.

 🛡️ An AI-powered security auditing tool that leverages Ollama models to detect and analyze potential security vulnerabilities in your code.

Advanced code security analysis through the power of AI

Related contents:

- [OASIS - Sécurisez votre code avec l&amp;#039;IA et Ollama @ Korben :fr:](https://korben.info/oasis-outil-ia-securite-code-ollama.html).]]>
            </summary>
            <updated>2025-08-28T19:41:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2639</id>
            <title type="text"><![CDATA[Am I Isolated]]></title>
            <link rel="alternate" href="https://github.com/edera-dev/am-i-isolated" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2639"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Validate the isolation posture of your container environment.

Am I Isolated is a security posture benchmarking tool.

It evaluates a given runtime environment and attempts to look for things which may be a security problem, as well as providing suggestions for solving the security problem.]]>
            </summary>
            <updated>2025-08-28T23:17:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2712</id>
            <title type="text"><![CDATA[garak]]></title>
            <link rel="alternate" href="https://github.com/NVIDIA/garak" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2712"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[the LLM vulnerability scanner. Generative AI Red-teaming &amp;amp; Assessment Kit

garak checks if an LLM can be made to fail in a way we don&amp;#039;t want. garak probes for hallucination, data leakage, prompt injection, misinformation, toxicity generation, jailbreaks, and many other weaknesses. If you know nmap, it&amp;#039;s nmap for LLMs.]]>
            </summary>
            <updated>2025-08-28T23:29:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2902</id>
            <title type="text"><![CDATA[🔒AcSecurity]]></title>
            <link rel="alternate" href="https://github.com/austincabler13/AcSecurity" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2902"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AcSecurity is a Python module designed to scan applications for common security vulnerabilities. It checks for hardcoded secrets, dependency vulnerabilities, and code quality issues.]]>
            </summary>
            <updated>2025-08-29T00:01:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2919</id>
            <title type="text"><![CDATA[twyn]]></title>
            <link rel="alternate" href="https://github.com/elementsinteractive/twyn" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2919"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security tool against dependency typosquatting attacks.

Twyn is a security tool that compares the name of your dependencies against a set of the most popular ones, in order to determine if there is any similarity between them, preventing you from using a potentially illegitimate one. In short, Twyn protects you against typosquatting attacks.]]>
            </summary>
            <updated>2025-08-29T00:02:40+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2920</id>
            <title type="text"><![CDATA[sastsweep]]></title>
            <link rel="alternate" href="https://github.com/chebuya/sastsweep" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2920"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automatically detect potential vulnerabilities and analyze repository metrics to prioritize open source security research targets .

sastsweep is a tool designed for identifying vulnerabilities in open source codebases at scale. It can gather and filter on key repository metrics such as popularity and project size, enabling targeted vulnerability research. It automatically detects potential vulnerabilities using semgrep and provides a streamlined HTML report, allowing researchers to quickly drill down to the affected portion of the codebase.]]>
            </summary>
            <updated>2025-08-29T00:02:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3066</id>
            <title type="text"><![CDATA[Penelope]]></title>
            <link rel="alternate" href="https://github.com/brightio/penelope" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3066"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Penelope Shell Handler.

Penelope is a shell handler designed to be easy to use and intended to replace netcat when exploiting RCE vulnerabilities. It is compatible with Linux and macOS and requires Python 3.6 or higher. It is a standalone script that does not require any installation or external dependencies, and it is intended to remain this way.]]>
            </summary>
            <updated>2025-08-29T00:28:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3085</id>
            <title type="text"><![CDATA[Vulnhuntr]]></title>
            <link rel="alternate" href="https://github.com/protectai/vulnhuntr" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3085"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Zero shot vulnerability discovery using LLMs. A tool to identify remotely exploitable vulnerabilities using LLMs and static code analysis.

Vulnhuntr leverages the power of LLMs to automatically create and analyze entire code call chains starting from remote user input and ending at server output for detection of complex, multi-step, security-bypassing vulnerabilities that go far beyond what traditional static code analysis tools are capable of performing. 

Related contents:

- [VulnHuntr - L&amp;#039;IA qui trouve des failles 0day dans votre code Python @ Korben :fr:](https://korben.info/vulnhuntr-ia-detecteur-vulnerabilites-0day-python.html).]]>
            </summary>
            <updated>2025-08-29T00:30:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3098</id>
            <title type="text"><![CDATA[EMBA]]></title>
            <link rel="alternate" href="https://www.securefirmware.de/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3098"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The firmware security analyzer.

EMBA is designed as the central firmware analysis and SBOM tool for penetration testers, product security teams, developers and responsible product managers. It supports the complete security analysis process starting with firmware extraction, doing static analysis and dynamic analysis via emulation, building the SBOM and finally generating a web report. EMBA automatically discovers possible weak spots and vulnerabilities in firmware. Examples are insecure binaries, old and outdated software components, potentially vulnerable scripts, or hard-coded passwords. EMBA is a command line tool with the possibility to generate an easy-to-use web report for further analysis.]]>
            </summary>
            <updated>2025-08-29T00:32:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3237</id>
            <title type="text"><![CDATA[VulnAPI]]></title>
            <link rel="alternate" href="https://vulnapi.cerberauth.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3237"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[API Security Vulnerability Scanner designed to help you secure your APIs. 

Your First Line of Defense in API Security. Scan your APIs for vulnerabilities with VulnAPI.

Help developers and security professionals quickly and efficiently scan their APIs for security vulnerabilities and weaknesses.

- [VulnAPI @ GitHub](https://github.com/cerberauth/vulnapi)]]>
            </summary>
            <updated>2025-08-29T00:56:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3317</id>
            <title type="text"><![CDATA[Octoscan]]></title>
            <link rel="alternate" href="https://github.com/synacktiv/octoscan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3317"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Octoscan is a static vulnerability scanner for GitHub action workflows. 

- [action octoscan @ GitHub](https://github.com/synacktiv/action-octoscan).]]>
            </summary>
            <updated>2025-08-29T01:09:00+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3491</id>
            <title type="text"><![CDATA[Mageni]]></title>
            <link rel="alternate" href="https://www.mageni.net/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3491"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Free and open-source vulnerability scanner.

Mageni is an open source vulnerability management platform. Mageni provides a faster, enjoyable, and leaner vulnerability management experience for modern cybersecurity programs.

- [Mageni @ GitHub](https://github.com/mageni/mageni).]]>
            </summary>
            <updated>2025-08-29T01:38:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4008</id>
            <title type="text"><![CDATA[Nuclei]]></title>
            <link rel="alternate" href="https://docs.projectdiscovery.io/tools/nuclei/overview" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4008"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A fast and customisable vulnerability scanner powered by simple YAML-based templates.

- [Nuclei @ GitHub](https://github.com/projectdiscovery/nuclei).
- [Nuclei Templates homepage](https://nuclei-templates.netlify.app/) ([Nuclei Templates @ GitHub](https://github.com/projectdiscovery/nuclei-templates)).
- [Nuclei: The Ultimate Guide to Fast and Customizable Vulnerability Scanning @ InfoSec Write-ups&amp;#039; Medium](https://infosecwriteups.com/nuclei-the-ultimate-guide-to-fast-and-customizable-vulnerability-scanning-c86c50168798).
- [Simplifying XSS Detection with Nuclei - A New Approach @ ProjectDiscovery Blog](https://blog.projectdiscovery.io/simplifying-xss-detection-with-nuclei/).]]>
            </summary>
            <updated>2025-08-29T03:05:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4113</id>
            <title type="text"><![CDATA[Security Scanner for Laravel]]></title>
            <link rel="alternate" href="https://ephort.dk/scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4113"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Check for free whether your Laravel website is safe or vulnerable before others do!

This is a free tool to all who wants to optimize and check the security on their Laravel website
While there are many security scanners out there, we thought that one was missing. That’s why we made this vulnerability scanner that focus specific on Laravel websites. We focused on known Laravel vulnerabilities, and made the scanner focus on them. 

- [In Depth: Pentesting Laravel part 1 - Passive Scans @ Securing Laravel](https://securinglaravel.com/in-depth-pentesting-laravel-part-1-passive-scans/).]]>
            </summary>
            <updated>2025-08-29T03:22:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4358</id>
            <title type="text"><![CDATA[Mantis]]></title>
            <link rel="alternate" href="https://phonepe.github.io/mantis/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4358"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning. 

Mantis is a command-line framework designed to automate the workflow of asset discovery, reconnaissance, and scanning. It takes the top-level domains as input, then seamlessly progresses to discovering corresponding assets, including subdomains and certificates. The tool performs reconnaissance on active assets and concludes with a comprehensive scan for vulnerabilities, secrets, misconfigurations and phishing domains - all powered by a blend of open-source and custom tools.

- [Mantis @ GitHub](https://github.com/PhonePe/mantis).]]>
            </summary>
            <updated>2025-08-29T04:03:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4618</id>
            <title type="text"><![CDATA[OSTE meta scanner]]></title>
            <link rel="alternate" href="https://github.com/OSTEsayed/OSTE-Meta-Scan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4618"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The OSTE meta scanner is a comprehensive web vulnerability scanner that combines multiple DAST scanners, including Nikto Scanner, OWASP ZAP, Nuclei, SkipFish, and Wapiti.]]>
            </summary>
            <updated>2025-08-29T04:46:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4640</id>
            <title type="text"><![CDATA[Grype]]></title>
            <link rel="alternate" href="https://github.com/anchore/grype" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4640"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A vulnerability scanner for container images and filesystems.

- [Grype @ Snapcraft](https://snapcraft.io/grype).

Related contents:

- [Grype MCP Server @ GitHub](https://github.com/anchore/grype-mcp).
- [EP 64: Ethical Retro Gaming @ Linux Matters](https://linuxmatters.sh/64/).]]>
            </summary>
            <updated>2025-09-23T05:50:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4674</id>
            <title type="text"><![CDATA[Vuls]]></title>
            <link rel="alternate" href="https://vuls.io/en/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4674"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Agentless Vulnerability Scanner for Linux/FreeBSD, Container, WordPress, Programming language libraries, Network devices 

- [Vuls @ GitHub](https://github.com/future-architect/vuls).]]>
            </summary>
            <updated>2025-08-29T04:55:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4751</id>
            <title type="text"><![CDATA[vulscan.nse]]></title>
            <link rel="alternate" href="https://www.computec.ch/projekte/vulscan/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4751"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Advanced vulnerability scanning with Nmap NSE.

Vulscan is a module which enhances nmap to a vulnerability scanner. The nmap option -sV enables version detection per service which is used to determine potential flaws according to the identified product. The data is looked up in an offline version of VulDB.

- [vulscan @ GitHub](https://github.com/scipag/vulscan).
- [Nmap Vulnerability Scan: How to Find Weak Systems Easily @ StationX](https://www.stationx.net/nmap-vulnerability-scan/).]]>
            </summary>
            <updated>2025-08-29T05:08:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4791</id>
            <title type="text"><![CDATA[OpenVAS]]></title>
            <link rel="alternate" href="https://openvas.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4791"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Vulnerability Assessment Scanner.

OpenVAS is a full-featured vulnerability scanner. Its capabilities include unauthenticated and authenticated testing, various high-level and low-level internet and industrial protocols, performance tuning for large-scale scans and a powerful internal programming language to implement any type of vulnerability test.

- [OpenVAS @ GitHub](https://github.com/greenbone/openvas-scanner).

Related contents:

- [OpenVAS - Le scanner de vulnérabilités open source qui vous dit la vérité sur votre serveur @ Korben :fr:](https://korben.info/openvas-scanner-vulnerabilites-gratuit-audit-secur.html).]]>
            </summary>
            <updated>2026-02-16T08:49:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4850</id>
            <title type="text"><![CDATA[reNgine]]></title>
            <link rel="alternate" href="https://yogeshojha.github.io/rengine/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4850"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Quickly discover the attack surface, and identify vulnerabilities using highly customizable and powerful scan engines. Enjoy peace of mind with reNgine&amp;#039;s continuous monitoring, deeper reconnaissance, and open-source powered Vulnerability Scanner.

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine&amp;#039;s correlation, it just makes recon effortless.

- [reNgine @ GitHub](https://github.com/yogeshojha/rengine)]]>
            </summary>
            <updated>2025-08-29T05:25:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4998</id>
            <title type="text"><![CDATA[OWASP Amass]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-amass/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4998"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The OWASP Amass Project performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.

The OWASP Amass Project has developed a framework to help information security professionals perform network mapping of attack surfaces and external asset discovery using open source intelligence gathering and reconnaissance techniques.

- [OWASP Amass](https://github.com/owasp-amass/amass).]]>
            </summary>
            <updated>2026-03-20T08:26:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5004</id>
            <title type="text"><![CDATA[Active Directory Security Assessment by Purple Knight]]></title>
            <link rel="alternate" href="https://www.purple-knight.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5004"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[#1 Active Directory security assessment community tool

Active Directory, Azure AD (now called Entra ID), and Okta vulnerabilities can give attackers virtually unrestricted access to your organization’s network and resources. Semperis built Purple Knight—a free AD, Azure AD, and Okta security assessment tool—to help you discover indicators of exposure (IoEs) and indicators of compromise (IoCs) in your hybrid AD environment. Download Purple Knight and dramatically reduce your AD attack surface today.]]>
            </summary>
            <updated>2025-08-29T05:51:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5067</id>
            <title type="text"><![CDATA[Grype]]></title>
            <link rel="alternate" href="https://github.com/anchore/Grype" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5067"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A vulnerability scanner for container images and filesystems.]]>
            </summary>
            <updated>2025-08-29T06:01:22+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5329</id>
            <title type="text"><![CDATA[PingCastle]]></title>
            <link rel="alternate" href="https://www.pingcastle.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5329"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Get Active Directory Security at 80% in 20% of the time.

PingCastle is an Active Directory vunerability and misconfiguration scanner.

[PingCastle @ GitHub](https://github.com/vletoux/pingcastle/).]]>
            </summary>
            <updated>2025-08-29T06:44:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5415</id>
            <title type="text"><![CDATA[Nuclei]]></title>
            <link rel="alternate" href="https://nuclei.projectdiscovery.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5415"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Community Powered Vulnerability Scanner


[Nuclei @ GitHub](https://github.com/projectdiscovery/nuclei).]]>
            </summary>
            <updated>2025-08-29T06:59:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6293</id>
            <title type="text"><![CDATA[OSV-Scanner]]></title>
            <link rel="alternate" href="https://github.com/google/osv-scanner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6293"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Vulnerability scanner written in Go which uses the data provided by https://osv.dev.
Use OSV-Scanner to find existing vulnerabilities affecting your project&amp;#039;s dependencies.
OSV-Scanner provides an officially supported frontend to the OSV database that connects a project’s list of dependencies with the vulnerabilities that affect them.]]>
            </summary>
            <updated>2025-08-29T09:26:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6404</id>
            <title type="text"><![CDATA[Trivy]]></title>
            <link rel="alternate" href="https://trivy.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6404"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Trivy (pronunciation) is a comprehensive and versatile security scanner. Trivy has scanners that look for security issues, and targets where it can find those issues.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more.

- [Trivy @ GitHub](https://github.com/aquasecurity/trivy).
- [Trivy Documentation](https://aquasecurity.github.io/trivy/).
- [Integrer la sécurité dés le départ avec Trivy @ Culture et Outils DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser-projets-trivy/).
- [Trivy Is Noise by Default, Here’s the Seven-Rule Filter That Catches Real Risk @ DevOpsDynamo&amp;#039;s Medium](https://medium.com/@DynamoDevOps/trivy-is-noise-by-default-heres-the-seven-rule-filter-that-catches-real-risk-05c4c3249c26).
- [Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation](https://cd.foundation/blog/2026/02/06/blueprinting-security/).
- [20 Days Later: Trivy Compromise, Act II @ Boost Security Labs](https://labs.boostsecurity.io/articles/20-days-later-trivy-compromise-act-ii/).
- [Trivy supply chain compromise: What Docker Hub users should know @ Docker blog](https://www.docker.com/blog/trivy-supply-chain-compromise-what-docker-hub-users-should-know/).
- [Trivy compromis une seconde fois : la release v0.69.4 était empoisonnée @ DevSecOps :fr:](https://blog.stephane-robert.info/post/trivy-actii/).
- [When Security Scans Break the Brain: Solving Trivy’s etcd Exhaustion Problem @ aqua](https://www.aquasec.com/blog/when-security-scans-break-the-brain-solving-trivys-etcd-exhaustion-problem/).]]>
            </summary>
            <updated>2026-07-06T11:39:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6419</id>
            <title type="text"><![CDATA[Intruder]]></title>
            <link rel="alternate" href="https://www.intruder.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6419"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An Effortless Vulnerability Scanner.
Find your weaknesses, before the hackers do.
Intruder is an online vulnerability scanner that finds cyber security weaknesses in your digital infrastructure, to avoid costly data breaches.]]>
            </summary>
            <updated>2025-08-29T09:47:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6946</id>
            <title type="text"><![CDATA[AutoPWN Suite]]></title>
            <link rel="alternate" href="https://kaangultekin.net/projects/autopwn-suite/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6946"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

- [AutoPWN Suite @ GitHub](https://github.com/GamehunterKaan/AutoPWN-Suite).]]>
            </summary>
            <updated>2026-03-27T11:15:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7099</id>
            <title type="text"><![CDATA[OWASP ZAP]]></title>
            <link rel="alternate" href="https://www.zaproxy.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7099"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The world&amp;#039;s most widely used web app scanner. Free and open source. Actively maintained by a dedicated international team of volunteers.

- [ZAP @ GitHub](https://github.com/zaproxy/zaproxy).

Related  contents:

- [Automating OWASP PTK with ZAP (Phase 1) @ ZAP](https://www.zaproxy.org/blog/2026-05-06-automating-owasp-ptk-with-zap-phase-1/).
- [Automating OWASP PTK with ZAP (Phase 2) @ ZAP](https://www.zaproxy.org/blog/2026-06-05-automating-owasp-ptk-with-zap-phase-2/).
- [Building a Scanner and a Community with Zed Attack Proxy - Simon Bennetts - ASW #254  @ YouTube](https://www.youtube.com/watch?v=alIBoz7AooI).
- [Strengthening Your Web Application Security: Integrating OWASP ZAP with GitHub Actions @ System Weakness](https://systemweakness.com/strengthening-your-web-application-security-integrating-owasp-zap-with-github-actions-2c177545f21d).]]>
            </summary>
            <updated>2026-06-11T06:09:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7194</id>
            <title type="text"><![CDATA[Checkov]]></title>
            <link rel="alternate" href="https://www.checkov.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7194"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Checkov scans cloud infrastructure configurations to find misconfigurations before they&amp;#039;re deployed.

Checkov uses a common command line interface to manage and analyze infrastructure as code (IaC) scan results across platforms such as Terraform, CloudFormation, Kubernetes, Helm, ARM Templates and Serverless framework.

- [Checkov @ GitHub](https://github.com/bridgecrewio/checkov).

Related contents:

- [Checkov vérifie votre code d&amp;#039;infrastructure @ Culture et Outils DevSecOps :fr:](https://blog.stephane-robert.info/docs/securiser/outils/checkov/).
- [Getting Started with Terraform Vulnerability Scanning @ scalr](https://scalr-cdn.com/getting-started-with-terraform-vulnerability-scanning/).]]>
            </summary>
            <updated>2025-11-17T06:06:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/9390</id>
            <title type="text"><![CDATA[Sucuri]]></title>
            <link rel="alternate" href="https://sitecheck.sucuri.net/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/9390"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Free website malware and security checker

Enter a URL like example.com and the Sucuri SiteCheck scanner will check the website for known malware, viruses, blacklisting status, website errors, out-of-date software, and malicious code.]]>
            </summary>
            <updated>2025-08-29T18:19:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/9475</id>
            <title type="text"><![CDATA[Nikto]]></title>
            <link rel="alternate" href="http://cirt.net/nikto2" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/9475"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Nikto web server scanner.

Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files/CGIs, checks for outdated versions of over 1200 servers, and version specific problems on over 270 servers.

It also checks for server configuration items such as the presence of multiple index files, HTTP server options, and will attempt to identify installed web servers and software. Scan items and plugins are frequently updated and can be automatically updated.

- [Nikto @ GitHub](https://github.com/sullo/nikto).
- [Nikto : outil pour scanner la sécurité d’un serveur web @ Memo-Linux.com](https://memo-linux.com/nikto-outil-scanner-de-securite-serveur-web/).
- [ La version 2.5 de Nikto est sortie @ Stéphane MORICO&amp;#039;s LinkedIn](https://www.linkedin.com/posts/stephane-morico_la-version-25-de-nikto-est-sortie-nikto-activity-7137480505309937665-jQDK/).]]>
            </summary>
            <updated>2025-08-29T18:18:00+00:00</updated>
        </entry>
    </feed>
