Simon Bennetts

@psiinon.bsky.social

ZAP Project Lead

An Insecure Java Deserialization vulnerability has been reported in a ZAP add-on via Neo by ProjectDiscovery. Update your ZAP add-ons now, and definitely update from older versions of ZAP. For more details see: www.zaproxy.org/blog/2026-06...

Java Deserialization Vulnerability in ZAP Viewstate Add-on

A Java Deserialization Vulnerability has been found in the ZAP Viewstate Add-on. Update your ZAP add-ons now, and if you are on an older version of ZAP then update that ASAP.

zaproxy.org

We have made a good start on #AI integration in @zaproxy.org We know some of you will be very anti-AI, so this will be optional and opt-in. We have lots of plans, but feedback also appreciated - what integrations would you really like to see .. or not see?

Dear Open Source contributors: If your AI spent X mins on "enhancement" or "refactorings" but the project maintainer needs >X mins to fix guideline violations and broken code, you didn’t contribute—you drained time and motivation from Open Source maintainers. infosec.exchange/@bkimminich/...

Björn Kimminich :verified: (@bkimminich@infosec.exchange)

Dear aspiring Open Source contributors: If you spent X minutes to let your AI tool make some "enhancement", "refactoring", or "clean up", and it takes the project maintainer >X minutes to review and l...

infosec.exchange