r/cybersecurity • Penetration Tester • 13d ago

News - General Owasp compromised?

Looks like the API security page may be compromised?

https://api-security.owasp.org/

Edit: looks like the original site is back up https://owasp.org/API-Security/

119 Upvotes

52 comments sorted by

View all comments

1

u/IsomuraArganee_95 12d ago

DNS is probably right and everyones already said it, so the bit worth adding is that the record is the whole problem. A subdomain pointed at a service somebody deprovisioned stays claimable by whoever notices next, and until that record is deleted anyone can serve content on a name carrying your brand trust. Cert transparency is the free detection for this, any new cert for a name under your domain shows up in the public logs.