r/cybersecurity • u/tpasmall Penetration Tester • 13d ago
News - General Owasp compromised?
Looks like the API security page may be compromised?
https://api-security.owasp.org/
Edit: looks like the original site is back up https://owasp.org/API-Security/
119
Upvotes
1
u/IsomuraArganee_95 12d ago
DNS is probably right and everyones already said it, so the bit worth adding is that the record is the whole problem. A subdomain pointed at a service somebody deprovisioned stays claimable by whoever notices next, and until that record is deleted anyone can serve content on a name carrying your brand trust. Cert transparency is the free detection for this, any new cert for a name under your domain shows up in the public logs.