<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>The ZAP Blog on ZAP</title>
    <link>/blog/</link>
    <description>Recent content in The ZAP Blog on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 21 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="/blog/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Scanning MCP Servers with ZAP</title>
      <link>/blog/2026-05-21-scanning-mcp-servers-with-zap/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-05-21-scanning-mcp-servers-with-zap/</guid>
      <description>ZAP can now scan MCP (Model Context Protocol) servers as a first-class target. Import an MCP server from the ZAP desktop or the Automation Framework, or run the new action-mcp-scan GitHub Action to scan one from CI.</description>
    </item>
    <item>
      <title>Automating OWASP PTK with ZAP (Phase 1)</title>
      <link>/blog/2026-05-06-automating-owasp-ptk-with-zap-phase-1/</link>
      <pubDate>Wed, 06 May 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-05-06-automating-owasp-ptk-with-zap-phase-1/</guid>
      <description>ZAP&amp;rsquo;s Automation Framework can now drive OWASP PTK scans using the Client Spider. This is an early release - we want you to try it and give us feedback while we work toward deeper integration with ZAP&amp;rsquo;s active and passive scan engines.</description>
    </item>
    <item>
      <title>ZAP Updates - April 2026</title>
      <link>/blog/2026-05-01-zap-updates-april-2026/</link>
      <pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-05-01-zap-updates-april-2026/</guid>
      <description>ZAP was started nearly &lt;strong&gt;10 million times&lt;/strong&gt; in April, and the main zaproxy repo hit &lt;strong&gt;15,000 GitHub stars&lt;/strong&gt;. Read on for blog post summaries and the full add-on changelog.</description>
    </item>
    <item>
      <title>Vibe Coding Security Fixes</title>
      <link>/blog/2026-04-15-vibe-coding-security-fixes/</link>
      <pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-04-15-vibe-coding-security-fixes/</guid>
      <description>ZAP now has a &amp;ldquo;Generate Fix Prompt&amp;rdquo; option that copies everything an LLM needs to fix a vulnerability straight to your clipboard. Also: ZAP was run 9.5 million times in March. Vibe coding, anyone?</description>
    </item>
    <item>
      <title>Use ZAP with KRO in Kubernetes</title>
      <link>/blog/2026-04-13-use-zap-with-kro-in-kubernetes/</link>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-04-13-use-zap-with-kro-in-kubernetes/</guid>
      <description>Learn how to integrate ZAP with KRO in a Kubernetes cluster to scan the security of each new deployment.</description>
    </item>
    <item>
      <title>ZAP Updates - March 2026</title>
      <link>/blog/2026-04-03-zap-updates-march-2026/</link>
      <pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-04-03-zap-updates-march-2026/</guid>
      <description>ZAP was started nearly &lt;strong&gt;9.5 million times&lt;/strong&gt; in March, published integrations with 3 other open source projects, and released the first of many AI related features.</description>
    </item>
    <item>
      <title>The ZAP MCP Server</title>
      <link>/blog/2026-04-02-zap-mcp-server/</link>
      <pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-04-02-zap-mcp-server/</guid>
      <description>Connect AI assistants like Claude and ChatGPT to ZAP via the Model Context Protocol. Start scans, read alerts, and explore your application—all through natural conversation.</description>
    </item>
    <item>
      <title>OWASP PTK Findings as ZAP Alerts (Juice Shop Walkthrough)</title>
      <link>/blog/2026-04-01-owasp-ptk-findings-to-zap-alerts/</link>
      <pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-04-01-owasp-ptk-findings-to-zap-alerts/</guid>
      <description>OWASP PTK 9.8.0 and the ZAP OWASP PTK add-on 0.3.0 now let ZAP display OWASP PTK findings directly as ZAP Alerts. This post shows how to install the add-on, choose which PTK rules to run (SAST / IAST / DAST), optionally auto-start scans on browser launch, and then scan OWASP Juice Shop with all results visible in ZAP.</description>
    </item>
    <item>
      <title>Guided ZAP Scans: Faster CI/CD Feedback Using Static Analysis</title>
      <link>/blog/2026-03-27-guided-zap-scans-faster-cicd-feedback-using-sast/</link>
      <pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-03-27-guided-zap-scans-faster-cicd-feedback-using-sast/</guid>
      <description>This post describes an approach that uses static analysis findings to guide ZAP&amp;rsquo;s active scans toward the most relevant endpoints. The result is a faster scanning mode suited for CI/CD pipelines, built on top of ZAP&amp;rsquo;s Automation Framework.</description>
    </item>
    <item>
      <title>Introducing DeepViolet</title>
      <link>/blog/2026-03-19-introducing-deepviolet/</link>
      <pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-03-19-introducing-deepviolet/</guid>
      <description>Introducing DeepViolet: The Engine Behind ZAP&amp;rsquo;s New TLS Analysis</description>
    </item>
    <item>
      <title>ZAP Updates - February 2026</title>
      <link>/blog/2026-03-02-zap-updates-february-2026/</link>
      <pubDate>Mon, 02 Mar 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-03-02-zap-updates-february-2026/</guid>
      <description>February was another busy month for the ZAP project, with improvements across browser automation, GraphQL and the Encode/Decode/Hash add-on.</description>
    </item>
    <item>
      <title>Custom Browsers and Preferences</title>
      <link>/blog/2026-02-24-custom-browsers-and-preferences/</link>
      <pubDate>Tue, 24 Feb 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-02-24-custom-browsers-and-preferences/</guid>
      <description>You can now add custom browsers to ZAP and manage any browser preferences.</description>
    </item>
    <item>
      <title>Using ZAP&#39;s Encode/Decode/Hash Add-on with CyberChef via Encode/Decode Scripts</title>
      <link>/blog/2026-02-17-encoder-cyberchef-via-scripts/</link>
      <pubDate>Tue, 17 Feb 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-02-17-encoder-cyberchef-via-scripts/</guid>
      <description>Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.</description>
    </item>
    <item>
      <title>Detecting Circular Type References in GraphQL Schemas</title>
      <link>/blog/2026-02-06-detecting-graphql-cycles/</link>
      <pubDate>Fri, 06 Feb 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-02-06-detecting-graphql-cycles/</guid>
      <description>ZAP can now detect cycles in GraphQL schemas that could lead to denial of service attacks.</description>
    </item>
    <item>
      <title>ZAP Updates - 2025 Highlights and Plans for 2026</title>
      <link>/blog/2026-02-02-zap-updates-2025-highlights-2026-plans/</link>
      <pubDate>Mon, 02 Feb 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-02-02-zap-updates-2025-highlights-2026-plans/</guid>
      <description>Highlights of 2025 and our initial plans for 2026, including more 3rd Party tool integrations, enhanced exploring and, yes, AI integration!</description>
    </item>
    <item>
      <title>OWASP PTK Integration with ZAP</title>
      <link>/blog/2026-01-19-owasp-ptk-add-on/</link>
      <pubDate>Mon, 19 Jan 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026-01-19-owasp-ptk-add-on/</guid>
      <description>OWASP PTK is now pre-installed in the browsers launched by ZAP (Chrome, Edge and Firefox). This post shows how to run PTK’s DAST, IAST, SAST, and SCA inside the same authenticated session you’re testing, plus practical JWT and cookie workflows—while ZAP remains your traffic and context hub.</description>
    </item>
    <item>
      <title>ZAP 2.17.0</title>
      <link>/blog/2025-12-15-zap-2-17-0/</link>
      <pubDate>Mon, 15 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-12-15-zap-2-17-0/</guid>
      <description>ZAP 2.17.0 has just been &lt;a href=&#34;/docs/desktop/releases/2.17.0/&#34;&gt;released&lt;/a&gt;. The release includes core performance improvements and will significantly reduce the number of “duplicate” alerts reported.</description>
    </item>
    <item>
      <title>React2Shell Detection with ZAP</title>
      <link>/blog/2025-12-05-react2shell-detection-with-zap/</link>
      <pubDate>Fri, 05 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-12-05-react2shell-detection-with-zap/</guid>
      <description>React2Shell is the latest big &amp;ldquo;named&amp;rdquo; vulnerability - heres how you can detect it with ZAP.</description>
    </item>
    <item>
      <title>ZAP Updates - November 2025</title>
      <link>/blog/2025-12-03-zap-updates-november-2025/</link>
      <pubDate>Wed, 03 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-12-03-zap-updates-november-2025/</guid>
      <description>2.17.0 is coming soon, along with Insights and fixes for some issues that caused ZAP to log 50 million errors in one day!</description>
    </item>
    <item>
      <title>Enhancing ZAP with AI for Bug Bounty Hunting</title>
      <link>/blog/2025-11-28-enhancing-zap-with-ai-for-bug-bounty-hunting/</link>
      <pubDate>Fri, 28 Nov 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-11-28-enhancing-zap-with-ai-for-bug-bounty-hunting/</guid>
      <description>Building an intelligent security testing system that leverages ZAP&amp;rsquo;s automation capabilities and machine learning to improve vulnerability detection</description>
    </item>
    <item>
      <title>50 Million Errors in One Day?!</title>
      <link>/blog/2025-11-25-50-million-errors-in-one-day/</link>
      <pubDate>Tue, 25 Nov 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-11-25-50-million-errors-in-one-day/</guid>
      <description>ZAP logged a LOT of errors yesterday - heres why, and what we have already done to address the underlying problems</description>
    </item>
    <item>
      <title>ZAP Updates - October 2025</title>
      <link>/blog/2025-11-06-zap-updates-october-2025/</link>
      <pubDate>Thu, 06 Nov 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-11-06-zap-updates-october-2025/</guid>
      <description>Systemic alerts, check for updates bug, auth improvements, project pulse, etc See what the ZAP team has been up to.</description>
    </item>
    <item>
      <title>SHH! ZAP Was Not So Silent</title>
      <link>/blog/2025-10-21-zap-was-not-so-silent/</link>
      <pubDate>Tue, 21 Oct 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-10-21-zap-was-not-so-silent/</guid>
      <description>A new ZAP scan rule unintentionally caused a Check for Updates call even when &amp;ldquo;silent&amp;rdquo; mode was used.</description>
    </item>
    <item>
      <title>Solving Caido Labs</title>
      <link>/blog/2025-10-15-solving-caido-labs/</link>
      <pubDate>Wed, 15 Oct 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-10-15-solving-caido-labs/</guid>
      <description>In this blog we show how to solve Caido labs using ZAP.</description>
    </item>
    <item>
      <title>ZAP Updates - September 2025</title>
      <link>/blog/2025-10-01-zap-updates-september-2025/</link>
      <pubDate>Wed, 01 Oct 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-10-01-zap-updates-september-2025/</guid>
      <description>Configuring scan policies with alert tags, WAVSEP adoption, alert de-duplication and a new add-on publishing guide.</description>
    </item>
    <item>
      <title>Alert De-Duplication</title>
      <link>/blog/2025-09-30-alert-de-duplication/</link>
      <pubDate>Tue, 30 Sep 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-09-30-alert-de-duplication/</guid>
      <description>How and why we will be reporting fewer &amp;ldquo;duplicate&amp;rdquo; alerts in ZAP.</description>
    </item>
    <item>
      <title>ZAP is Adopting WAVSEP</title>
      <link>/blog/2025-09-08-zap-is-adopting-wavsep/</link>
      <pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-09-08-zap-is-adopting-wavsep/</guid>
      <description>The ZAP team has forked and will maintain WAVSEP going forwards. This blog post explains why.</description>
    </item>
    <item>
      <title>Configuring Scan Policies with Alert Tags</title>
      <link>/blog/2025-09-03-configuring-scan-policies-with-alert-tags/</link>
      <pubDate>Wed, 03 Sep 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-09-03-configuring-scan-policies-with-alert-tags/</guid>
      <description>A new feature in ZAP&amp;rsquo;s automation framework allows you to configure scan policies using alert tags, making it easier to target specific types of vulnerabilities without manually managing individual scan rules.</description>
    </item>
    <item>
      <title>ZAP Updates - August 2025</title>
      <link>/blog/2025-09-02-zap-updates-august-2025/</link>
      <pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-09-02-zap-updates-august-2025/</guid>
      <description>Microsoft Online Login Support, forking wavsep and much, much more!</description>
    </item>
    <item>
      <title>ZAP Updates - July 2025</title>
      <link>/blog/2025-08-01-zap-updates-july-2025/</link>
      <pubDate>Fri, 01 Aug 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-08-01-zap-updates-july-2025/</guid>
      <description>Authentication improvements, Edge support, timing rule changes, Docker news, and a new scan rule.</description>
    </item>
    <item>
      <title>The New &#39;ZAP is Out of Date&#39; Rule</title>
      <link>/blog/2025-07-25-the-new-zap-is-out-of-date-rule/</link>
      <pubDate>Fri, 25 Jul 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-07-25-the-new-zap-is-out-of-date-rule/</guid>
      <description>If you are using an old version of ZAP then you might start seeing a new alert&amp;hellip;</description>
    </item>
    <item>
      <title>Timing Related Scan Rule Changes</title>
      <link>/blog/2025-07-22-timing-rule-changes/</link>
      <pubDate>Tue, 22 Jul 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-07-22-timing-rule-changes/</guid>
      <description>Scan rules related to time based attacks have been split or renamed.</description>
    </item>
    <item>
      <title>Edge Support</title>
      <link>/blog/2025-07-10-edge-support/</link>
      <pubDate>Thu, 10 Jul 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-07-10-edge-support/</guid>
      <description>ZAP now has &amp;ldquo;tier 1&amp;rdquo; support for Microsoft Edge, including exploring, crawling, and attacking.</description>
    </item>
    <item>
      <title>Authentication Improvements</title>
      <link>/blog/2025-07-03-authentication-improvements/</link>
      <pubDate>Thu, 03 Jul 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-07-03-authentication-improvements/</guid>
      <description>We&amp;rsquo;ve made a lot of improvements in ZAP&amp;rsquo;s handling of authentication - here&amp;rsquo;s a summary of the most significant changes we&amp;rsquo;ve made.</description>
    </item>
    <item>
      <title>ZAP Updates - June 2025</title>
      <link>/blog/2025-07-01-zap-updates-june-2025/</link>
      <pubDate>Tue, 01 Jul 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-07-01-zap-updates-june-2025/</guid>
      <description>A new Intro video, lots of authentication work, and more news on the ZAP browser extensions.</description>
    </item>
    <item>
      <title>ZAP Updates - April 2025</title>
      <link>/blog/2025-05-05-zap-updates-april-2025/</link>
      <pubDate>Mon, 05 May 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-05-05-zap-updates-april-2025/</guid>
      <description>April 2025 updates and ongoing feature development statuses.</description>
    </item>
    <item>
      <title>ZAP Wins Inaugural DefectDojo Award for Open-Source Cybersecurity</title>
      <link>/blog/2025-04-22-zap-wins-inaugural-defectdojo-award-for-open-source/</link>
      <pubDate>Tue, 22 Apr 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-04-22-zap-wins-inaugural-defectdojo-award-for-open-source/</guid>
      <description>ZAP was recognised as being one of the best dynamic application security testing (DAST) Tools.</description>
    </item>
    <item>
      <title>PortSwigger Labs: Broken Brute-Force Protection, IP Block</title>
      <link>/blog/2025-04-09-portswigger-labs-broken-brute-force-protection-ip-block/</link>
      <pubDate>Wed, 09 Apr 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-04-09-portswigger-labs-broken-brute-force-protection-ip-block/</guid>
      <description>Walkthrough for the PortSwigger lab, &amp;ldquo;Broken brute-force protection, IP block&amp;rdquo;.</description>
    </item>
    <item>
      <title>ZAP Updates - March 2025</title>
      <link>/blog/2025-04-02-zap-updates-march-2025/</link>
      <pubDate>Wed, 02 Apr 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-04-02-zap-updates-march-2025/</guid>
      <description>We released &lt;a href=&#34;/blog/2025-03-25-zap-2-16-1/&#34;&gt;2.16.1&lt;/a&gt; and made more authentication handling improvements.</description>
    </item>
    <item>
      <title>ZAP 2.16.1</title>
      <link>/blog/2025-03-25-zap-2-16-1/</link>
      <pubDate>Tue, 25 Mar 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-03-25-zap-2-16-1/</guid>
      <description>ZAP 2.16.1 has just been &lt;a href=&#34;/docs/desktop/releases/2.16.1/&#34;&gt;released&lt;/a&gt;. This is a bug fix release, along with some minor enhancements</description>
    </item>
    <item>
      <title>ZAP Updates - February 2025</title>
      <link>/blog/2025-03-03-zap-updates-february-2025/</link>
      <pubDate>Mon, 03 Mar 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-03-03-zap-updates-february-2025/</guid>
      <description>Authentication, authentication, authentication&amp;hellip; And there will be a 2.16.1 release &amp;ldquo;soon&amp;rdquo;.</description>
    </item>
    <item>
      <title>Solving Portswigger Lab File Path Traversal Simple Case with ZAP</title>
      <link>/blog/2025-02-27-portswigger-lab-file-path-traversal-simple-case/</link>
      <pubDate>Thu, 27 Feb 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-02-27-portswigger-lab-file-path-traversal-simple-case/</guid>
      <description>Video and explanation of How to Solve the Portswigger labs using ZAP, in this case: &amp;lsquo;Path Traversal Simple Case&amp;rsquo;</description>
    </item>
    <item>
      <title>ZAP Updates - January 2025</title>
      <link>/blog/2025-02-04-zap-updates-january-2025/</link>
      <pubDate>Tue, 04 Feb 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-02-04-zap-updates-january-2025/</guid>
      <description>Starting 2025 with a full release, a new way to crawl modern web apps, and better authentication capabilities.</description>
    </item>
    <item>
      <title>The Client Spider</title>
      <link>/blog/2025-01-31-client-spider/</link>
      <pubDate>Fri, 31 Jan 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-01-31-client-spider/</guid>
      <description>We introduced a new Client Spider in ZAP 2.16.0, this blog post and video explain why we did that, how it works, and where it’s going</description>
    </item>
    <item>
      <title>ZAP 2.16.0</title>
      <link>/blog/2025-01-10-zap-2-16-0/</link>
      <pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate>
      <guid>/blog/2025-01-10-zap-2-16-0/</guid>
      <description>ZAP 2.16.0 has just been &lt;a href=&#34;/docs/desktop/releases/2.16.0/&#34;&gt;released&lt;/a&gt;. It includes a brand new spider, detachable tabs, policy definitions, and lots more&amp;hellip;</description>
    </item>
    <item>
      <title>Use ZAP with Flagger in Kubernetes</title>
      <link>/blog/2024-12-24-use-zap-with-flagger-in-kubernetes/</link>
      <pubDate>Tue, 24 Dec 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-12-24-use-zap-with-flagger-in-kubernetes/</guid>
      <description>Learn how to integrate ZAP with Flagger in a Kubernetes cluster to scan the security of each new deployment.</description>
    </item>
    <item>
      <title>ZAP Updates - November 2024</title>
      <link>/blog/2024-12-02-zap-updates-november-2024/</link>
      <pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-12-02-zap-updates-november-2024/</guid>
      <description>A brand new Scan Policies add-on, how to integrate ZAP with OWASP Noir and ZAP 2.16.0 is getting very close..</description>
    </item>
    <item>
      <title>Powering Up DAST with ZAP and Noir</title>
      <link>/blog/2024-11-11-powering-up-dast-with-zap-and-noir/</link>
      <pubDate>Mon, 11 Nov 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-11-11-powering-up-dast-with-zap-and-noir/</guid>
      <description>Integrating Noir, a tool for discovering hidden endpoints in source code, with ZAP enhances dynamic application security testing (DAST).</description>
    </item>
    <item>
      <title>ZAP Updates - October 2024</title>
      <link>/blog/2024-11-01-zap-updates-october-2024/</link>
      <pubDate>Fri, 01 Nov 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-11-01-zap-updates-october-2024/</guid>
      <description>ZAP Updates are back after a small break. Read about the updates from October, including an upgrade to Java 17, scanning of sequenced requests, a potential LLM integration, and more.</description>
    </item>
    <item>
      <title>Improving Fuzzing Payloads for LLMs with FuzzAI</title>
      <link>/blog/2024-09-30-improving-fuzzing-payloads-for-llms-with-fuzzai/</link>
      <pubDate>Mon, 30 Sep 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-09-30-improving-fuzzing-payloads-for-llms-with-fuzzai/</guid>
      <description>Improving Fuzzing Payloads for LLMs with FuzzAI, and a call for community feedback.</description>
    </item>
    <item>
      <title>ZAP Has Joined Forces With Checkmarx</title>
      <link>/blog/2024-09-24-zap-has-joined-forces-with-checkmarx/</link>
      <pubDate>Tue, 24 Sep 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-09-24-zap-has-joined-forces-with-checkmarx/</guid>
      <description>This is a huge investment (and vote of confidence) in ZAP and will secure the project’s future success.</description>
    </item>
    <item>
      <title>ZAP Scripts are now Full Scan Rules!</title>
      <link>/blog/2024-07-17-script-scan-rules/</link>
      <pubDate>Wed, 17 Jul 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-07-17-script-scan-rules/</guid>
      <description>ZAP scripts can now do everything that scan rules can.</description>
    </item>
    <item>
      <title>Polyfill.io Script Detection</title>
      <link>/blog/2024-06-27-polyfill.io-script-detection/</link>
      <pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-06-27-polyfill.io-script-detection/</guid>
      <description>A new scan rule which allows you to find out which of your sites are loading scripts from polyfill.io really quickly.</description>
    </item>
    <item>
      <title>Should ZAP Switch to a Non-OSI Approved Licence?</title>
      <link>/blog/2024-06-07-should-zap-switch-to-a-non-osi-licence/</link>
      <pubDate>Fri, 07 Jun 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-06-07-should-zap-switch-to-a-non-osi-licence/</guid>
      <description>Yes, we are still struggling to find a way to make ZAP development sustainable.</description>
    </item>
    <item>
      <title>ZAP Updates - May 2024</title>
      <link>/blog/2024-06-03-zap-updates-may-2024/</link>
      <pubDate>Mon, 03 Jun 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-06-03-zap-updates-may-2024/</guid>
      <description>It was another &amp;ldquo;full release&amp;rdquo; month, with 2.15.0 and a brand new add-on for gRPC support.</description>
    </item>
    <item>
      <title>Introducing the gRPC Add-on</title>
      <link>/blog/2024-05-21-introducing-the-grpc-addon/</link>
      <pubDate>Tue, 21 May 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-05-21-introducing-the-grpc-addon/</guid>
      <description>Introducing a new add-on for viewing and attacking gRPC endpoints.</description>
    </item>
    <item>
      <title>ZAP 2.15.0</title>
      <link>/blog/2024-05-07-zap-2-15-0/</link>
      <pubDate>Tue, 07 May 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-05-07-zap-2-15-0/</guid>
      <description>ZAP 2.15.0 has just been &lt;a href=&#34;/docs/desktop/releases/2.15.0/&#34;&gt;released&lt;/a&gt;, and adds support for scripts as first class scan rules, restructured desktop menu items, and more&amp;hellip;</description>
    </item>
    <item>
      <title>ZAP Updates - April 2024</title>
      <link>/blog/2024-05-01-zap-updates-april-2024/</link>
      <pubDate>Wed, 01 May 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-05-01-zap-updates-april-2024/</guid>
      <description>ZAP professional services, a new Docker Hub org, a new GitHub Action and 2.15.0 is coming soon.</description>
    </item>
    <item>
      <title>ZAP Professional Services!</title>
      <link>/blog/2024-04-08-zap-professional-services/</link>
      <pubDate>Mon, 08 Apr 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-04-08-zap-professional-services/</guid>
      <description>ZAP Professional Services are now available, delivered by key members of the ZAP Core Team. Money raised from these services will help fund ZAP development.</description>
    </item>
    <item>
      <title>ZAP Updates - March 2024</title>
      <link>/blog/2024-04-02-zap-updates-march-2024/</link>
      <pubDate>Tue, 02 Apr 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-04-02-zap-updates-march-2024/</guid>
      <description>ZAP funding, the Open Source Fellowship, ZAProxy Ltd, script scan rules as first class scan rules.</description>
    </item>
    <item>
      <title>Support Changes</title>
      <link>/blog/2024-03-18-support-changes/</link>
      <pubDate>Mon, 18 Mar 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-03-18-support-changes/</guid>
      <description>Changes that we are having to put in place regarding ZAP support.</description>
    </item>
    <item>
      <title>ZAP Funding and the Open Source Fellowship</title>
      <link>/blog/2024-03-13-zap-funding-and-the-open-source-fellowship/</link>
      <pubDate>Wed, 13 Mar 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-03-13-zap-funding-and-the-open-source-fellowship/</guid>
      <description>ZAP is now supported by the Crash Override Open Source Fellowship!</description>
    </item>
    <item>
      <title>Unveiling the ZAP User Personas</title>
      <link>/blog/2024-03-11-user-personas-poll-results/</link>
      <pubDate>Mon, 11 Mar 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-03-11-user-personas-poll-results/</guid>
      <description>Unveiling the ZAP User Personas - Insights from Our Community</description>
    </item>
    <item>
      <title>ZAP Updates - February 2024</title>
      <link>/blog/2024-03-04-zap-updates-february-2024/</link>
      <pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-03-04-zap-updates-february-2024/</guid>
      <description>Restructured desktop menus, OWASP Docker Hub depreciation, Funding, and GSoC.</description>
    </item>
    <item>
      <title>ZAP Professional Services?</title>
      <link>/blog/2024-02-19-zap-professional-services/</link>
      <pubDate>Mon, 19 Feb 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-02-19-zap-professional-services/</guid>
      <description>Would you be interested in ZAP based professional services? If so please get in touch.</description>
    </item>
    <item>
      <title>ZAP Updates - January 2024</title>
      <link>/blog/2024-02-02-zap-updates-january-2024/</link>
      <pubDate>Fri, 02 Feb 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-02-02-zap-updates-january-2024/</guid>
      <description>ZAP funding investigations, a CLA and Google Summer of Code.</description>
    </item>
    <item>
      <title>Signing Requests using RSA Keys</title>
      <link>/blog/2024-01-29-signing-requests-using-rsa-keys/</link>
      <pubDate>Mon, 29 Jan 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-01-29-signing-requests-using-rsa-keys/</guid>
      <description>A new script in the community-scripts repository enables the signing of outgoing requests with RSA keys, addressing the challenge of testing applications that require this functionality.</description>
    </item>
    <item>
      <title>ZAP Contributor License Agreement</title>
      <link>/blog/2024-01-23-zap-contributor-license-agreement/</link>
      <pubDate>Tue, 23 Jan 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-01-23-zap-contributor-license-agreement/</guid>
      <description>We are introducing a Contributor License Agreement to cover all ZAP contributions.</description>
    </item>
    <item>
      <title>2023 in Review</title>
      <link>/blog/2024-01-03-2023-in-review/</link>
      <pubDate>Wed, 03 Jan 2024 00:00:00 +0000</pubDate>
      <guid>/blog/2024-01-03-2023-in-review/</guid>
      <description>A summary of everything ZAP related that happened in 2023.</description>
    </item>
    <item>
      <title>Discovering Our Users - The ZAP User Personas Questionnaire</title>
      <link>/blog/2023-12-21-user-personas-poll/</link>
      <pubDate>Thu, 21 Dec 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-12-21-user-personas-poll/</guid>
      <description>Join our journey to tailor ZAP for every user, by sharing your unique insights and experiences. Your perspective is the key to unlocking ZAP&amp;rsquo;s full potential for everyone in the cybersecurity community.</description>
    </item>
    <item>
      <title>Automated ZAP Scans for Orchard Core Apps</title>
      <link>/blog/2023-12-08-automated-zap-scans-for-orchard-core-apps/</link>
      <pubDate>Fri, 08 Dec 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-12-08-automated-zap-scans-for-orchard-core-apps/</guid>
      <description>If you have an app running on the ASP.NET Core web framework and CMS Orchard Core, you can now easily run ZAP scans for it.</description>
    </item>
    <item>
      <title>ZAP Development Focus Questionnaire Results</title>
      <link>/blog/2023-12-04-development-focus-results/</link>
      <pubDate>Mon, 04 Dec 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-12-04-development-focus-results/</guid>
      <description>The questionnaire results, and what we&amp;rsquo;re doing about the things you care about most.</description>
    </item>
    <item>
      <title>ZAP Updates - November 2023</title>
      <link>/blog/2023-12-01-zap-updates-november-2023/</link>
      <pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-12-01-zap-updates-november-2023/</guid>
      <description>Improved modern web app handling and lots of videos.</description>
    </item>
    <item>
      <title>ZAP Technology Support</title>
      <link>/blog/2023-11-20-technology-support/</link>
      <pubDate>Mon, 20 Nov 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-11-20-technology-support/</guid>
      <description>How you can tell ZAP which technology your target uses, and why it can be a really good idea.</description>
    </item>
    <item>
      <title>Handling Modern Web Apps Better - Part 1</title>
      <link>/blog/2023-11-03-handling-modern-web-apps-better-part1/</link>
      <pubDate>Fri, 03 Nov 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-11-03-handling-modern-web-apps-better-part1/</guid>
      <description>Introducing a new add-on which allows ZAP (and you) to see what is going on in the browser.</description>
    </item>
    <item>
      <title>ZAP Updates - October 2023</title>
      <link>/blog/2023-11-02-zap-updates-october-2023/</link>
      <pubDate>Thu, 02 Nov 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-11-02-zap-updates-october-2023/</guid>
      <description>A new ZAP version, a CLI feature to do quick reconnaissance, and more!</description>
    </item>
    <item>
      <title>Map Local Add-on</title>
      <link>/blog/2023-10-31-maplocal-add-on/</link>
      <pubDate>Tue, 31 Oct 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-10-31-maplocal-add-on/</guid>
      <description>Allows mapping of responses to content of chosen local file.</description>
    </item>
    <item>
      <title>ZAPit</title>
      <link>/blog/2023-10-18-zapit/</link>
      <pubDate>Wed, 18 Oct 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-10-18-zapit/</guid>
      <description>Want to find out as much info about a URL as possible really quickly? Then ZAPit!</description>
    </item>
    <item>
      <title>ZAP 2.14.0</title>
      <link>/blog/2023-10-12-zap-2-14-0/</link>
      <pubDate>Thu, 12 Oct 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-10-12-zap-2-14-0/</guid>
      <description>ZAP 2.14.0 has just been &lt;a href=&#34;/docs/desktop/releases/2.14.0/&#34;&gt;released&lt;/a&gt;, and adds support for Host Header Manipulation, ZAPit, API File Transfers, Graal JS Add-on Access, Postman collections, SBOMs, and more&amp;hellip;</description>
    </item>
    <item>
      <title>ZAP Updates - September 2023</title>
      <link>/blog/2023-10-02-zap-updates-september-2023/</link>
      <pubDate>Mon, 02 Oct 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-10-02-zap-updates-september-2023/</guid>
      <description>Both of our GSoC students completed their projects, and we started a new video series.</description>
    </item>
    <item>
      <title>Postman Add-on</title>
      <link>/blog/2023-09-25-postman-add-on/</link>
      <pubDate>Mon, 25 Sep 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-09-25-postman-add-on/</guid>
      <description>Import Postman collections with the new Postman add-on for ZAP.</description>
    </item>
    <item>
      <title>ZAP Chat Video Series</title>
      <link>/blog/2023-09-15-zap-chat-video-series/</link>
      <pubDate>Fri, 15 Sep 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-09-15-zap-chat-video-series/</guid>
      <description>We have just started a new series of videos called &lt;a href=&#34;/zap-chat/&#34;&gt;ZAP Chat&lt;/a&gt; which focus on ZAP features, new and old.</description>
    </item>
    <item>
      <title>GSoC 2023 Browser Recorder</title>
      <link>/blog/2023-09-11-browser-recorder/</link>
      <pubDate>Mon, 11 Sep 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-09-11-browser-recorder/</guid>
      <description>ZAP has introduced a new feature to record pre-task activities such as logging in etc. using Browser Recorder.</description>
    </item>
    <item>
      <title>Parsing .DS_Store files with ZAP</title>
      <link>/blog/2023-09-08-ds-store-parsing/</link>
      <pubDate>Fri, 08 Sep 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-09-08-ds-store-parsing/</guid>
      <description>ZAP Spider can now probe and parse macOS&amp;rsquo; .DS_Store files.</description>
    </item>
    <item>
      <title>ZAP Updates - August 2023</title>
      <link>/blog/2023-09-01-zap-updates-august-2023/</link>
      <pubDate>Fri, 01 Sep 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-09-01-zap-updates-august-2023/</guid>
      <description>August 2023 was a big change for us!</description>
    </item>
    <item>
      <title>What Should We Focus On?</title>
      <link>/blog/2023-08-29-what-should-we-focus-on/</link>
      <pubDate>Tue, 29 Aug 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-08-29-what-should-we-focus-on/</guid>
      <description>We want your input on what we should focus on as part of ZAP development.</description>
    </item>
    <item>
      <title>Community - Tips and Tricks</title>
      <link>/blog/2023-08-25-community-tips-and-tricks/</link>
      <pubDate>Fri, 25 Aug 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-08-25-community-tips-and-tricks/</guid>
      <description>News about a community area to contribute ZAP usage tips and tricks.</description>
    </item>
    <item>
      <title>ZAP is Available via Winget</title>
      <link>/blog/2023-08-21-zap-is-available-via-winget/</link>
      <pubDate>Mon, 21 Aug 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-08-21-zap-is-available-via-winget/</guid>
      <description>You can now install ZAP via winget - the Windows Package Manager</description>
    </item>
    <item>
      <title>ZAP is Joining the Software Security Project</title>
      <link>/blog/2023-08-01-zap-is-joining-the-software-security-project/</link>
      <pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-08-01-zap-is-joining-the-software-security-project/</guid>
      <description>I’m delighted to announce that ZAP is joining the new &lt;a href=&#34;https://softwaresecurityproject.org/&#34;&gt;Software Security Project&lt;/a&gt; (SSP) as one of the founding projects. This does however mean we are leaving OWASP.</description>
    </item>
    <item>
      <title>ZAP 2.13.0</title>
      <link>/blog/2023-07-12-zap-2.13.0/</link>
      <pubDate>Wed, 12 Jul 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-07-12-zap-2.13.0/</guid>
      <description>ZAP 2.13.0 has just been &lt;a href=&#34;/docs/desktop/releases/2.13.0/&#34;&gt;released&lt;/a&gt;, and adds support for HTTP/2, improved authentication handling and Mac Silicon.</description>
    </item>
    <item>
      <title>ZAP Updates - June 2023</title>
      <link>/blog/2023-07-05-zap-updates-june-2023/</link>
      <pubDate>Wed, 05 Jul 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-07-05-zap-updates-june-2023/</guid>
      <description>June 2023 updates and ongoing feature development statuses.</description>
    </item>
    <item>
      <title>ZAP Docker Images in GitHub Container Registry</title>
      <link>/blog/2023-06-13-ghcr-docker-images/</link>
      <pubDate>Tue, 13 Jun 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-06-13-ghcr-docker-images/</guid>
      <description>ZAP Docker images are now also published to the GitHub Container Registry.</description>
    </item>
    <item>
      <title>ZAP Updates - May 2023</title>
      <link>/blog/2023-06-01-zap-updates-may-2023/</link>
      <pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-06-01-zap-updates-may-2023/</guid>
      <description>May 2023 updates and ongoing feature development statuses.</description>
    </item>
    <item>
      <title>Authentication Tester Dialog</title>
      <link>/blog/2023-05-23-authentication-tester/</link>
      <pubDate>Tue, 23 May 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-05-23-authentication-tester/</guid>
      <description>There is now a &lt;em&gt;really&lt;/em&gt; easy way to check if ZAP can handle your app&amp;rsquo;s authentication.</description>
    </item>
    <item>
      <title>ZAP Updates - April 2023</title>
      <link>/blog/2023-05-03-zap-updates-april-2023/</link>
      <pubDate>Wed, 03 May 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-05-03-zap-updates-april-2023/</guid>
      <description>April 2023 updates - the ZAP 2.13.0 Release Candidate is available now!</description>
    </item>
    <item>
      <title>Authentication Auto-Detection</title>
      <link>/blog/2023-05-02-authentication-auto-detection/</link>
      <pubDate>Tue, 02 May 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-05-02-authentication-auto-detection/</guid>
      <description>ZAP can now automatically detect and configure itself to handle common authentication mechanisms.</description>
    </item>
    <item>
      <title>ZAP Updates - March 2023</title>
      <link>/blog/2023-04-03-zap-updates-march-2023/</link>
      <pubDate>Mon, 03 Apr 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-04-03-zap-updates-march-2023/</guid>
      <description>March 2023 updates and ongoing feature development statuses.</description>
    </item>
    <item>
      <title>How Should We Fund ZAP Development?</title>
      <link>/blog/2023-03-09-how-should-we-fund-zap-development/</link>
      <pubDate>Thu, 09 Mar 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-03-09-how-should-we-fund-zap-development/</guid>
      <description>We would love to be able to make ZAP even better for you - your feedback on how that could be funded would be appreciated!</description>
    </item>
    <item>
      <title>ZAP Updates 2023 January</title>
      <link>/blog/2023-02-02-zap-updates-2023-january/</link>
      <pubDate>Thu, 02 Feb 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-02-02-zap-updates-2023-january/</guid>
      <description>The January 2023 updates including authentication improvements and future plans.</description>
    </item>
    <item>
      <title>Authenticating Using Selenium</title>
      <link>/blog/2023-02-01-authenticating-using-selenium/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-02-01-authenticating-using-selenium/</guid>
      <description>How to configure ZAP to handle complex authentication using Selenium.</description>
    </item>
    <item>
      <title>Authentication Help</title>
      <link>/blog/2023-01-19-authentication-help/</link>
      <pubDate>Thu, 19 Jan 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-01-19-authentication-help/</guid>
      <description>Handling authentication in automation is hard, but help is on its way.</description>
    </item>
    <item>
      <title>2022 in Review</title>
      <link>/blog/2023-01-03-2022-in-review/</link>
      <pubDate>Tue, 03 Jan 2023 00:00:00 +0000</pubDate>
      <guid>/blog/2023-01-03-2022-in-review/</guid>
      <description>A summary of everything ZAP related that happened in 2022.</description>
    </item>
    <item>
      <title>The Twelve Days of ZAPmas</title>
      <link>/blog/2022-12-24-12-days-of-zapmas/</link>
      <pubDate>Sat, 24 Dec 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-12-24-12-days-of-zapmas/</guid>
      <description>A reply to an excellent blog series from &lt;a href=&#34;https://www.secureideas.com/&#34;&gt;Secure Ideas&lt;/a&gt;: Twelve Days of ZAPmas - ZAP impressions from a Burp user.</description>
    </item>
    <item>
      <title>ZAP Updates 2022 November</title>
      <link>/blog/2022-12-01-zap-updates-2022-november/</link>
      <pubDate>Thu, 01 Dec 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-12-01-zap-updates-2022-november/</guid>
      <description>The November 2022 updates, following the 2.12.0 release.</description>
    </item>
    <item>
      <title>Monthly Active Scan Rule Statistics</title>
      <link>/blog/2022-11-03-monthly-active-scan-rule-statistics/</link>
      <pubDate>Thu, 03 Nov 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-11-03-monthly-active-scan-rule-statistics/</guid>
      <description>See the data behind the most popular active scan rules every month</description>
    </item>
    <item>
      <title>ZAP 2.12.0 - the Ten Thousand Star Release</title>
      <link>/blog/2022-10-27-zap-2-12-0-the-ten-thousand-star-release/</link>
      <pubDate>Thu, 27 Oct 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-10-27-zap-2-12-0-the-ten-thousand-star-release/</guid>
      <description>ZAP 2.12.0 has just been released, and as the main &lt;a href=&#34;https://github.com/zaproxy/zaproxy&#34;&gt;zaproxy/zaproxy&lt;/a&gt; repo has just reached 10k stars we&amp;rsquo;re calling this the &lt;strong&gt;Ten Thousand Star&lt;/strong&gt; Release</description>
    </item>
    <item>
      <title>ZAP and Hacktoberfest 2022</title>
      <link>/blog/2022-10-01-zap-and-hacktoberfest/</link>
      <pubDate>Sat, 01 Oct 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-10-01-zap-and-hacktoberfest/</guid>
      <description>ZAP is participating in Hacktoberfest 2022.</description>
    </item>
    <item>
      <title>ZAP Updates 2022 September</title>
      <link>/blog/2022-09-30-zap-updates-2022-september/</link>
      <pubDate>Fri, 30 Sep 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-09-30-zap-updates-2022-september/</guid>
      <description>The September 2022 updates, including our new Platinum Supporter - Jit,  GSoC 2022 success, more news on the forthcoming 2.12.0 release, and no less than 31 add-on updates!</description>
    </item>
    <item>
      <title>New Platinum Supporter: Jit</title>
      <link>/blog/2022-09-14-new-platinum-supporter-jit/</link>
      <pubDate>Wed, 14 Sep 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-09-14-new-platinum-supporter-jit/</guid>
      <description>Simon&amp;rsquo;s work on ZAP is now sponsored by &lt;a href=&#34;https://jit.io&#34;&gt;Jit&lt;/a&gt;.</description>
    </item>
    <item>
      <title>Hacking ZAP - ZAP Extender Scripts</title>
      <link>/blog/2022-09-13-zap-extender-scripts/</link>
      <pubDate>Tue, 13 Sep 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-09-13-zap-extender-scripts/</guid>
      <description>An overview of ZAP Extender scripts with examples. Use ZAP as a web server, subscribe to internal ZAP events, and more!</description>
    </item>
    <item>
      <title>ZAP Updates 2022 August</title>
      <link>/blog/2022-08-31-zap-updates-2022-august/</link>
      <pubDate>Wed, 31 Aug 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-08-31-zap-updates-2022-august/</guid>
      <description>All of the things that have been happening related to ZAP in August 2022.</description>
    </item>
    <item>
      <title>Spider News</title>
      <link>/blog/2022-08-30-spider-move/</link>
      <pubDate>Tue, 30 Aug 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-08-30-spider-move/</guid>
      <description>News about changes to the Traditional Spider for the up-coming release.</description>
    </item>
    <item>
      <title>Running ZAP on a raspberry pi</title>
      <link>/blog/2022-08-25-zap-on-raspberry-pi/</link>
      <pubDate>Thu, 25 Aug 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-08-25-zap-on-raspberry-pi/</guid>
      <description>Setting up ZAP on the raspberry pi.</description>
    </item>
    <item>
      <title>The Param Digger Add-on GSOC 2022</title>
      <link>/blog/2022-08-22-the-param-digger-addon/</link>
      <pubDate>Mon, 22 Aug 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-08-22-the-param-digger-addon/</guid>
      <description>The parameter discovery add-on for ZAP.</description>
    </item>
    <item>
      <title>Help Needed: Fund ZAP Development</title>
      <link>/blog/2022-06-17-help-needed-fund-zap-development/</link>
      <pubDate>Fri, 17 Jun 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-06-17-help-needed-fund-zap-development/</guid>
      <description>Has ZAP helped you? Now it is your turn to help ZAP.</description>
    </item>
    <item>
      <title>The Requester Add-on</title>
      <link>/blog/2022-05-10-the-requester-addon/</link>
      <pubDate>Tue, 10 May 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-05-10-the-requester-addon/</guid>
      <description>An add-on aimed squarely at the pentesters.</description>
    </item>
    <item>
      <title>PortSwigger Labs: Username Enumeration with ZAP Scripts</title>
      <link>/blog/2022-04-14-portswigger-lab-username-enumeration-with-zap-scripts/</link>
      <pubDate>Thu, 14 Apr 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-04-14-portswigger-lab-username-enumeration-with-zap-scripts/</guid>
      <description>How to solve the PortSwigger Lab: Username enumeration via account lock using ZAP scripts.</description>
    </item>
    <item>
      <title>PortSwigger Labs: 2FA Broken Logic</title>
      <link>/blog/2022-04-06-portswigger-lab-2fa-broken-logic/</link>
      <pubDate>Wed, 06 Apr 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-04-06-portswigger-lab-2fa-broken-logic/</guid>
      <description>How to solve the PortSwigger Lab: 2FA Broken Logic using ZAP.</description>
    </item>
    <item>
      <title>Spring4Shell Detection with ZAP</title>
      <link>/blog/2022-04-04-spring4shell-detection-with-zap/</link>
      <pubDate>Mon, 04 Apr 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-04-04-spring4shell-detection-with-zap/</guid>
      <description>How to detect Spring4Shell with the new Spring4Shell Alpha Active Scan Rule.</description>
    </item>
    <item>
      <title>PortSwigger Labs: Password Brute-force via Password Change with ZAP</title>
      <link>/blog/2022-03-29-portswigger-lab-brute-force-password-change/</link>
      <pubDate>Tue, 29 Mar 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-03-29-portswigger-lab-brute-force-password-change/</guid>
      <description>How to solve the PortSwigger Lab: Password Brute-force via Password Change using ZAP.</description>
    </item>
    <item>
      <title>ZAPCon 2022 Schedule is Now Live</title>
      <link>/blog/2022-02-16-zapcon-2022-schedule-is-now-live/</link>
      <pubDate>Wed, 16 Feb 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-02-16-zapcon-2022-schedule-is-now-live/</guid>
      <description>I am excited to share that we’ve just released the speaker lineup and schedule for the &lt;a href=&#34;https://zapcon.io/&#34;&gt;ZAPCon&lt;/a&gt; 2022!  ZAPCon takes place on March 8-9, with one day of talks and one day of incredible workshops.</description>
    </item>
    <item>
      <title>New ZAP Networking Layer</title>
      <link>/blog/2022-02-10-new-zap-networking-layer/</link>
      <pubDate>Thu, 10 Feb 2022 00:00:00 +0000</pubDate>
      <guid>/blog/2022-02-10-new-zap-networking-layer/</guid>
      <description>The ZAP Weekly and Live releases have an all new networking layer.</description>
    </item>
    <item>
      <title>ZAPCon 2022 Call - for Papers</title>
      <link>/blog/2021-12-17-zapcon-2022-call-for-papers/</link>
      <pubDate>Fri, 17 Dec 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-12-17-zapcon-2022-call-for-papers/</guid>
      <description>ZAPCon is returning for its second year! The second annual ZAP user conference will take place on March 8, 2022 and the &lt;a href=&#34;https://sessionize.com/zapcon2-cfs&#34;&gt;Call for Papers&lt;/a&gt; is open!.</description>
    </item>
    <item>
      <title>Log4Shell Detection with ZAP</title>
      <link>/blog/2021-12-14-log4shell-detection-with-zap/</link>
      <pubDate>Tue, 14 Dec 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-12-14-log4shell-detection-with-zap/</guid>
      <description>A walkthrough of using the new Log4Shell Alpha Active Scan rule with the ZAP Automation Framework.</description>
    </item>
    <item>
      <title>ZAP and Log4Shell</title>
      <link>/blog/2021-12-10-zap-and-log4shell/</link>
      <pubDate>Fri, 10 Dec 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-12-10-zap-and-log4shell/</guid>
      <description>ZAP appears to be impacted by the Log4Shell vulnerability - CVE-2021-44228. We have released ZAP 2.11.1 which fixes the problem, this blog post gives more information and the impact on older versions of ZAP.</description>
    </item>
    <item>
      <title>The Eval Villain Add-on</title>
      <link>/blog/2021-12-01-the-eval-villain-add-on/</link>
      <pubDate>Wed, 01 Dec 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-12-01-the-eval-villain-add-on/</guid>
      <description>Eval Villain was recently added to the ZAP Marketplace. This add-on installs the Eval Villain web extension in Firefox and allows the inspection of arguments to arbitrary native JavaScript functions.</description>
    </item>
    <item>
      <title>Launching Browsers with Extensions</title>
      <link>/blog/2021-11-26-launching-browsers-with-extensions/</link>
      <pubDate>Fri, 26 Nov 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-11-26-launching-browsers-with-extensions/</guid>
      <description>You can now launch your favourite browsers from ZAP with your favourite extensions.</description>
    </item>
    <item>
      <title>OWASP Outstanding Project 2021</title>
      <link>/blog/2021-11-24-owasp-outstanding-project-2021/</link>
      <pubDate>Wed, 24 Nov 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-11-24-owasp-outstanding-project-2021/</guid>
      <description>ZAP has been awarded the 2021 Waspy Award for Outstanding Project, as selected by OWASP Members.</description>
    </item>
    <item>
      <title>ZAP Telemetry Plans</title>
      <link>/blog/2021-10-25-zap-telemetry-plans/</link>
      <pubDate>Mon, 25 Oct 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-10-25-zap-telemetry-plans/</guid>
      <description>We are planning to add telemetry to ZAP - data that will tell us more about how ZAP is being used. This blog post explains why we are planning on doing this, what data we plan to collect, what data we will definitely not collect,  the benefits you can expect, and how you will be able to opt out of it.</description>
    </item>
    <item>
      <title>ZAP 2.11.0</title>
      <link>/blog/2021-10-07-zap-2-11-0/</link>
      <pubDate>Thu, 07 Oct 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-10-07-zap-2-11-0/</guid>
      <description>&lt;p&gt;ZAP 2.11.0 (also known as the OWASP 20th anniversary release) is &lt;a href=&#34;/download/#main&#34;&gt;available now&lt;/a&gt;.&lt;/p&gt;&#xA;&#xA;&lt;div class=&#39;embed-youtube&#39;&gt;&#xA;&lt;iframe src=&#39;https://www.youtube.com/embed/8liaCddrb8s&#39; frameborder=&#39;0&#39; allowfullscreen&gt;&lt;/iframe&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&#xA;&lt;p&gt;Major changes include:&lt;/p&gt;&#xA;&#xA;&lt;h3 id=&#34;alert-tags&#34;&gt;Alert Tags &lt;a class=&#34;header-link&#34; href=&#34;#alert-tags&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Alerts can now be tagged with arbitrary keys or key=value pairs - this can be done via the desktop GUI and the API.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Out-of-band Application Security Testing with OWASP ZAP</title>
      <link>/blog/2021-08-23-oast-with-owasp-zap/</link>
      <pubDate>Mon, 23 Aug 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-08-23-oast-with-owasp-zap/</guid>
      <description>An overview of the features of the OAST add-on for OWASP ZAP. This add-on allows you to discover out-of-band vulnerabilities like SSRF.</description>
    </item>
    <item>
      <title>Retesting alerts with OWASP ZAP</title>
      <link>/blog/2021-08-23-retest-with-zap/</link>
      <pubDate>Mon, 23 Aug 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-08-23-retest-with-zap/</guid>
      <description>An overview of the features of the Retest add-on for OWASP ZAP. This add-on allows you to retest for previously generated alerts.</description>
    </item>
    <item>
      <title>ZAP FileUpload Add-on</title>
      <link>/blog/2021-08-20-zap-fileupload-addon/</link>
      <pubDate>Fri, 20 Aug 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-08-20-zap-fileupload-addon/</guid>
      <description>&lt;h2 id=&#34;overview&#34;&gt;Overview &lt;a class=&#34;header-link&#34; href=&#34;#overview&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;File upload is becoming a more and more essential part of any application, where the user is able to upload their photo, their CV, or a video showcasing a project they are working on. The application should be able to fend off bogus and malicious files in a way to keep the application and the users safe. Generally file upload functionality is quite complex to automate and has huge attack surface hence there is a need to automate the process and also secure it. So the FileUpload add-on has scan rule which is used to find vulnerabilities in file upload functionality and this blog explains on how to use it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Community Questionnaire Results</title>
      <link>/blog/2021-06-29-community-questionnaire-results/</link>
      <pubDate>Tue, 29 Jun 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-06-29-community-questionnaire-results/</guid>
      <description>The results of the Community Questionnaire which we ran during the first half of 2021.</description>
    </item>
    <item>
      <title>Baseline Scan Changes</title>
      <link>/blog/2021-06-15-baseline-scan-changes/</link>
      <pubDate>Tue, 15 Jun 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-06-15-baseline-scan-changes/</guid>
      <description>Important information for anyone who uses the baseline scan in the Live or Weekly Docker images.</description>
    </item>
    <item>
      <title>Collecting Statistics for Open Source Projects</title>
      <link>/blog/2021-04-19-collecting-statistics-for-open-source-projects/</link>
      <pubDate>Mon, 19 Apr 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-04-19-collecting-statistics-for-open-source-projects/</guid>
      <description>This blog post will show you how you can collect and publish statistics on your open source projects using free resources and open source scripts, based on the setup we have for ZAP.</description>
    </item>
    <item>
      <title>ZAP 2.10 Features</title>
      <link>/blog/2021-03-29-zap-2-10-0-features/</link>
      <pubDate>Mon, 29 Mar 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-03-29-zap-2-10-0-features/</guid>
      <description>Do you know what interesting bits were added to ZAP 2.10.0? Don&amp;rsquo;t read release notes? This blog post is for you! Dark mode, Expand/Collapse top panes, Custom pages, Scriptable encode/decode/hash, Authentication polling, Auth header via ENV vars, Site tree control, and more.</description>
    </item>
    <item>
      <title>ZAP Report Competition</title>
      <link>/blog/2021-03-12-report-competition/</link>
      <pubDate>Fri, 12 Mar 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-03-12-report-competition/</guid>
      <description>Help us add modern, useful and stylish reports to ZAP - the competition is now open until October 1st 2021.</description>
    </item>
    <item>
      <title>ZAPCon 2021 is Nearly Here</title>
      <link>/blog/2021-03-04-zapcon-is-nearly-here/</link>
      <pubDate>Thu, 04 Mar 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-03-04-zapcon-is-nearly-here/</guid>
      <description>The talks and speakers have been announced. See &lt;a href=&#34;https://zapcon.io&#34;&gt;https://zapcon.io&lt;/a&gt;</description>
    </item>
    <item>
      <title>Automate checking ASVS controls using ZAP scripts</title>
      <link>/blog/2021-02-10-automate-checking-asvs-controls-using-zap-scripts/</link>
      <pubDate>Wed, 10 Feb 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-02-10-automate-checking-asvs-controls-using-zap-scripts/</guid>
      <description>Write scripts in ZAP which will check a target application&amp;rsquo;s compliance against ASVS controls.</description>
    </item>
    <item>
      <title>Run ZAP without Java using Docker and Webswing</title>
      <link>/blog/2021-02-03-run-zap-without-java-using-docker-and-webswing/</link>
      <pubDate>Wed, 03 Feb 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-02-03-run-zap-without-java-using-docker-and-webswing/</guid>
      <description>You can access the ZAP Desktop even when it is running in Docker, and that means you do not have to install Java if you do not want to.</description>
    </item>
    <item>
      <title>1st Ever ZAPCon - Call For Papers</title>
      <link>/blog/2021-01-28-announcing-the-first-ever-zapcon/</link>
      <pubDate>Thu, 28 Jan 2021 00:00:00 +0000</pubDate>
      <guid>/blog/2021-01-28-announcing-the-first-ever-zapcon/</guid>
      <description>Today we are calling for topics and speakers in the first-ever OWASP ZAP User Conference!</description>
    </item>
    <item>
      <title>ZAP 2.10.0 - The 10 Year Anniversary Release</title>
      <link>/blog/2020-12-21-zap-2-10-0-the-10-year-anniversary-release/</link>
      <pubDate>Mon, 21 Dec 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-12-21-zap-2-10-0-the-10-year-anniversary-release/</guid>
      <description>ZAP 2.10.0 has just been released so we&amp;rsquo;re treating this as a belated 10 year anniversary release!</description>
    </item>
    <item>
      <title>Sites Tree Modifiers</title>
      <link>/blog/2020-09-22-sites-tree-modifiers/</link>
      <pubDate>Tue, 22 Sep 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-09-22-sites-tree-modifiers/</guid>
      <description>The Sites Tree is a key component of ZAP, and one whose purpose is often misunderstood. This blog post will explain why the Sites Tree is so important, how you can change it now and how you will be able to change it in the next ZAP release.</description>
    </item>
    <item>
      <title>ZAP Tags</title>
      <link>/blog/2020-09-14-tags/</link>
      <pubDate>Mon, 14 Sep 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-09-14-tags/</guid>
      <description>How to give some colours to ZAP&amp;rsquo;s History tab. An introduction to passive scanning tags, its use cases, and the Neonmarker add-on.</description>
    </item>
    <item>
      <title>ZAP is Ten Years Old</title>
      <link>/blog/2020-09-06-zap-is-ten-years-old/</link>
      <pubDate>Sun, 06 Sep 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-09-06-zap-is-ten-years-old/</guid>
      <description>On September 6th 2010 I posted this message to Bugtraq: Title - The Zed Attack Proxy (ZAP) version 1.0.0. From those very humble beginnings ZAP has now become what we believe is the world’s most frequently used web application scanner.</description>
    </item>
    <item>
      <title>ZAP JWT Support Add-on</title>
      <link>/blog/2020-09-03-zap-jwt-scanner/</link>
      <pubDate>Thu, 03 Sep 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-09-03-zap-jwt-scanner/</guid>
      <description>&lt;p&gt;With the popularity of JSON Web Tokens (JWTs) there comes the need to secure their use so that they are not misused because of bad configuration, older libraries, or buggy implementations. So the JWT Support add-on is used to find such vulnerabilities and this blog explains on how to use it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introducing the GraphQL Add-on for ZAP</title>
      <link>/blog/2020-08-28-introducing-the-graphql-add-on-for-zap/</link>
      <pubDate>Fri, 28 Aug 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-08-28-introducing-the-graphql-add-on-for-zap/</guid>
      <description>&lt;p&gt;GraphQL Schemas can be very large and testing them can be a very time-consuming process. Currently, there is a lack of tools that allow developers to launch and automate attacks on these endpoints. The GraphQL add-on for ZAP intends to fill this gap.&lt;/p&gt;&#xA;&lt;p&gt;The add-on is still in an early stage, so the range of its functionality is limited. However, you can combine it with existing ZAP functionality to abuse GraphQL endpoints in many different ways.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP 2.9 Highlights</title>
      <link>/blog/2020-06-04-zap-2-9-0-highlights/</link>
      <pubDate>Thu, 04 Jun 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-06-04-zap-2-9-0-highlights/</guid>
      <description>Do you know what interesting bits were added to ZAP 2.9.0? Don&amp;rsquo;t read release notes? This blog post is for you! Session Management Scripts, Proxy Info Display, Proxy Port Reservation Failure Handling, Options Panel(s) Filter, Active Scan Filter, and more.</description>
    </item>
    <item>
      <title>Dynamic Application Security Testing with ZAP and GitHub Actions</title>
      <link>/blog/2020-05-15-dynamic-application-security-testing-with-zap-and-github-actions/</link>
      <pubDate>Fri, 15 May 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-05-15-dynamic-application-security-testing-with-zap-and-github-actions/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://github.com/marketplace/actions/zap-full-scan&#34;&gt;&lt;img src=&#34;./images/zap-action.png&#34; alt=&#34;zap-action&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/marketplace/actions/zap-full-scan&#34;&gt;ZAP full scan GitHub action&lt;/a&gt; provides free dynamic application&#xA;security testing (DAST) of your web applications. DAST is also known as black-box testing, which allows ZAP to identify&#xA;potential vulnerabilities in your web applications. We previously introduced the &lt;a href=&#34;https://github.com/marketplace/actions/zap-baseline-scan&#34;&gt;ZAP baseline scan GitHub action&lt;/a&gt;&#xA;to passively identify potential alerts in a web application. However, unlike the baseline scan, ZAP full scan attacks the web application&#xA;to find additional vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Customize Alert Details</title>
      <link>/blog/2020-05-11-alert-overrides-youdontknowzap/</link>
      <pubDate>Mon, 11 May 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-05-11-alert-overrides-youdontknowzap/</guid>
      <description>&lt;p&gt;Did you know that you or your company/organization could customize the generic details of the alerts that ZAP raises?&lt;/p&gt;&#xA;&lt;p&gt;Alerts raised by ZAP contain a variety of information, some generic, some specific to the issue at hand. Specific details may include things such as&#xA;URL, parameter, values, etc. While generic details include things like a description, solution, and links to related background material and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Automate Security Testing with ZAP and GitHub Actions</title>
      <link>/blog/2020-04-09-automate-security-testing-with-zap-and-github-actions/</link>
      <pubDate>Thu, 09 Apr 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-04-09-automate-security-testing-with-zap-and-github-actions/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://github.com/marketplace/actions/zap-baseline-scan&#34;&gt;&lt;img src=&#34;./images/zap-action.png&#34; alt=&#34;zap-action&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;With the increasing number of web application security breaches, it is essential to keep your web application secure at all times.&#xA;Furthermore having security integrated into your CI/CD pipeline (DevSecOps) will become a lifesaver if you are actively&#xA;developing the application. To cater to this need ZAP provides a baseline scan feature to find common security faults in&#xA;a web application without doing any active attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is ZAP the World’s most Popular Web Scanner?</title>
      <link>/blog/2020-04-02-is-zap-the-worlds-most-popular-web-scanner/</link>
      <pubDate>Thu, 02 Apr 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-04-02-is-zap-the-worlds-most-popular-web-scanner/</guid>
      <description>&lt;p&gt;I’ve stated that ZAP is the world’s most popular free and open source web application scanner on stage at security conferences around the world for many years. No one has ever contradicted me so it must be true :)&lt;/p&gt;&#xA;&lt;p&gt;However I’ve started to wonder if ZAP is actually more popular than most &lt;em&gt;if not all&lt;/em&gt; of the commercial scanners as well?&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP SSRF Setup</title>
      <link>/blog/2020-03-09-zap-ssrf-setup/</link>
      <pubDate>Mon, 09 Mar 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-03-09-zap-ssrf-setup/</guid>
      <description>&lt;p&gt;Some vulnerabilities can only be found by sending payloads that cause a callback to the tester. One example is &lt;a href=&#34;https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing&#34;&gt;XXE vulnerabilities&lt;/a&gt; when the XML rendering result is not available to the user. ZAP can find these vulnerabilities that depend on &lt;a href=&#34;https://owasp.org/www-community/attacks/Server_Side_Request_Forgery&#34;&gt;SSRF&lt;/a&gt; detection but the target system needs to be able to reach the ZAP callback endpoint. In many cases the computer running ZAP is behind some kind of NAT and doesn’t have a public IP so it will not receive the expected callbacks and miss some of the existent vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dark Mode in the Weekly Release</title>
      <link>/blog/2020-03-04-dark-mode-in-the-weekly-release/</link>
      <pubDate>Wed, 04 Mar 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-03-04-dark-mode-in-the-weekly-release/</guid>
      <description>&lt;p&gt;We release ZAP every week: &lt;a href=&#34;/download/#weekly&#34;&gt;https://www.zaproxy.org/download/#weekly&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;We’re happy to announce that this week’s release includes the first steps towards an all new &lt;strong&gt;dark mode&lt;/strong&gt; for the ZAP Desktop UI:&lt;/p&gt;&#xA;&#xA;&lt;figure&gt;&#xA;&#x9;&lt;img src=&#34;/blog/2020-03-04-dark-mode-in-the-weekly-release/images/zap-dark-desktop.png&#34; alt=&#34;&#34; /&gt;&#xA;&#x9;&lt;figcaption&gt;&lt;/figcaption&gt;&#xA;&lt;/figure&gt;&#xA;&lt;p&gt;It’s early days - not all screens use suitable colours, but it should be mostly usable.&#xA;To enable it in the weekly release:&lt;/p&gt;</description>
    </item>
    <item>
      <title>The ZAP Blog has Moved</title>
      <link>/blog/2020-03-02-zap-blog-has-moved/</link>
      <pubDate>Mon, 02 Mar 2020 00:00:00 +0000</pubDate>
      <guid>/blog/2020-03-02-zap-blog-has-moved/</guid>
      <description>&lt;figure&gt;&#xA;&#x9;&lt;img src=&#34;/blog/2020-03-02-zap-blog-has-moved/images/zapbot-running.png&#34; alt=&#34;&#34; /&gt;&#xA;&#x9;&lt;figcaption&gt;&lt;/figcaption&gt;&#xA;&lt;/figure&gt;&#xA;&lt;p&gt;OK, OK, it&amp;rsquo;s been a long time since the last ZAP blog post.&#xA;But we certainly have not been idle - since that last blog post we&amp;rsquo;ve published 3 full ZAP releases, well over 100 weekly releases and a shiny new web site: &lt;a href=&#34;/&#34;&gt;https://zaproxy.org/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Because we now have a new website we&amp;rsquo;ve decided to move our blog from &lt;a href=&#34;https://zaproxy.blogspot.com/&#34;&gt;https://zaproxy.blogspot.com/&lt;/a&gt; to &lt;a href=&#34;/blog/&#34;&gt;https://zaproxy.org/blog/&lt;/a&gt;.&#xA;As part of that move all of the old blog posts have been moved to the new site and updated to fix some of the links that had broken.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP Browser Launch</title>
      <link>/blog/2017-08-22-zap-browser-launch/</link>
      <pubDate>Tue, 22 Aug 2017 00:00:00 +0000</pubDate>
      <guid>/blog/2017-08-22-zap-browser-launch/</guid>
      <description>&lt;p&gt;We have just released a new feature for ZAP that allows you to launch browsers from within ZAP. The browsers are automatically configured to&#xA;proxy via ZAP and ignore certificate warnings, making it much easier for people to get started with ZAP as well as for more experienced users&#xA;who want to use ZAP with a variety of browsers. You can install and use Browser Launch right now via the ZAP Marketplace, which can be accessed&#xA;via the &amp;lsquo;Manage Add-ons&amp;rsquo; button in ZAP:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Scanning APIs with ZAP</title>
      <link>/blog/2017-06-19-scanning-apis-with-zap/</link>
      <pubDate>Mon, 19 Jun 2017 00:00:00 +0000</pubDate>
      <guid>/blog/2017-06-19-scanning-apis-with-zap/</guid>
      <description>&lt;p&gt;The previous ZAP blog post explained how you could &lt;a href=&#34;/blog/2017-04-03-exploring-apis-with-zap/&#34;&gt;Explore APIs with ZAP&lt;/a&gt;.&lt;br&gt;&#xA;This blog post goes one step further, and explains how you can both explore and perform security scanning of APIs using ZAP from the command&#xA;line.&lt;br&gt;&#xA;This allows you to easily automate the scanning of your APIs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploring APIs with ZAP</title>
      <link>/blog/2017-04-03-exploring-apis-with-zap/</link>
      <pubDate>Mon, 03 Apr 2017 00:00:00 +0000</pubDate>
      <guid>/blog/2017-04-03-exploring-apis-with-zap/</guid>
      <description>&lt;p&gt;APIs can be challenging for security testing for a variety of reasons.&lt;br&gt;&#xA;The first problem you will encounter is how to effectively explore an API - most APIs cannot be explored using browsing or standard spidering&#xA;techniques.&lt;br&gt;&#xA;However many APIs are described using technologies such as:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/SOAP&#34;&gt;SOAP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.openapis.org/&#34;&gt;OpenAPI / Swagger&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;These standards define the API endpoints and can be imported into ZAP using 2 optional add-ons.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introducing the JxBrowser add-on for ZAP</title>
      <link>/blog/2017-02-06-introducing-the-jxbrowser-add-on-for-zap/</link>
      <pubDate>Mon, 06 Feb 2017 00:00:00 +0000</pubDate>
      <guid>/blog/2017-02-06-introducing-the-jxbrowser-add-on-for-zap/</guid>
      <description>&lt;h3 id=&#34;&#34;&gt; &lt;a class=&#34;header-link&#34; href=&#34;#&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;As modern web applications are increasing their reliance on JavaScript, security tools that do not understand JavaScript will not be able to&#xA;work effectively with them.  ZAP already has components like the Ajax Spider and DOM XSS scanner that work by launching browsers and controlling&#xA;them via Selenium, and we are planning to make much more use of browsers in the future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Announcing the ZAP Jenkins Plugin</title>
      <link>/blog/2016-11-22-announcing-the-official-zap-jenkins-plugin/</link>
      <pubDate>Tue, 22 Nov 2016 00:00:00 +0000</pubDate>
      <guid>/blog/2016-11-22-announcing-the-official-zap-jenkins-plugin/</guid>
      <description>&lt;p&gt;Using ZAP during the development process is now easier than ever. We are proud to present the Jenkins plugin, it extends the functionality of&#xA;the ZAP security tool into a CI Environment.&lt;/p&gt;&#xA;&#xA;&lt;figure&gt;&#xA;&#x9;&lt;img src=&#34;/blog/2016-11-22-announcing-the-official-zap-jenkins-plugin/images/ZAP_CI_SMALLER.png&#34; alt=&#34;&#34; /&gt;&#xA;&#x9;&lt;figcaption&gt;&lt;/figcaption&gt;&#xA;&lt;/figure&gt;&#xA;&#xA;&lt;h5 id=&#34;the-process-explained&#34;&gt;The process explained&lt;/h5&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;A Jenkins CI Build step initializes ZAP&lt;/li&gt;&#xA;&lt;li&gt;Traffic flows (Regression Pack) through ZAP (Web Proxy)&lt;/li&gt;&#xA;&lt;li&gt;ZAP modifies requests to include Vulnerability Tests&lt;/li&gt;&#xA;&lt;li&gt;Target Application/Server sends Response back through ZAP&lt;/li&gt;&#xA;&lt;li&gt;ZAP sends reporting data back to Jenkins&lt;/li&gt;&#xA;&lt;li&gt;Jenkins publishes and archives the report(s)&lt;/li&gt;&#xA;&lt;li&gt;Jenkins creates JIRA tickets for the alerts&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;The ZAP Jenkins plugin makes use of the readily available and diverse ZAP API, allowing you to use the same session files and scan policy&#xA;profiles between ZAP and the Jenkins plugin, so they can be interchangeably loaded.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Announcing ZAP Unit Test Bounties</title>
      <link>/blog/2016-08-22-announcing-zap-unit-test-bounties/</link>
      <pubDate>Mon, 22 Aug 2016 00:00:00 +0000</pubDate>
      <guid>/blog/2016-08-22-announcing-zap-unit-test-bounties/</guid>
      <description>&lt;p&gt;Unit tests are wonderful things, but they are painful to add to a mature project that doesn’t have enough of them. We would love to have more&#xA;ZAP unit tests, and we are therefore launching a Unit Test Bounty program, where we pay for unit tests for specific areas of the ZAP codebase.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP 2.5.0</title>
      <link>/blog/2016-06-03-zap-2-5-0/</link>
      <pubDate>Fri, 03 Jun 2016 00:00:00 +0000</pubDate>
      <guid>/blog/2016-06-03-zap-2-5-0/</guid>
      <description>&lt;p&gt;ZAP 2.5.0 is &lt;a href=&#34;/download/#main&#34;&gt;now available&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This release contains a large number of enhancements and fixes which are detailed in the &lt;a href=&#34;/docs/desktop/releases/2.5.0/&#34;&gt;release notes&lt;/a&gt;.&lt;/p&gt;&#xA;&#xA;&lt;h3 id=&#34;api-changes&#34;&gt;API changes &lt;a class=&#34;header-link&#34; href=&#34;#api-changes&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;There have been some API changes which are not backwards compatible, and the reason for the version change to 2.5. These are detailed in the&#xA;release notes.&lt;br&gt;&#xA;The API has also been extended to cover even more of the functionality in ZAP, including full access to the statistics.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP Newsletter - 2016 March</title>
      <link>/blog/2016-03-29-zap-newsletter-2016-march/</link>
      <pubDate>Tue, 29 Mar 2016 00:00:00 +0000</pubDate>
      <guid>/blog/2016-03-29-zap-newsletter-2016-march/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction &lt;a class=&#34;header-link&#34; href=&#34;#introduction&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Welcome to the March newsletter, read on for some really good news, details of the new site level stats ZAP now supports and an introduction to&#xA;scripting.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP Newsletter - 2016 February</title>
      <link>/blog/2016-02-19-zap-newsletter-2016-february/</link>
      <pubDate>Fri, 19 Feb 2016 00:00:00 +0000</pubDate>
      <guid>/blog/2016-02-19-zap-newsletter-2016-february/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction &lt;a class=&#34;header-link&#34; href=&#34;#introduction&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Welcome to a slightly delayed February newsletter - we were holding on for some expected news that will now have to wait until next time ;)&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP Newsletter - 2016 January</title>
      <link>/blog/2016-01-04-zap-newsletter-2016-january/</link>
      <pubDate>Mon, 04 Jan 2016 00:00:00 +0000</pubDate>
      <guid>/blog/2016-01-04-zap-newsletter-2016-january/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction &lt;a class=&#34;header-link&#34; href=&#34;#introduction&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Happy New Year!&lt;br&gt;&#xA;For the first newsletter of 2016 we have a special feature on a new vulnerability &lt;strong&gt;“XCOLD Information Leak”&lt;/strong&gt; that caught the eye of one of our&#xA;key contributors, how he found it and how you can use a new ZAP rule to detect it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP Newsletter - 2015 December</title>
      <link>/blog/2015-12-15-zap-newsletter-2015-december/</link>
      <pubDate>Tue, 15 Dec 2015 00:00:00 +0000</pubDate>
      <guid>/blog/2015-12-15-zap-newsletter-2015-december/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction &lt;a class=&#34;header-link&#34; href=&#34;#introduction&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Welcome to the second ZAP Newsletter.&lt;br&gt;&#xA;And apologies for the delay - 2.4.3 took longer than expected, and last week I was away at a Mozilla work week.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP Newsletter - 2015 November</title>
      <link>/blog/2015-11-02-zap-newsletter-2015-november/</link>
      <pubDate>Mon, 02 Nov 2015 00:00:00 +0000</pubDate>
      <guid>/blog/2015-11-02-zap-newsletter-2015-november/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction &lt;a class=&#34;header-link&#34; href=&#34;#introduction&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Welcome to the first monthly ZAP newsletter.&lt;br&gt;&#xA;We plan to cover pretty much anything ZAP related in these newsletters, including newly created or updated add-ons, new features just&#xA;implemented and 3rd party tools.&lt;br&gt;&#xA;We also encourage contributions from people like yourself - see the last section for details.&lt;br&gt;&#xA;Oh, and please let us know what you think of this newsletter via the &lt;a href=&#34;https://docs.google.com/forms/d/1_XaettHPjLOD56AbSlui67gk-771yJ_xfd7w2lSEdXw/viewform?usp=send_form&#34;&gt;Feedback Form&lt;/a&gt;!&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP Q&amp;A Session - Tuesday 13th October 2015</title>
      <link>/blog/2015-10-06-zap-q-a-session-tuesday-13th-october-2015/</link>
      <pubDate>Tue, 06 Oct 2015 00:00:00 +0000</pubDate>
      <guid>/blog/2015-10-06-zap-q-a-session-tuesday-13th-october-2015/</guid>
      <description>&lt;p&gt;&lt;strong&gt;The first online ZAP Q&amp;amp;A Session was held on Tuesday 13th October.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;You can listen to a recording of the session &lt;a href=&#34;https://soundcloud.com/simon-bennetts/2015-10-13-owasp-zap-qa&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Please leave feedback via this &lt;a href=&#34;https://docs.google.com/forms/d/1KxMTz18IZCr1BVcqA40zXf8ZH5S3-rbFrffjXVLANR4/viewform&#34;&gt;Google Form&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Some links to resources mentioned in the session or related to the questions:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;/docs/desktop/addons/dom-xss-active-scan-rule/&#34;&gt;The DOM XSS add-on&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;/docs/desktop/addons/alert-filters/&#34;&gt;The Context Alert Filters add-on&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;/docs/desktop/addons/revisit/&#34;&gt;The Revisit Add-on&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;/docs/desktop/addons/access-control-testing/&#34;&gt;The Access Control add-on&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;/faq/what-does-zap-test-for/&#34;&gt;The vulnerabilities detected by ZAP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;/faq/how-can-zap-automatically-authenticate-via-forms/&#34;&gt;How to set up form based authentication&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/zaproxy/community-scripts&#34;&gt;The community-scripts repo&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Note that you can download add-ons from within ZAP via the &lt;a href=&#34;/addons/&#34;&gt;Marketplace&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP as a Service (ZaaS)</title>
      <link>/blog/2015-05-27-zap-as-a-service-zaas/</link>
      <pubDate>Wed, 27 May 2015 00:00:00 +0000</pubDate>
      <guid>/blog/2015-05-27-zap-as-a-service-zaas/</guid>
      <description>&lt;p&gt;At OWASP AppSec EU in Amsterdam this year I announced ZAP as a Service (ZaaS).&lt;br&gt;&#xA;The slides are &lt;a href=&#34;https://www.slideshare.net/psiinon/owasp-2015-06appseceuzap24&#34;&gt;here&lt;/a&gt; and the video will hopefully be available soon.&lt;/p&gt;&#xA;&lt;p&gt;The idea behind this development is to enhance ZAP so that it can be run in a ‘server’ mode.&lt;br&gt;&#xA;This is different to the current ‘daemon’ mode in that it will be designed to be a long running, highly scalable, distributed service accessed&#xA;by multiple users with different roles.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Alberto&#39;s GSoC 2014 Project for ZAP  SOAP Scanner Add-On</title>
      <link>/blog/2014-09-03-alberto-s-gsoc-2014-project-for-zap-soap-scanner-add-on/</link>
      <pubDate>Wed, 03 Sep 2014 00:00:00 +0000</pubDate>
      <guid>/blog/2014-09-03-alberto-s-gsoc-2014-project-for-zap-soap-scanner-add-on/</guid>
      <description>&lt;p&gt;Hello everybody, my name is Alberto Verza, a 23 year student from Spain, and this summer I have participated in &lt;a href=&#34;https://www.google-melange.com/archive/gsoc/2014/orgs/owasp&#34;&gt;Google Summer of Code 2014&lt;/a&gt;. My&#xA;project was the SOAP Scanner add-on for ZAP, in which I worked during all the Program. Let me explain you the features it includes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking ZAP #4 - Active scan rules</title>
      <link>/blog/2014-04-30-hacking-zap-4-active-scan-rules/</link>
      <pubDate>Wed, 30 Apr 2014 00:00:00 +0000</pubDate>
      <guid>/blog/2014-04-30-hacking-zap-4-active-scan-rules/</guid>
      <description>&lt;p&gt;Welcome to a &lt;a href=&#34;https://github.com/zaproxy/zaproxy/wiki/Development#hacking-zap&#34;&gt;series of blog posts&lt;/a&gt; aimed at helping you “hack the ZAP source code”.&lt;br&gt;&#xA;The previous post in this series is: &lt;a href=&#34;/blog/2014-04-03-hacking-zap-3-passive-scan-rules/&#34;&gt;Hacking ZAP #3 - Passive scan rules&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Active scan rules are another relatively simple way to enhance ZAP. Active scan rules attack the server, and therefore are only run when&#xA;explicitly invoked by the user. You should only use active scan rules against applications that you have permission to attack.&lt;br&gt;&#xA;You can also write active scan rules dynamically using scripts, as we will see later in this series, but even then it&amp;rsquo;s very useful to understand&#xA;some of the concepts underlying classes available to you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking ZAP #3 - Passive scan rules</title>
      <link>/blog/2014-04-03-hacking-zap-3-passive-scan-rules/</link>
      <pubDate>Thu, 03 Apr 2014 00:00:00 +0000</pubDate>
      <guid>/blog/2014-04-03-hacking-zap-3-passive-scan-rules/</guid>
      <description>&lt;p&gt;Welcome to a &lt;a href=&#34;https://github.com/zaproxy/zaproxy/wiki/Development#hacking-zap&#34;&gt;series of blog posts&lt;/a&gt; aimed at helping you “hack the ZAP source&#xA;code”.&lt;br&gt;&#xA;The previous post in this series is: &lt;a href=&#34;/blog/2014-03-20-hacking-zap-2-getting-started/&#34;&gt;Hacking ZAP #2 - Getting Started&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;One of the easiest ways to enhance ZAP is to write new passive scan rules.&lt;br&gt;&#xA;Passive scan rules are used to warn the user of potential vulnerabilities that can be detected passively - they are not allowed to make any new&#xA;requests or manipulate the requests or responses in any way.&lt;br&gt;&#xA;They typically run against all of the requests and responses that flow through ZAP.&lt;br&gt;&#xA;Passive rules run in separate background thread so that they have as little effect on performance as possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking ZAP #2 - Getting Started</title>
      <link>/blog/2014-03-20-hacking-zap-2-getting-started/</link>
      <pubDate>Thu, 20 Mar 2014 00:00:00 +0000</pubDate>
      <guid>/blog/2014-03-20-hacking-zap-2-getting-started/</guid>
      <description>&lt;p&gt;Welcome to a &lt;a href=&#34;https://github.com/zaproxy/zaproxy/wiki/Development#hacking-zap&#34;&gt;series of blog posts&lt;/a&gt; aimed at&#xA;helping you “hack the ZAP source code”.&lt;br&gt;&#xA;The previous post in this series is: &lt;a href=&#34;/blog/2014-03-10-hacking-zap-1-why-should-you/&#34;&gt;Hacking ZAP #1 - Why should you?&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;In order to change the ZAP source code you will need to set up a development environment.&lt;/p&gt;&#xA;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements &lt;a class=&#34;header-link&#34; href=&#34;#requirements&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;The following software is used/required to obtain and build ZAP (core) and the add-ons:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking ZAP #1 - Why should you?</title>
      <link>/blog/2014-03-10-hacking-zap-1-why-should-you/</link>
      <pubDate>Mon, 10 Mar 2014 00:00:00 +0000</pubDate>
      <guid>/blog/2014-03-10-hacking-zap-1-why-should-you/</guid>
      <description>&lt;p&gt;Welcome to a &lt;a href=&#34;https://github.com/zaproxy/zaproxy/wiki/Development#hacking-zap&#34;&gt;series of blog posts&lt;/a&gt; aimed at&#xA;helping you “hack the ZAP source code”.&lt;/p&gt;&#xA;&lt;p&gt;ZAP is an open source tool for finding vulnerabilities in web applications. It is the &lt;a href=&#34;https://www.openhub.net/orgs/OWASP&#34;&gt;most active OWASP&#xA;project&lt;/a&gt; and is very community focused - it probably has more&#xA;&lt;a href=&#34;https://www.openhub.net/p/zaproxy/contributors/summary&#34;&gt;contributors&lt;/a&gt; than any other web application security tool. It is being &lt;a href=&#34;https://www.openhub.net/p/zaproxy/commits/summary&#34;&gt;continually enhanced&lt;/a&gt; and, unusually for a security tool, has been translated into over &lt;a href=&#34;https://crowdin.com/project/zaproxy&#34;&gt;25 languages&lt;/a&gt; thanks to over 70 translators.&lt;br&gt;&#xA;This series is designed to help newcomers dive head-first into the ZAP source code. However for this first blog post I thought I’d take a step back and give some reasons why you might want to change the ZAP source code in the first place.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP 2.0.0 and the Google Summer of Code 2012 Projects</title>
      <link>/blog/2012-12-10-zap-2-0-0-and-the-google-summer-of-code-2012-projects/</link>
      <pubDate>Mon, 10 Dec 2012 00:00:00 +0000</pubDate>
      <guid>/blog/2012-12-10-zap-2-0-0-and-the-google-summer-of-code-2012-projects/</guid>
      <description>&lt;p&gt;We are getting close to releasing the next major version of ZAP.&lt;/p&gt;&#xA;&lt;p&gt;As there are so many changes we&amp;rsquo;ve decided to go to version 2.0.0 rather than 1.5, and some of the biggest changes have come about thanks to the&#xA;&lt;a href=&#34;https://www.google-melange.com/archive/gsoc/2012&#34;&gt;Google Summer of Code&lt;/a&gt; (GSoC).&lt;/p&gt;&#xA;&lt;p&gt;This is the first year in which ZAP has taken part in the GSoC, and it has been a resounding success.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ZAP Weekly Releases</title>
      <link>/blog/2012-10-22-zap-weekly-releases/</link>
      <pubDate>Mon, 22 Oct 2012 00:00:00 +0000</pubDate>
      <guid>/blog/2012-10-22-zap-weekly-releases/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve been struggling with the question of ZAP releases.&lt;br&gt;&#xA;We&amp;rsquo;ve made loads of enhancements to ZAP recently, and I want them to be available to as wide an audience as possible.&lt;br&gt;&#xA;But I also want to make sure our &amp;lsquo;full&amp;rsquo; releases remain as robust and stable as possible.&lt;br&gt;&#xA;I want to get the next full release (2.0.0) out of the door asap, but I still want to get a load more features into it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OWASP ZAP – the Firefox of web security tools</title>
      <link>/blog/2012-09-13-owasp-zap-the-firefox-of-web-security-tools/</link>
      <pubDate>Thu, 13 Sep 2012 00:00:00 +0000</pubDate>
      <guid>/blog/2012-09-13-owasp-zap-the-firefox-of-web-security-tools/</guid>
      <description>&lt;p&gt;The OWASP Zed Attack Proxy (otherwise known as ZAP) is a free security tool&#xA;which you can use to find security vulnerabilities in web applications. My name is Simon Bennetts, and I am the ZAP Project Leader; there is&#xA;also an international group of volunteers who develop and support it. Future posts on this blog will describe the features that ZAP provides and&#xA;how you can use them, but this post will concentrate on the philosophy behind ZAP. Some of the ideals that have driven ZAP are listed below and&#xA;will be expanded upon in the rest of this post:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
