About
Seasoned Application Security & Product Management professional with broad range of…
Articles by Dave
Activity
-
‼️ Versions 2.6.2 and 2.6.3 of the PyPI package "lightning" are compromised. RL research note: It is the same type of #Shaihulud malware as in recent…
‼️ Versions 2.6.2 and 2.6.3 of the PyPI package "lightning" are compromised. RL research note: It is the same type of #Shaihulud malware as in recent…
Liked by Dave Ferguson
-
Mythos and OpenAI’s cyber-focused releases like GPT-5.4-Cyber are so hot right now. But the leap people are making is off. A stronger model does not…
Mythos and OpenAI’s cyber-focused releases like GPT-5.4-Cyber are so hot right now. But the leap people are making is off. A stronger model does not…
Liked by Dave Ferguson
Experience
Education
-
University of Kansas
-
Master's Thesis: Characterization of Intake Valve Deposits Including Thermal Resistance Effects.
-
-
Licenses & Certifications
-
-
-
Certified Information Systems Security Professional (CISSP)
(ISC)²
Issued ExpiresCredential ID 85508 -
Payment Application Qualified Security Assessor (PA-QSA)
PCI Security Standards Council
Issued Expires -
-
-
-
Volunteer Experience
-
Kansas City OWASP chapter leader
OWASP Foundation
- 1 year
Science and Technology
Led the KC chapter of OWASP to help evangelize web application security in the local community. I planned and organized regular meetings, recruited speakers, and promoted the free resources, tools, and information available at OWASP.
Publications
-
It's All About That C-SURF, No Trouble
Presentation at Lone Star AppSec Conference (LASCON) 2016
See publicationMy 2nd talk at LASCON. Abstract: "What's with cross-site request forgery? A decade ago it was supposed to be a sleeping giant, preparing to wake and inflict havoc upon the worldwide web. But the doomsday scenario never materialized and you don't even seem to hear much about it anymore. In this talk, 10 years after disclosing massive CSRF vulnerabilities in Netflix's website, I will cover all things CSRF!"
-
AppSec United: Why You Need Both Dynamic Scans and Manual Pen Tests
Presentation at Triangle InfoSeCon 2016
Learn why both insecure code and flawed business logic must be considered when assessing applications and how the strengths and weaknesses of automated dynamic scanning and manual penetration testing come into play.
Other authorsSee publication -
Securing the New Breed of Web Applications
Presentation at the CSO50 Conference+Awards
-
Introduction to Security Testing
Webinar for uTest University
See publicationWebinar to explain the fundamentals of web application security testing. Target audience was the uTest community, a large community of freelance QA professionals who typically focus on functional and performance testing.
-
Practical AppSec: Quick Wins for More Secure Software
Presentation at Lone Star AppSec Conference (LASCON) 2014
See publicationMy first speaking session at LASCON.
-
Building Secure Applications - How Mature Are You?
Checkmarx Blog
See publicationMy second article as a guest blogger for Checkmarx.
-
Where To Practice Your Web Hacking Skills
Checkmarx Blog
See publicationMy first article as a guest blogger for Checkmarx.
-
Tips for Creating a Successful Application Security Program
Presentation at OWASP Denver chapter
-
OWASP Cheat Sheet Series
OWASP Foundation
The OWASP Prevention Cheat Sheet Series was created to provide a concise collection of high value information on specific web application security topics. These cheat sheets were created by multiple application security experts and provide excellent security guidance in an easy to read format.
Other authorsSee publication -
Best Practices for a Secure Forgot Password Feature
FishNet Security white paper
See publicationMy original white paper. Subsequently used as the basis for the OWASP Forgot Password Cheat Sheet.
Recommendations received
6 people have recommended Dave
Join now to viewMore activity by Dave
-
Today is my last day at Veracode. After almost 11 years, I'm finding it harder to put this into words than I expected. I joined when the company had…
Today is my last day at Veracode. After almost 11 years, I'm finding it harder to put this into words than I expected. I joined when the company had…
Liked by Dave Ferguson
-
Here's a good example of what's available on Spectra Assure Community. You can even get a free API token to automate protection from threats in OSS.
Here's a good example of what's available on Spectra Assure Community. You can even get a free API token to automate protection from threats in OSS.
Shared by Dave Ferguson
-
🚨 Developers using Lightning for AI/ML projects might want to take a closer look before the next pip install. The package currently shows: -1…
🚨 Developers using Lightning for AI/ML projects might want to take a closer look before the next pip install. The package currently shows: -1…
Liked by Dave Ferguson
-
Celebrating 19 years with this amazing lady Lisa Johnson. Joined by friend and #TeamCAI colleague Frank Ury and Rhonda for a celebration at 1587…
Celebrating 19 years with this amazing lady Lisa Johnson. Joined by friend and #TeamCAI colleague Frank Ury and Rhonda for a celebration at 1587…
Liked by Dave Ferguson
-
Looking forward to speaking at BSidesKC, Inc this Saturday, April 25 at 1:00pm. Talk is on AI-powered pentesting (what works, what doesn't). A few of…
Looking forward to speaking at BSidesKC, Inc this Saturday, April 25 at 1:00pm. Talk is on AI-powered pentesting (what works, what doesn't). A few of…
Liked by Dave Ferguson
-
echo "2000 word essay on a topic of your choice" | claude >> /dev/null I've been hearing whispers of people confessing to burning tokens because…
echo "2000 word essay on a topic of your choice" | claude >> /dev/null I've been hearing whispers of people confessing to burning tokens because…
Liked by Dave Ferguson
-
Huge thanks to Kyle Rogers from GuidePoint Security for hitting the mark at our #GenAI #DataSecurity Lunch & Learn event in Baton Rouge today! Kyle’s…
Huge thanks to Kyle Rogers from GuidePoint Security for hitting the mark at our #GenAI #DataSecurity Lunch & Learn event in Baton Rouge today! Kyle’s…
Liked by Dave Ferguson
-
I recently came across the actual certificate from one of the most defining challenges of my early Army career. Fort Leavenworth. Summer 1993. I…
I recently came across the actual certificate from one of the most defining challenges of my early Army career. Fort Leavenworth. Summer 1993. I…
Liked by Dave Ferguson
-
RL Research Alert! #TeamPCP has again compromised Checkmarx VSCode extensions and Docker images. Newly published VSCode extensions…
RL Research Alert! #TeamPCP has again compromised Checkmarx VSCode extensions and Docker images. Newly published VSCode extensions…
Liked by Dave Ferguson
-
After more than two decades, I’ve started a new chapter by launching Streamline IT. I joined TouchNet, A Global Payments Company as its first IT…
After more than two decades, I’ve started a new chapter by launching Streamline IT. I joined TouchNet, A Global Payments Company as its first IT…
Liked by Dave Ferguson
-
Not every Monday involves running into a world champion, but today was not every Monday. Mario "El Azteca" Barrios was as cool as you hope he would…
Not every Monday involves running into a world champion, but today was not every Monday. Mario "El Azteca" Barrios was as cool as you hope he would…
Liked by Dave Ferguson
-
Well, my time with Security Journey has come to an end, so I'm ramping up my efforts on Katilyst, Consulting, and Community initiatives. My mission:…
Well, my time with Security Journey has come to an end, so I'm ramping up my efforts on Katilyst, Consulting, and Community initiatives. My mission:…
Liked by Dave Ferguson
Other similar profiles
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content