Sign in

Josh Grossman (tghosth 👻)

@joshcgrossman.com
1.3K followers 432 following 182 posts

Friendly AppSec Ghost 👻 appsecg.host

PostsRepliesMedia
Josh Grossman (tghosth 👻) @joshcgrossman.com · 08/06/2026
Introducing, the new Secure Software Development Lifecycle!!!!!
042
Josh Grossman (tghosth 👻) @joshcgrossman.com · 20/05/2026
🚀 Introducing aghast v0.7.1: Diff-scoped security scanning When you're reviewing a PR, you don't want to be flooded with findings from code that didn't change. v0.7.1 adds automatic diff filtering so aghast focuses its analysis on what actually changed. 1/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 18/05/2026
Them: We need a super-sophisticated AI powered security review tool to stop vulnerabilities entering our products. Me: No, you just need to stop ignoring the security PR comments that your current AI reviewer is adding...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/05/2026
Live footage of anyone trying to do anything clever using the @ClaudeDevs AgentSDK 🤦‍♂️🤦‍♂️🤦‍♂️ #Anthropic #BaitAndSwitcha #Claude
000
Reposted by Josh Grossman (tghosth 👻)
OWASP Juice Shop @owasp-juice.shop · 13/05/2026
OWASP Juice Shop v20 is here! 🍹 Featuring: AI/LLM-based chatbot (w/ 3 hacking + 2 coding challenges), redesigned storefront, ~30% faster startup time, Angular 21, neon-fire & lime-green theme, and much more! owasp.org/blog/2026/05...
12113
Josh Grossman (tghosth 👻) @joshcgrossman.com · 12/05/2026
Quiz! I submitted an Open Source Program application to @AnthropicAI to assist with my work on @OWASP_ASVS. (Don't quite meet requirements but thought I'd try) Did I get: a) Accepted onto the program b) No response c) Spam to the email address I used to register d) both b + c?
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 10/05/2026
Having spent a bunch of time using Opus, I tried to economize last week by using Sonnet more. I feel like it makes more mistakes and needs more guidance, even if I get Opus to plan first. Starting to wonder whether the time incurred costs more than the token saving...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 07/05/2026
🚀 aghast v0.6.0 is out! Cost and budget controls, per-check repository exclusion, and enhanced security hardening. Run aghast stats to see your scan costs, set budgets, and scale with confidence. Get it: npm install -g @bouncesecurity/aghast #SecurityTesting #DevSecOps
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/05/2026
Wearing my @Semgrep socks to celebrate as sorting by name finally comes to the Semgrep playground. Thanks Semgrep Hack Week!!!
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 04/05/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 5th example where we take the units produced by a @Knostic OpenAnt scan and scan those units individually for vulnerabilities.
youtu.be
AGHAST - Walkthrough of Example 5
This video walks you through example 5 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-5-various-security-vulnerabilities-targeted-check-openant-discovery-general-vulnerability-analysis Link to
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 30/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 4th example takes a SARIF file simulating some generic SAST results and evaluates each finding to decide if it is a false positive.
youtu.be
AGHAST - Walkthrough of Example 4
This video walks you through example 4 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-4-sast-finding-verification-targeted-check-sarif-input-false-positive-validation Link to the repository of
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 28/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 3rd example which doesn't use AI at all but rather just a custom written static rule to find exposed API endpoints without authentication decorators.
youtu.be
AGHAST - Walkthrough of Example 3
This video walks you through example 3 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-3-missing-api-token-decorator-static-check-semgrep-discovery Link to the repository of public examples: ht
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 27/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 2nd video is a hybrid check using a static @Semgrep rule to find uses of a sensitive function and an AI prompt on each use to check for correct validation.
youtu.be
AGHAST - Walkthrough of Example 2
This video walks you through example 2 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-2-important-validations-before-ai-queries-targeted-check-semgrep-discovery Link to the repository of publi
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 27/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 5th example where we take the units produced by a @Knostic OpenAnt scan and scan those units individually for vulnerabilities.
youtu.be
AGHAST - Walkthrough of Example 5
This video walks you through example 5 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-5-various-security-vulnerabilities-targeted-check-openant-discovery-general-vulnerability-analysis Link to
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 26/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the first one with a simple check that just uses an AI prompt to look for business logic being incorrectly enforced.
youtu.be
AGHAST - Walkthrough of Example 1
This video walks you through example 1 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-1-business-logic-bypass-repository-check Link to the repository of public examples: https://github.com/Bou
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 23/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 4th example takes a SARIF file simulating some generic SAST results and evaluates each finding to decide if it is a false positive.
youtu.be
AGHAST - Walkthrough of Example 4
This video walks you through example 4 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-4-sast-finding-verification-targeted-check-sarif-input-false-positive-validation Link to the repository of
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 21/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 3rd example which doesn't use AI at all but rather just a custom written static rule to find exposed API endpoints without authentication decorators.
youtu.be
AGHAST - Walkthrough of Example 3
This video walks you through example 3 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-3-missing-api-token-decorator-static-check-semgrep-discovery Link to the repository of public examples: ht
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 20/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 2nd video is a hybrid check using a static @Semgrep rule to find uses of a sensitive function and an AI prompt on each use to check for correct validation.
youtu.be
AGHAST - Walkthrough of Example 2
This video walks you through example 2 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-2-important-validations-before-ai-queries-targeted-check-semgrep-discovery Link to the repository of publi
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 16/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. There is the first one with a simple check that just uses an AI prompt to look for business logic being incorrectly enforced.
youtu.be
AGHAST - Walkthrough of Example 1
This video walks you through example 1 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-1-business-logic-bypass-repository-check Link to the repository of public examples: https://github.com/Bou
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/04/2026
Today, we are releasing AGHAST, an open source framework that combines static discovery with AI prompts to find repository-specific and company-specific security issues for accurate and economical analysis. 1/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 06/04/2026
I think my local, multi git account setup has reached its final form (for now...), starting Microsoft Windows, 1Password and some help from Claude :) Check out details here:
joshcgrossman.com
Getting multiple GitHub accounts on one Windows machine – 2026 update
A guide on how to manage multiple GitHub accounts on a single Windows machine using 1Password and SSH host aliases, updated for 2026.
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 30/03/2026
I think my local, multi git account setup has reached its final form (for now...), starting Microsoft Windows, 1Password and some help from Claude :) Check out details here:
joshcgrossman.com
Getting multiple GitHub accounts on one Windows machine – 2026 update
A guide on how to manage multiple GitHub accounts on a single Windows machine using 1Password and SSH host aliases, updated for 2026.
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 23/03/2026
Be the first to attend my new training course at @OWASP Global AppSec Vienna! "Repeatable, Scalable and Valuable Code Security Scanning" is a deep dive into the newest ways to validate code security with a strong emphasis on AI acceleration. Register: owaspglobalappseceuv...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 16/03/2026
Be the first to attend my new training course at @OWASP Global AppSec Vienna! "Repeatable, Scalable and Valuable Code Security Scanning" is a deep dive into the newest ways to validate code security with a strong emphasis on AI acceleration. Register: owaspglobalappseceuv...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 16/02/2026
I'm sure this blogpost will be interesting to the two or three other people people in the world who are using Claude Code on Windows and want to have multiple accounts active :) Keen to hear feedback and experiences 😀
joshcgrossman.com
Running two Claude Code accounts on one Windows PC (without them fighting)
How I isolated Personal and Work Claude Code accounts on a single Windows machine by faking per-account home directories and a handful of symlinks.
030
Josh Grossman (tghosth 👻) @joshcgrossman.com · 09/02/2026
I'm sure this blogpost will be interesting to the two or three other people people in the world who are using Claude Code on Windows and want to have multiple accounts active :) Keen to hear feedback and experiences 😀
joshcgrossman.com
Running two Claude Code accounts on one Windows PC (without them fighting)
How I isolated Personal and Work Claude Code accounts on a single Windows machine by faking per-account home directories and a handful of symlinks.
020
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/01/2026
Starting off the year with the uno reverse card 🤣🤣🤣
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 01/12/2025
LONDON, BABY! I'm bringing my course "Building a High-Value AppSec Scanning Programme" to London as part of @OWASP's London training days, 23-24 February 2026. As seen at OWASP Global conferences, @BlackHatEvents and @NDC_Conferences, don't miss your chance to attend!
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/11/2025
#justaithings
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 04/11/2025
CFTs for both @BlackHatEvents #BHUSA and @OWASP Global AppSec EU (Vienna) are now open and close in early December! Thinking of submitting? Check out my blog series for @BounceSecurity "So you want to train at Black Hat (or other conferences)?"
bouncesecurity.com
So, you want to train at Black Hat (or other conferences)? An Introduction | Bounce Security
Efficient, Value-Driven Product Security
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 02/09/2025
If you attended my vibe coding session at the @OWASP Community at @defcon (or you didn't but you are interested) and you want to continue the conversation, Emile Delcourt opened a dedicated channel on the @OWASP slack workspace: owasp.slack.com/arch...
011
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/08/2025
About to head home after a packed week+ in Vegas for Hacker Summer Camp. Some highlights for me:
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 06/08/2025
My searing hot take for today is that everyone hitting out at "security influencer" culture might want to consider that being able to persuade and influence is probably the most important tool in your security skillset.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/08/2025
Excited to be back delivering my course again at Black Hat USA!
120
Josh Grossman (tghosth 👻) @joshcgrossman.com · 17/07/2025
The final two parts of my blog series about delivering training at conferences have now been released! You can check them out on the @BounceSecurity website now!
121
Josh Grossman (tghosth 👻) @joshcgrossman.com · 24/06/2025
Pulled last year's class workbook out so that I can prepare the updated version for this year. You still have time to sign up for my updated course at @blackhatofficial.bsky.social #BHUSA, in person in Las Vegas, August 4-5.
110
Josh Grossman (tghosth 👻) @joshcgrossman.com · 12/06/2025
So you have a great training course with super-cool interactivity, now you have to get it accepted. In my next blogpost, I talk about writing a proposal which appeals to both the review board and also your potential attendees. Check it out here: www.bouncesecurity.c...
111
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/06/2025
Last week, I was honoured to received a Distinguished Lifetime Member award from OWASP at Global AppSec EU Barcelona 2025. I wrote more about it here: www.linkedin.com/pos...
040
Reposted by Josh Grossman (tghosth 👻)
OWASP ASVS @asvs.owasp.org · 30/05/2025
So @ElarLang just published version 5.0.0 of OWASP ASVS, live on stage at @OWASP Global AppSec EU Barcelona 2025!
0129
Reposted by Josh Grossman (tghosth 👻)
Daniel Cuthbert @dcuthbert.bsky.social · 30/05/2025
In October, 2021, we released 4.0.3 of the OWASP ASVS Standard. This release marked the start of the Vanilla Ice (or 5.0 as everyone else called it) release. A major rethink about how we use the standard and with feedback from the community.
272
Josh Grossman (tghosth 👻) @joshcgrossman.com · 19/05/2025
Last week to save before prices go up on 23rd May! Unless you Accelerate your AppSec Programme, you are going to get left behind.. Join me @blackhatofficial.bsky.social #BHUSA this summer in Las Vegas (4-5 Aug) for a practical guide on how to build bridges with developers and build securely!
011
Josh Grossman (tghosth 👻) @joshcgrossman.com · 13/05/2025
Welcome @blackhatofficial.bsky.social 🙂 You should probably report this account for impersonation though... bsky.app/profile/blac...
bsky.app
000
Reposted by Josh Grossman (tghosth 👻)
Black Hat Events @blackhatofficial.bsky.social · 12/05/2025
The #BHUSA Early Registration Rate ends May 23rd! Register today to lock-in the lowest rate before it increases. Register here >> bit.ly/4jnXIa5 #BHUSA #Cybersecurity
011
Reposted by Josh Grossman (tghosth 👻)
Black Hat Events @blackhatofficial.bsky.social · 08/05/2025
The #BHUSA 2025 Early Registration rate ends MAY 23! Secure your spot today at the lowest rates available>> bit.ly/4l9aYRH
011
Josh Grossman (tghosth 👻) @joshcgrossman.com · 13/05/2025
Want to make your security training course memorable? 🎯 My latest post dives into creative ways to get students' hands dirty, from cloud-hosted labs to simulated stakeholder exercises. Learn how to make practical exercises the highlight of your course, not just an afterthought.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 21/04/2025
My blog series on developing training courses continues with a post about how to find the topic you are passionate about and that will also attract attendees: www.bouncesecurity.c...
bouncesecurity.com
Finding your niche/selling point | Bounce Security
Introduction
000
Reposted by Josh Grossman (tghosth 👻)
Catalin Cimpanu @campuscodi.risky.biz · 10/04/2025
The bat-shit insane stories coming out of the US government this week is quite something
0182
Josh Grossman (tghosth 👻) @joshcgrossman.com · 01/04/2025
So, you've decided you want to deliver training courses at a conference? In the next post in my series about my experiences, I want to talk about money. I don't think it should be your main motivation but you probably can't ignore it! Check it out: www.bouncesecurity.c...
100
Reposted by Josh Grossman (tghosth 👻)
OWASP ASVS @asvs.owasp.org · 31/03/2025
You can find out details in our contribution guide: github.com/OWASP/ASV... Alternatively, get in contact with us via OWASP Slack: owasp.slack.com/arch... Have your say now! Submit early to avoid disappointment 😀 2/2
github.com
ASVS/CONTRIBUTING.md at master · OWASP/ASVS
Application Security Verification Standard. Contribute to OWASP/ASVS development by creating an account on GitHub.
043
Reposted by Josh Grossman (tghosth 👻)
OWASP ASVS @asvs.owasp.org · 31/03/2025
📯YOUR INPUT IS NEEDED!📯 @OWASP ASVS version 5.0 release candidate is ready for review. The final version is planned for the end of May. We want your feedback before then! Can devs understand it? How about testers? Anything missing? Dive into GitHub and let us know! 1/2
165