Sign in

Josh Grossman (tghosth 👻)

@joshcgrossman.com
1.3K followers 432 following 182 posts

Friendly AppSec Ghost 👻 appsecg.host

PostsRepliesMedia
Josh Grossman (tghosth 👻) @joshcgrossman.com · 08/06/2026
Introducing, the new Secure Software Development Lifecycle!!!!!
042
Josh Grossman (tghosth 👻) @joshcgrossman.com · 20/05/2026
🚀 Introducing aghast v0.7.1: Diff-scoped security scanning When you're reviewing a PR, you don't want to be flooded with findings from code that didn't change. v0.7.1 adds automatic diff filtering so aghast focuses its analysis on what actually changed. 1/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 18/05/2026
Them: We need a super-sophisticated AI powered security review tool to stop vulnerabilities entering our products. Me: No, you just need to stop ignoring the security PR comments that your current AI reviewer is adding...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/05/2026
Live footage of anyone trying to do anything clever using the @ClaudeDevs AgentSDK 🤦‍♂️🤦‍♂️🤦‍♂️ #Anthropic #BaitAndSwitcha #Claude
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 12/05/2026
Quiz! I submitted an Open Source Program application to @AnthropicAI to assist with my work on @OWASP_ASVS. (Don't quite meet requirements but thought I'd try) Did I get: a) Accepted onto the program b) No response c) Spam to the email address I used to register d) both b + c?
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 10/05/2026
Having spent a bunch of time using Opus, I tried to economize last week by using Sonnet more. I feel like it makes more mistakes and needs more guidance, even if I get Opus to plan first. Starting to wonder whether the time incurred costs more than the token saving...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 07/05/2026
🚀 aghast v0.6.0 is out! Cost and budget controls, per-check repository exclusion, and enhanced security hardening. Run aghast stats to see your scan costs, set budgets, and scale with confidence. Get it: npm install -g @bouncesecurity/aghast #SecurityTesting #DevSecOps
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/05/2026
Wearing my @Semgrep socks to celebrate as sorting by name finally comes to the Semgrep playground. Thanks Semgrep Hack Week!!!
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/04/2026
Today, we are releasing AGHAST, an open source framework that combines static discovery with AI prompts to find repository-specific and company-specific security issues for accurate and economical analysis. 1/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 23/03/2026
Be the first to attend my new training course at @OWASP Global AppSec Vienna! "Repeatable, Scalable and Valuable Code Security Scanning" is a deep dive into the newest ways to validate code security with a strong emphasis on AI acceleration. Register: owaspglobalappseceuv...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 16/03/2026
Be the first to attend my new training course at @OWASP Global AppSec Vienna! "Repeatable, Scalable and Valuable Code Security Scanning" is a deep dive into the newest ways to validate code security with a strong emphasis on AI acceleration. Register: owaspglobalappseceuv...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/01/2026
Starting off the year with the uno reverse card 🤣🤣🤣
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 01/12/2025
LONDON, BABY! I'm bringing my course "Building a High-Value AppSec Scanning Programme" to London as part of @OWASP's London training days, 23-24 February 2026. As seen at OWASP Global conferences, @BlackHatEvents and @NDC_Conferences, don't miss your chance to attend!
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/11/2025
#justaithings
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/08/2025
About to head home after a packed week+ in Vegas for Hacker Summer Camp. Some highlights for me:
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 06/08/2025
My searing hot take for today is that everyone hitting out at "security influencer" culture might want to consider that being able to persuade and influence is probably the most important tool in your security skillset.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/08/2025
Excited to be back delivering my course again at Black Hat USA!
120
Josh Grossman (tghosth 👻) @joshcgrossman.com · 17/07/2025
The final two parts of my blog series about delivering training at conferences have now been released! You can check them out on the @BounceSecurity website now!
121
Josh Grossman (tghosth 👻) @joshcgrossman.com · 24/06/2025
Pulled last year's class workbook out so that I can prepare the updated version for this year. You still have time to sign up for my updated course at @blackhatofficial.bsky.social #BHUSA, in person in Las Vegas, August 4-5.
110
Josh Grossman (tghosth 👻) @joshcgrossman.com · 12/06/2025
So you have a great training course with super-cool interactivity, now you have to get it accepted. In my next blogpost, I talk about writing a proposal which appeals to both the review board and also your potential attendees. Check it out here: www.bouncesecurity.c...
111
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/06/2025
Last week, I was honoured to received a Distinguished Lifetime Member award from OWASP at Global AppSec EU Barcelona 2025. I wrote more about it here: www.linkedin.com/pos...
040
Josh Grossman (tghosth 👻) @joshcgrossman.com · 19/05/2025
Last week to save before prices go up on 23rd May! Unless you Accelerate your AppSec Programme, you are going to get left behind.. Join me @blackhatofficial.bsky.social #BHUSA this summer in Las Vegas (4-5 Aug) for a practical guide on how to build bridges with developers and build securely!
011
Josh Grossman (tghosth 👻) @joshcgrossman.com · 13/05/2025
Want to make your security training course memorable? 🎯 My latest post dives into creative ways to get students' hands dirty, from cloud-hosted labs to simulated stakeholder exercises. Learn how to make practical exercises the highlight of your course, not just an afterthought.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 24/03/2025
This year should hopefully be the 3rd year that I train at @BlackHatEvents #BHUSA and also at @OWASP #AppSecEU? But how did I get to this stage? The short answer is a lot of thought and hard work. And the long answer? Well I thought I'd write some thoughts down... 🧵 1/x
101
Josh Grossman (tghosth 👻) @joshcgrossman.com · 18/03/2025
At @BlackHatEvents #BHUSA on 4-5 Aug in Las Vegas, you can attend "Accelerated AppSec: Hacking your Product Security Programme for Velocity and Value". This course helps you build a successful programme to bridge the gap between developers and security, without losing speed. 4/5
101
Josh Grossman (tghosth 👻) @joshcgrossman.com · 18/03/2025
At #GlobalAppSec EU on 26-27 May at the CCIB in Barcelona, you can attend "Building a High-Value AppSec Scanning Programme", with big updates for 2025. If you want to build effective and valuable processes around tools like SAST, DAST and SCA, this is the course for you. 2/5
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 18/03/2025
For the third year running, I am going to be delivering application security training at both @OWASP #GlobalAppSec EU in Barcelona (26-27 May) and also @BlackHatEvents #BHUSA in Las Vegas (4-5 Aug) and I am super excited! Want to hear more? Keep reading... 1/5
121
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/03/2025
At @BlackHatEvents #BHUSA on 4-5 Aug in Las Vegas, you can attend "Accelerated AppSec: Hacking your Product Security Programme for Velocity and Value". This course helps you build a successful programme to bridge the gap between developers and security, without losing speed. 4/5
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/03/2025
At #GlobalAppSec EU on 26-27 May at the CCIB in Barcelona, you can attend "Building a High-Value AppSec Scanning Programme", with big updates for 2025. If you want to build effective and valuable processes around tools like SAST, DAST and SCA, this is the course for you. 2/5
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/03/2025
For the third year running, I am going to be delivering application security training at both @OWASP #GlobalAppSec EU in Barcelona (26-27 May) and also @BlackHatEvents #BHUSA in Las Vegas (4-5 Aug) and I am super excited! Want to hear more? Keep reading... 1/5
130
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/02/2025
If you want to find the finest vulnerabilities, look for the feature that was considered a critical delivery from a business perspective and was therefore rushed out super fast...
050
Josh Grossman (tghosth 👻) @joshcgrossman.com · 10/02/2025
What fresh hell is this!!! And where is my Right-Ctrl!!!
230
Josh Grossman (tghosth 👻) @joshcgrossman.com · 04/02/2025
Inspired by @sethlaw.bsky.social on the @absoluteappsec.bsky.social podcast... Eliminate entire classes of vulnerabilities in your app by learning which findings from your SAST are always nonsense and ignoring them...
022
Josh Grossman (tghosth 👻) @joshcgrossman.com · 03/02/2025
I wrote a blog for AppSec practitioners about how you gather information about what is going on in the development organization. Some of it is more relevant when contracting but a lot of it is relevant to internal people as well.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 03/02/2025
Attention 3rd party library risk experts! On a scale of 1 to 10, how high would you rate the risk for: "library is hosted on SourceForge" Is the library considered "end of life"? Never mind that, is the platform which hosts it considered "end of life"....?!?!?
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 29/01/2025
0-days since last time it was DNS
0-days since last time it was DNS (futurama accident meme)
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 29/01/2025
Apparently moving blogging platform on the same day as publishing a popular blog post was not a smart move by me...
DM which says "The link in your article today isn't working for me."

Includes a screenshot which says there is a DNS problem when trying to access my blog.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 28/01/2025
If you were looking for a comprehensive update and clarification on what has happened with @Semgrep and @opengrep so far, I wrote up a post about it. There are some nuances that got lost in this story but overall I think this is a positive thing for the Semgrep engine.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 28/01/2025
What I should have done this morning: Published my 6 page blog post about what's going on with @Opengrep and @Semgrep What I actually did this morning: Migrated my website, blog and all historic posts over to Jekyll 🤦‍♂️ I'll get there, I promise.
210
Josh Grossman (tghosth 👻) @joshcgrossman.com · 27/01/2025
What I should have done this evening: Worked on the @asvs.owasp.org What I actually did this evening: Wrote a 6 page blog post about whats going on with @opengrep and @semgrep 🤦‍♂️ Look out for that tomorrow...
130
Josh Grossman (tghosth 👻) @joshcgrossman.com · 24/01/2025
However, the CEO's subsequent statement on December community slack channel states that this rule use was not allowed according to the license (see screenshot below). 7/10
110
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/01/2025
I'm going to be talking about the @OWASP_ASVS at @jit_io 's DevSecNext conference TONIGHT. Catch me in the back room upstairs at 18:15!
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 08/01/2025
I have a Windows VM that I rarely use and having booted it and done 45+ minutes of updates I think I now remember why... 1/2
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 09/12/2024
Sometimes I have to wonder how threads take the direction which they do.... 😂😂😂 cc: @viss.hax.lol
040
Josh Grossman (tghosth 👻) @joshcgrossman.com · 02/12/2024
That is not very imaginative from @Github Copilot...
110
Josh Grossman (tghosth 👻) @joshcgrossman.com · 27/11/2024
My email inbox says that an updated passkeys blogpost is coming 😀
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 25/11/2024
Use jorts, not JWTs!
020
Josh Grossman (tghosth 👻) @joshcgrossman.com · 25/11/2024
JWTs were a mistake
030
Josh Grossman (tghosth 👻) @joshcgrossman.com · 25/11/2024
Who can spot how @Hacker0x01's AI chatbot has beclowned me? Always check the results, people!!!
110
Josh Grossman (tghosth 👻) @joshcgrossman.com · 24/11/2024
Well.... Guess I'm a robot then...
010