1. X
  2. Core Rule Set
Log inSign up
Core Rule Set
560 posts
Image
user avatar
Core Rule Set
@CoreRuleSet
coreruleset.org
Joined May 2017
32
Following
1,236
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    user avatar
    Core Rule Set
    @CoreRuleSet
    Jun 18
    🛡️ Open WAF Day Vienna 2026 — full agenda is live! 📅 Wed June 24 · Austria Center, Vienna 🎤 5 talks: Coraza on Envoy, GitOps, Ingress NGINX migration, adaptive honeypots & more 💸 Free Register 👇
    coreruleset.org
    Open WAF Day Vienna 2026 – Full Agenda Announced
    We are happy to share the full agenda for Open WAF Day Vienna 2026, taking place on Wednesday, June 24, 2026 at the Austria Center in Vienna. Five talks, two connectors, one adaptive honeypot, and a...
    91
  • user avatar
    Core Rule Set
    @CoreRuleSet
    Jul 27
    Open WAF Day Vienna 2026 recap is up 🇦🇹 Talks on the new Coraza/Envoy connector, blazing-fast WAF log analysis, Coraza Center + GitOps, life after Ingress NGINX, and CRS-powered adaptive honeypots. Thanks to everyone who joined us! 📖 coreruleset.org/20260629/open-… #OWASP #WAF #AppSec
    coreruleset.org
    Open WAF Day Vienna 2026
    Open WAF Day Vienna 2026 is behind us, and it’s time to look back at a great day of talks and discussions at the Austria Center. We had around 20-30 people join us in the room, catching up between...
    379
  • user avatar
    Core Rule Set
    @CoreRuleSet
    Apr 7
    Part 2 of the CRS 3→4 migration series: configuration. Don't reuse your old crs-setup.conf — variables were renamed, split, and added. Post includes a full checklist and an interactive migration tool. coreruleset.org/20260406/migra… #OWASP #CRS #WAF #AppSec
    Image
    Migrating from CRS 3.3 to CRS 4.25 LTS — Part 2: Configuration
    From coreruleset.org
    116
  • user avatar
    Core Rule Set
    @CoreRuleSet
    Apr 1
    Migrating from OWASP CRS 3.3 to 4.25 LTS? Part 1 of a 7-part series is out — covering what changed, what breaks, and how to plan your upgrade. ~500 changes, new plugin architecture, RE2/Hyperscan compat, and more.
    Image
    Migrating from CRS 3.3 to CRS 4.25 LTS — Part 1: Overview
    From coreruleset.org
    128
  • user avatar
    Core Rule Set
    @CoreRuleSet
    Mar 30
    🔒 Security Advisory: OWASP CRS file upload extension checks could be bypassed using whitespace padding in filenames (e.g. shell. php). CVE-2026-33691, Moderate severity. Upgrade to CRS v4.25.0 or v3.3.9. Thanks @HackingRepo for the report!
    Image
    Whitespace padding in filenames bypasses file upload extension checks
    From github.com
    323
  • See @CoreRuleSet's full profile

    Sign up
    Log in
Advertisement
Advertisement