🛡️ Open WAF Day Vienna 2026 — full agenda is live!
📅 Wed June 24 · Austria Center, Vienna
🎤 5 talks: Coraza on Envoy, GitOps, Ingress NGINX migration, adaptive honeypots & more
💸 Free
Register 👇
Open WAF Day Vienna 2026 recap is up 🇦🇹 Talks on the new Coraza/Envoy connector, blazing-fast WAF log analysis, Coraza Center + GitOps, life after Ingress NGINX, and CRS-powered adaptive honeypots. Thanks to everyone who joined us!
📖 coreruleset.org/20260629/open-…#OWASP#WAF#AppSec
Part 2 of the CRS 3→4 migration series: configuration. Don't reuse your old crs-setup.conf — variables were renamed, split, and added. Post includes a full checklist and an interactive migration tool.
coreruleset.org/20260406/migra…#OWASP#CRS#WAF#AppSec
Migrating from OWASP CRS 3.3 to 4.25 LTS? Part 1 of a 7-part series is out — covering what changed, what breaks, and how to plan your upgrade. ~500 changes, new plugin architecture, RE2/Hyperscan compat, and more.
🔒 Security Advisory: OWASP CRS file upload extension checks could be bypassed using whitespace padding in filenames (e.g. shell. php). CVE-2026-33691, Moderate severity.
Upgrade to CRS v4.25.0 or v3.3.9.
Thanks @HackingRepo for the report!