New ZAP PTK Add-On Converts Browser Security Findings Into Native ZAP Alerts
ID: 8fce9636-afdc-53a3-99e3-8f6c89ef644b
STIX ID: report--8fce9636-afdc-53a3-99e3-8f6c89ef644b
Feed Name: GBHackers
The report announces OWASP ZAP PTK Add-on 0.3.0, which integrates browser-based client-side security findings (SAST, IAST, DAST) into native ZAP alerts, adds 142 PTK-tagged alert types, and supports features like custom rule selection and auto-start scanning. It explains how PTK helps detect client-side issues in modern SPAs (e.g., DOM-based XSS and unsafe JavaScript patterns) that traditional proxy tools miss and provides step-by-step instructions to install and run the integration for testing (using OWASP Juice Shop as an example).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
