#JavaSecurity
🎉 Apache Shiro 2.1.0 release!

- fixing real auth & session edge cases
- unblocking legitimate requests (CORS, encoded paths)
- dependency upgrades

Release notes 👇

github.com/apache/shiro...

#Java #OpenSource #ApacheShiro @apache.org #OSS #JavaSecurity
Release Apache Shiro 2.1.0 · apache/shiro
What's Changed chore(deps): bump org.htmlunit:htmlunit from 4.17.0 to 4.18.0 by @dependabot[bot] in #2355 chore: hide deprecation warning in AD test by @lprimak in #2352 chore(deps): bump github/c...
github.com
February 10, 2026 at 3:58 PM
#Java Cryptography Architecture (JCA) - An Overview

Provider-based crypto framework enables secure hashing, digital signatures, key management & more — all modular, extensible, and ready for real-world security needs. #JavaSecurity #Cryptography #JCA #SecureCoding

svenruppert.com/2025/04/03/j...
Java Cryptography Architecture (JCA) – An Overview
The Java Cryptography Architecture (JCA) is an essential framework within the Java platform that provides developers with a flexible and extensible interface for cryptographic operations. It is a c…
svenruppert.com
April 3, 2025 at 10:26 AM
🚀 New article: Boost your security skills with my latest guide on essential #application #security #testing! 
Explore SCA, SAST, DAST, and PenTest to protect your projects from vulnerabilities. 

#JavaSecurity #Cybersecurity #AppSec #SecurityTesting

ionutbalosin.com/2025/03/secu...
Security Application Testing for Java Developers
Content Introduction Software Composition Analysis (SCA) Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) Penetration Testing (PenTest) Summary References 🔒 This ...
ionutbalosin.com
March 25, 2025 at 7:05 AM
⚠️ Androxgh0st botnet is back and evolving
🎯 Targets US universities including UC San Diego
💥 Uses RCE, JNDI, OGNL, web shells
🛡️ Patch devices now!

🔗 hackread.com/androxgh0st-...

#Androxgh0st #CyberSecurity #RCE #InfoSec #JavaSecurity
Androxgh0st Botnet Expands Reach, Exploiting US University Servers
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
June 24, 2025 at 5:32 PM
Java devs, stop guessing security! tr1ple's “Java openrasp学习记录‑2” spills the beans on lifesaving Runtime App Self‑Protection: real config hacks, step‑by‑step demos, and no‑frills insights. Ready to lock your Java apps? #OpenRASP #JavaSecurity ➜ Dive deeper 🚀

🔗 https://www.cnblogs.com/tr1ple/p/12...
Java openrasp学习记录-2 - tr1ple
www.cnblogs.com
May 22, 2026 at 12:13 AM
Join us for this live-coding webinar tomorrow & get hands on guidance for improving authentication, authorization, and runtime validation in your Java applications!
crowdcast.io/c/modern-jav...

#Java #JavaEE #JakartaEE #JavaDeveloper #Security #JavaSecurity #PayaraCommunity @jakarta.ee
December 10, 2025 at 10:35 AM
Oracle Java 27 adds hybrid post-quantum key exchange to TLS 1.3, helping organizations strengthen cryptographic infrastructure against quantum threats ahead of large-scale quantum computing.

#PostQuantumCryptography #JavaSecurity #News
Oracle Java 27 Introduces Post-Quantum Cryptography for TLS 1.3
iq.fp2.dev
September 15, 2026 at 6:30 PM
August 7, 2026 at 4:15 PM
🔒 ¿Tus JVMs están parcheados? Azul te ayuda a encontrarlos antes que la IA

https://thenewstack.io/azul-java-security-jvm-mythos/

#JavaSecurity #JVM #Ciberseguridad #Azul
June 24, 2026 at 11:24 PM
🔐 ¿Tu código Java está a salvo? Las 5 vulnerabilidades más críticas y cómo evitarlas

https://dzone.com/articles/java-security-vulnerabilities-prevention

#JavaSecurity #Ciberseguridad #DesarrolloSeguro #DevTips
June 21, 2026 at 11:25 PM
CRITICAL: Hutool <5.8.4 lets attackers exploit QLExpressEngine for RCE in Java apps. Audit, upgrade, and boost input validation now. No patch? Use WAF/RASP as interim defense. Details: https://radar.offseq.com/threat/cve-2025-56769-na-c4c55b32 #OffSeq #JavaSecurity #RCE
September 26, 2025 at 7:32 AM
HubSpot jinjava <2.8.1 hit by CRITICAL flaw—unsafe deserialization leads to RCE. Patch to 2.8.1+ now! Affects Java web apps. Details: https://radar.offseq.com/threat/cve-2025-59340-cwe-1336-improper-neutralization-of-b51614b8 #OffSeq #CVE202559340 #JavaSecurity
September 18, 2025 at 4:32 AM
NetSPI Security Consultant Mayuri Bochare has published an insightful deep-dive on securing Java Spring applications through code review.

👉 Read the full article: ow.ly/IWfx50WnoVy

#proactivesecurity #JavaSecurity #SecureCodeReview
Detecting Authorization Flaws in Java Spring via Source Code Review (SCR)
Discover how secure code review catches privilege escalation vulnerabilities in Java Spring apps that pentests miss - identify insecure patterns early.
ow.ly
July 10, 2025 at 1:42 PM
March 8, 2026 at 6:11 PM
The FFM API improves native integration by allowing fine-grained control over memory and function access. This is crucial for managing system resource permissions, preventing common JNI-related vulnerabilities, and boosting overall application security. #JavaSecurity 3/6
December 8, 2025 at 8:00 PM
Just dropped: A must-read guide to patching high-risk Tomcat flaws affecting SUSE Linux and enterprise users. Don’t wait—exploits are imminent. 👉 tinyurl.com/3kcewdf3 #SysAdmin #JavaSecurity
Critical Tomcat Security Update: Patch CVE-2025-31650 & CVE-2025-31651 Now
Blog com notícias sobre, Linux, Android, Segurança , etc
tinyurl.com
May 10, 2025 at 3:42 PM
Google fixes over 100 flaws in Android, many in chipset drivers http://lnk.al/1qas via @javaworldcom #Google #Android #JavaSecurity
December 7, 2024 at 12:43 PM
Oracle Releases June 2012 Java SE CPU, Fixes Sandbox Bypass | http://ht.ly/bD28w | #Oracle #JavaSecurity #JVM
December 7, 2024 at 11:06 AM