OWASP Ottawa
The OWASP Chapter for Canada's Capital region.
https://owasp.org/www-chapter-ottawa/
Join us for monthly meetups discussing a variety of security topics.
We are pleased to announce that Kayode Olabisi, FCIB will be speaking at #OWASP #Ottawa Day 2026 with:
"Your LLM App Passed the Checklist. Now What?"
If the OWASP Top 10 for LLMs provides risks this talk focuses on where controls belong. Using prompt injection, sensitive data disclosure, and supply chain risk as examples, it maps each to practical enforcement points across the application, policy layer, and model provider.
📅 October 17, 2026
ℹ️ Information: https://github.com/OWASP-Ottawa/OWASPOttawaDay2026
🎟️ Tickets (free): https://buytickets.at/owaspottawachapter/2389944
On behalf of OWASP Ottawa, a huge thank you to Professor Guy-Vincent Jourdan, the uOttawa | Faculty of Engineering | Faculté de génie Team and the UofO IBM CyberRange for supporting OWASP’s 25th Anniversary event at OWASP Ottawa Day!
Your generosity makes it possible for us to bring together the Ottawa security community for a full day of workshops, mentoring sessions, and talks. Events like this only happen because people like Professor Guy-Vincent Jourdan and organizations like University of Ottawa's Faculty of Engineering believe in investing in the community and in giving people a place to learn, connect, and grow.
We couldn't have pulled off this milestone without you. Thank you for backing OWASP Ottawa and for helping us celebrate 25 years of AppSec.
#OWASP #Ottawa #OWASPOttawa2026 #AppSec #Cybersecurity #Community
On behalf of #OWASP #Ottawa, a huge thank you to Mark Cimon and the Cimon Real Estate Team for supporting OWASP’s 25th Anniversary event at OWASP Ottawa Day!
Information and tickets:
https://github.com/OWASP-Ottawa/OWASPOttawaDay2026
#OWASP #Ottawa #OWASPOttawa2026 #AppSec #Cybersecurity #Community
🚨 #OWASP #Ottawa September 2026 #Meetup with Katie McMillan and Robert Babaev 🚨
Open Source Software is Federally Included in Canada with Katie McMillan
-and-
Can You Not? How to Avoid Destroying Prod with Agent Permissions with Robert Babaev
We’re looking for local organizations to help sponsor food, beverages, and/or swag for OWASP Ottawa Day on October 17, 2026.
Please consider supporting Ottawa’s application security community. Sponsorship is a great way to help make the event accessible, welcoming, and valuable for everyone attending.
Interested organizations will receive recognition as an event sponsor. Please contact us directly if you would like more information.
For the Community. By the Community.
🎉 Announcing OWASP Ottawa Day 2026 🎉
OWASP Ottawa is excited to announce that we will be hosting the “OWASP Ottawa Day 2026” on October 17, 2026, to celebrate the 25th anniversary of the establishment of the @owasp@infosec.exchange Foundation!
To make this a memorable event, we are inviting people from different fields within the Cyber Security community to present at our event. Whether you are a seasoned cybersecurity veteran with plenty of war stories or a budding cybersecurity enthusiast who wants to share what they are learning, we welcome all participants and offer a welcoming stage.
If you are interested in presenting a topic at our OWASP Ottawa Day 2026 event, please fill out the form at the link below.
Speaker talks submission form: https://docs.google.com/forms/d/e/1FAIpQLSe4W7iFl8bNQKZmBFQINGbMufktebe-hJ-4z-QjelzRGrWdwQ/viewform
We look forward to your submissions and to making this a memorable event for our Ottawa cybersecurity community!
Have any questions? Leave them in the comments section below 👇
🚨 OWASP Ottawa March 2026 Meetup - Featuring Garth Boyd! 🚨
OWASP Ottawa is excited to announce our March 2026 meetup featuring Garth Boyd present their talk “We know what you hide in JS: If it runs in the browser, it's public". The details are as follows:
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
📅 Date: March 18, 2026
⏰ Time: 6:00 PM EST - Arrival, networking, & pizza! 🍕
6:30 PM EST - Technical Talk
This session will focus on Garth going over some common and accidental assumptions made by software developers when writing JavaScript for modern applications, and how these mistakes can provide attackers with a variety of insights that can be leveraged to exploit vulnerabilities in a web application.
We will cover techniques and tools for performing comprehensive client-side JavaScript reconnaissance to uncover hidden endpoints, sensitive information, and potential security vulnerabilities.
Whether you’re a student, early-career professional, or seasoned practitioner looking to learn more about client-side security, come aboard and learn from experts!
We look forward to seeing you there in-person! If you cannot attend the event, you can watch the livestream on our YouTube channel.
🔗 : @OWASP_Ottawa@www.youtube.com
#OWASP #Ottawa #AppSec #Javascript #cybersecurity #networking
OWASP Ottawa would like to extend its gratitude to @garthoid@infosec.exchange (a.k.a, Garth Boyd) for an insightful presentation on their topic, "We know what you hide in JS" at our March 2026 meetup!
The topic was well-presented and a goldmine for developers and cybersecurity professionals, explaining what can go wrong when applications depend on client-side controls for securing web applications, and how to detect the presence of such secrets or other interesting patterns in JavaScript code.
Thank you once again, Garth! 👏
If you missed this session, you can catch the recording of this session on our YouTube channel, along with recordings of other sessions from our awesome speakers!
RE: @OWASP_Ottawa@infosec.exchange
Our monthly meetup is happening tomorrow (June 17)! As always, we will also be livestreaming the event on our YouTube channel at @owasp_ottawa@www.youtube.com
All details in the original post 👇
🚨 OWASP Ottawa June 2026 Meetup - with Ali Sadeghi Jahromi 🚨
OWASP Ottawa is excited to announce our June 2026 meetup featuring:
Blackout at Scale: A Multi-Perspective Study of Iran's Internet Shutdown
The details are as follows:
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
📅 Date: Wednesday June 17, 2026
⏰ Time: 6:00 PM EST - Arrival, networking, & pizza! 🍕
6:30 PM EST - Technical Talks
Blackout at Scale: A Multi-Perspective Study of Iran's Internet Shutdown with Ali Sadeghi Jahromi
This talk presents the Internet shutdowns in Iran during January and March 2026 using a multi-plane measurement approach that combines passive Internet-wide scanning, active probing, and BGP routing analysis. We show how these disruptions were enforced through centralized forwarding-plane null-routing while BGP announcements remained largely unchanged, effectively hiding outages from traditional routing-based monitoring. Using global scan data, we analyze how visible host populations collapse and fluctuate during shutdown periods, including apparent anomalies that reflect measurement artifacts rather than true recovery. Through active probing of thousands of Iranian prefixes from multiple global vantage points, we find that most infrastructure becomes consistently unreachable in a centrally coordinated manner, with only a small subset of networks remaining accessible. We further identify systematic structural exemptions, including academic networks and major CDN infrastructure, that exhibit distinct behavior under shutdown conditions. Together, these results demonstrate that different measurement perspectives provide complementary but individually limited views of large-scale Internet control, highlighting the need for a multi-plane approach to accurately interpret modern Internet shutdowns.
#owasp #ottawa #networking #cybersecurity #tech #internet #censorship
This past week, OWASP Ottawa had the pleasure of hosting @SheHacksPurple@infosec.exchange who's presentation titled " Secure Code Is Critical Infrastructure" gave us insights into her journey lobbying for the Canadian Government to implement a secure coding policy. During her talk, Tanya discussed her efforts to reach out to the elected officials and agencies like CRA to implement her (free) secure coding policy.
Thank you, Tanya for an amazing presentation, and we look forward to more talks from you in the future!
Missed this session? You can catch the recorded version of this talk on our YouTube channel.
🚨 OWASP Ottawa April 2026 Meetup - Featuring Rodrigo Rocha! 🚨
OWASP Ottawa is excited to announce our April 2026 meetup featuring Rodrigo Rocha present their talk “Threat Modeling in Practice: From Diagram to Defense". The details are as follows:
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 580
📅 Date: April 15, 2026
⏰ Time: 6:00 PM EST - Arrival, networking, & pizza! 🍕
6:30 PM EST - Technical Talk
Threat Modeling is often seen as heavy, theoretical, or compliance-driven, which leads to it being skipped. This session will focus on Rodrigo introducing a practical, lightweight approach to Threat Modeling that fits directly into agile workflows.
Using a real-world healthcare portal example, Rodrigo will walk us through the process from drawing a simple data flow diagram to identifying critical assets, mapping real attack scenarios (via MITRE CAPEC), linking root causes (CWE), and translating them into testable security requirements using OWASP ASVS.
Whether you’re a student, early-career professional, or seasoned practitioner looking to learn more about Threat Modeling, come aboard and learn from experts!
We look forward to seeing you there in-person! If you cannot attend the event, you can watch the livestream on our YouTube channel.
🎥 : @OWASP_Ottawa@www.youtube.com
Our Github Chapter page: https://github.com/OWASP-Ottawa/chapter-guide/blob/main/Nextevent/tab_nextevent.md
#OWASP #Ottawa #Cybersecurity #ThreatModeling #InfoSec #AppSec #TechCommunity
🎤 Call for Speakers: OWASP Ottawa Monthly Meetups 🎤
OWASP Ottawa is actively looking for speakers to present at our monthly meetups, and we warmly encourage first-time and beginner speakers to apply. Our chapter typically meets on the third Wednesday of each month.
If you’re passionate about cybersecurity and enjoy sharing knowledge, we’d love to hear from you.
📌 What speakers should know:
• OWASP Ottawa is a vendor-neutral, open-source community focused on improving software security.
• We are also open to speakers who wish to present cybersecurity-focussed talks that are not related to software security.
• However, all talks must be strictly non-commercial.
• Presentations should focus on education, research, open-source tools, or community benefit.
• Talks must not be used to promote products, services, or sales activities.
Company or tool references are allowed only when needed for technical context, not endorsement.
🕰️ Talk formats:
15, 30, or 50 minutes - your choice.
If you’ve been thinking about speaking but weren’t sure where to start, OWASP Ottawa is a supportive and inclusive place to share your ideas.
Apply using the Google Form linked in this post. We’re excited to hear your ideas and help amplify voices across the cybersecurity community!
Google Form: https://docs.google.com/forms/d/e/1FAIpQLSe4W7iFl8bNQKZmBFQINGbMufktebe-hJ-4z-QjelzRGrWdwQ/viewform
#OWASP #Ottawa #Cybersecurity #CallForSpeakers #InfoSec #AppSec #Community #PublicSpeaking
OWASP Ottawa
@owaspottawa.bsky.social
· 2m
🚨 OWASP Ottawa May 2026 Meetup - with Jainil Malaviya and Kira Evans
Kira will speak about the power of volunteering, building connections, and taking action with the Ada Sisterhood.
Jainil Malaviya how a malware analyst would approach the self-replicating worm called Shai-Hulud
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
📅 Date: May 20, 2026
⏰ Time: 6:00 PM EST - Arrival, networking, & pizza! 🍕
6:30 PM EST - Technical Talks
#OWASP #Ottawa #Cybersecurity #Malware #InfoSec #AppSec #Tech
🎤 Call for Speakers: OWASP Ottawa Monthly Meetups 🎤
OWASP Ottawa is actively looking for speakers to present at our monthly meetups, and we warmly encourage first-time and beginner speakers to apply. Our chapter typically meets on the third Wednesday of each month.
If you’re passionate about cybersecurity and enjoy sharing knowledge, we’d love to hear from you.
📌 What speakers should know:
• OWASP Ottawa is a vendor-neutral, open-source community focused on improving software security.
• We are also open to speakers who wish to present cybersecurity-focused talks that are not related to software security.
• However, all talks must be strictly non-commercial.
• Presentations should focus on education, research, open-source tools, or community benefit.
• Talks must not be used to promote products, services, or sales activities.
Company or tool references are allowed only when needed for technical context, not endorsement.
🕰️ Talk formats:
15, 30, or 50 minutes - your choice.
If you’ve been thinking about speaking but weren’t sure where to start, OWASP Ottawa is a supportive and inclusive place to share your ideas.
Apply using the Google Form linked in this post. We’re excited to hear your ideas and help amplify voices across the cybersecurity community!
Google Form: https://docs.google.com/forms/d/e/1FAIpQLSe4W7iFl8bNQKZmBFQINGbMufktebe-hJ-4z-QjelzRGrWdwQ/viewform?pli=1
#OWASP #Ottawa #Cybersecurity #CallForSpeakers #InfoSec #AppSec #Community #PublicSpeaking
OWASP Ottawa February 2026 Meetup - Featuring Fennix! 🚨
#OWASP #Ottawa is excited to announce our February 2026 meetup featuring Fennix (a.k.a Chris Shepherd) present their talk “E-Waste? In This Economy?: Building a testing lab at home on the cheap”.
Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
⏰ Time:
Wednesday February 18th
6:00 PM EST - Arrival & networking
6:30 PM EST - Technical Talk
https://github.com/OWASP-Ottawa/chapter-guide/blob/main/Nextevent/tab_nextevent.md
🎊 Sponsor Appreciation Post - @zaproxy@infosec.exchange 🎊
OWASP Ottawa is a community-driven, volunteer-run organization that aims to bring the cyber community in Ottawa together. These events are often made possible by the generosity of our sponsors, who sponsor the venue, food, beverages, and SWAG.
@zaproxy@infosec.exchange sponsored the pizzas for our April 2026 meetup! This generosity was greatly appreciated by OWASP Ottawa and the attendees.
OWASP Ottawa would like to extend its gratitude to Rodrigo Rocha for an insightful presentation on their topic, "Threat Modeling in Practice" at our April 2026 meetup!
Rodrigo laid out the basics of Threat Modeling to a packed room and explained the importance of performing threat modeling for development teams. Not only that, he walked us through a practical example of the threat modeling process for a mock healthcare web application.
Thank you once again, Rodrigo! 👏
If you missed this session, you can catch the recording of this session on our YouTube channel, along with recordings of other sessions from our awesome speakers!
🎥 : https://www.youtube.com/watch?v=TXpb7ooZZRg
#Cybersecurity #OWASP #Ottawa #ThreatModeling #Community #appsec
OWASP is leaving Meetup.
Starting in February #OWASP #Ottawa will no longer be planning our events using Meetup.
To learn of our events you can:
- Keep following us here and turn on notifications.
- Follow us on BlueSky at https://bsky.app/profile/owaspottawa.bsky.social
- and our owasp.org/ottawa page.
🚨OWASP Ottawa November Meetup – Featuring René Walendy!🚨
We’re thrilled to welcome René Walendy to our next in-person meetup at the University of Ottawa on November 12, 2025.
📅 Date: November 12, 2025
⏰ Time: 6:00 PM EST – Arrival, networking & pizza 🍕
6:30 PM EST – Technical Talks
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 564
🎙️ Talk: “Your Trusted Hardware Isn't - Why Silicon belongs in the Threat Model”
Modern security stacks assume that hardware is honest: CPUs execute the correct instructions, random number generators are truly random, and "secure enclaves" are actually secure. But none of these assumptions are guaranteed.
This talk explores hardware Trojans: malicious modifications buried in silicon that can leak secrets, weaken cryptography, or silently bypass your best defenses. We’ll follow a concrete example -- sabotaging a CPU's true random number generator -- and see how a few altered transistors can undermine TLS, disk encryption, and authentication without leaving software-visible evidence.
📺 Can’t make it in person? Watch live on the YouTube channel at @OWASP_Ottawa@www.youtube.com
🔗 RSVP here: https://www.meetup.com/owasp-ottawa/events/311779321/
Don’t miss this chance to hear from a PhD researcher (and hardware hacker), and grab some pizza 🍕.
#OWASP #Ottawa #Cybersecurity #HardwareHacking #InfoSec #ThreatModeling
📢 OWASP Ottawa September Meetup – Logging, Monitoring & MCP Security 📢
Join us in person at the University of Ottawa on September 17, 2025, for our next technical deep dive into one of the most overlooked yet critical aspects of cybersecurity: observability.
📅 Date: September 17, 2025
⏰ Time: 6:00 PM EST – Arrival, networking & pizza 🍕
6:30 PM EST – Technical Talks
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
🎙️ Talk: “Finally! Sufficient Logging and Monitoring (MCP Edition)”
👨💻 Speaker: Robert Babaev
Observability is often neglected, yet it’s a cornerstone of effective security. Robert will explore:
🔹 Centralized logging, metrics, and tracing
🔹 Building a lightweight SIEM
🔹 Practical tips & tricks for developers
🔹 Why strong monitoring matters in the age of AI & MCP
📺 Can’t join in person? You can catch the livestream on our YouTube channel at @OWASP_Ottawa@www.youtube.com
🔗 RSVP here: https://www.meetup.com/owasp-ottawa/events/310972006/
Come for the learning, stay for the community (and pizza!). 🍕
#OWASP #Ottawa #Cybersecurity #AppSec #Logging #Monitoring #Observability #MCP #InfoSec #Networking
Reminder this Wednesday.
🚨 OWASP Ottawa January Meetup – Featuring Vincent Dragnea! 🚨
#OWASP #Ottawa is excited to announce that we are hosting our first monthly meetup of the year! We’re thrilled to welcome Vincent Dragnea to our in-person meetup at the University of Ottawa on January 21, 2026.
RSVP at:
meetup.com/owasp-ottawa/events/312793912
📅 Date: January 21, 2026
⏰ Time: 6:00 PM EST – Arrival, networking & pizza 🍕
6:30 PM EST – Technical Talks
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
🎙️ Talk: "SameSite...or not? Bypassing SameSite cookie protections in browsers"
SameSite cookies are often relied upon too heavily to prevent cross-site request forgery, yet, due to browser implementations, these cookies can be included in unexpected requests. This talk demonstrates novel techniques to attach SameSite=Strict cookies to GET requests originating from another site, including a Google Chrome vulnerability (CVE-2025-8581) discovered while researching these methods. This material aims to help researchers identify insecure behaviors, as well as teach developers how to avoid them.
📺 Can’t make it in person? Watch live on the YouTube channel at youtube.com/@OWASP_Ottawa
🚨 OWASP Ottawa January Meetup – Featuring Vincent Dragnea! 🚨
#OWASP #Ottawa is excited to announce that we are hosting our first monthly meetup of the year! We’re thrilled to welcome Vincent Dragnea to our in-person meetup at the University of Ottawa on January 21, 2026.
RSVP at:
https://www.meetup.com/owasp-ottawa/events/312793912/
📅 Date: January 21, 2026
⏰ Time: 6:00 PM EST – Arrival, networking & pizza 🍕
6:30 PM EST – Technical Talks
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
🎙️ Talk: "SameSite...or not? Bypassing SameSite cookie protections in browsers"
SameSite cookies are often relied upon too heavily to prevent cross-site request forgery, yet, due to browser implementations, these cookies can be included in unexpected requests. This talk demonstrates novel techniques to attach SameSite=Strict cookies to GET requests originating from another site, including a Google Chrome vulnerability (CVE-2025-8581) discovered while researching these methods. This material aims to help researchers identify insecure behaviors, as well as teach developers how to avoid them.
📺 Can’t make it in person? Watch live on the YouTube channel at @OWASP_Ottawa@www.youtube.com
On Saturday, October 18th, 2025, OWASP Ottawa conducted the "Pentest 101" workshop.
The workshop was delivered by Chris Shepherd, an important member of our volunteer team, and led 38 attendees through the lifecycle of a web application penetration test. Chris covered reconnaissance (gathering information about our target web application), testing security controls using browser and dev tools only (testing for SQL Injection), and then using ZAP proxy to intercept and replay requests to perform attacks such as XSS and SSRF. Chris also walked attendees through how to prepare a professional write-up for these findings so that technical and non-technical people can understand the details and impact of these findings.
OWASP Ottawa would like to officially thank our workshop sponsors for supporting this event (in no-particular order):
1. @uottawa@mastodon.social Faculty of Engineering and the uOttawa-IBM Cyber range for providing the required infrastructure to host the event.
2. @owasp@infosec.exchange for providing the OWASP Juice Shop application used as the targeted web application and SWAG
3. Packetlabs for providing pizza and SWAG
4. DeviousPlan for providing beverages
Lastly, OWASP Ottawa would like to thank all the attendees for attending this workshop and the volunteers who dedicated their time to make this workshop a success.
If you would like for OWASP Ottawa to organize more such workshops, please leave a comment below indicating what workshops you would like us to organize.
Last night, OWASP Ottawa had the pleasure of hosting Robert Babaev for his insightful talk, titled "(Finally) Sufficient Logging and Monitoring - MCP Edition".
Attendees learned about the importance of sufficient logging and monitoring in web applications, and the problems insufficient monitoring and logging can lead to.
Thank you, Robert Babaev for this amazing talk, and we look forward to more talks from you in the future.
Missed this talk? Check out the recorded version of this talk on our YouTube channel, along with plenty of our past talks!
📢 OWASP Ottawa August 2025 Meetup 📢
OWASP Ottawa is back from our summer break! Join us in person at the University of Ottawa for our next OWASP Ottawa meetup on August 20, 2025, where we’ll dive into not one, but two timely and impactful talks at the intersection of cybersecurity, AI, and real-world application security.
📅 Date: August 20, 2025
⏰ Time: 6:00 PM EST – Arrival, setup & pizza 🍕
6:30 PM EST – Technical Talks
📍 Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
🎙️ Talk 1: "Doing More with Less: An Adaptive, Label-Efficient Approach to Fraud Detection from Day One" with Bahar Afshar
👥 Speaker: Bahar Afshar, Master’s in Computer Science candidate with specialization in AI at University of Ottawa
Discover an innovative approach on how to detect financial fraud using adaptive, label-efficient AI approaches, even when labeled, fraudulent data is scarce. A must-see for those in finance, security, and AI research.
🎙️ Talk 2: "Beyond APIs: MCP Security for AI Integrations" with Harsh Makwana
👥 Speaker: Harsh Makwana, M.Eng, Aplication Security Consultant at Software Secured
Model Context Protocol (MCP) is becoming the standard for LLM integration with external tools, but this increasingly fast adoption rate is coming at the cost of missed security challenges. Learn the security strategies necessary to build hardened AI agents.
📺 Can’t join in person? We’ll livestream on YouTube on our channel: @OWASP_Ottawa@www.youtube.com
🔗 RSVP now: https://www.meetup.com/owasp-ottawa/events/310273515/
Come learn, network, and grab some pizza 🍕 with Ottawa’s cybersecurity community!
.
.
.
.
.
.
.
.
#OWASP #Ottawa #Cybersecurity #InfoSec #Networking #AI #AISecurity #FraudDetection #MachineLearning