Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478)
The Thymeleaf vulnerability with a CVSS score of 9.1 grabs your attention, as it should. But before you call the cavalry and claim this as …

Java Champions & Developer Advocate and Software Engineer for Snyk. Passionate about Java, (Pure) Functional Programming, and Cybersecurity. Co-leading the Virtual JUG, NLJUG and DevSecCon community. Brian is also an Oracle Groundbreaker Ambassador and regular international speaker on mostly Java-related conferences.
1 views

Brian Vermeer
1,046 viewsThe Thymeleaf vulnerability with a CVSS score of 9.1 grabs your attention, as it should. But before you call the cavalry and claim this as …

Brian Vermeer
3,116 viewsDid you know that by tampering with chat history, you're able to make LLMs respond and execute functions that are out of policy?

Brian Vermeer
3,436 viewsWe know that LLMs can and will make mistakes, and while enriching your prompts with the proper context can help align results with your …

On May 13th and 14th, Foojay attended the JCON conference in Köln, Germany, where we did over 30 live-stream interviews. In this episode, we …

Brian Vermeer
3,993 viewsThe implementation of RAG introduces security considerations. Risks such as prompt injection, data poisoning, access control gaps, and data …

Brian Vermeer
4,952 viewsThis vulnerability highlights the importance of addressing supply chain security. If you aren't already, consider scanning your applications …

Brian Vermeer
3,490 viewsThe software bill of materials (SBOM) is quickly becoming an essential aspect of open source security and compliance. In this post, we'll …

Three years after Log4Shell caused a significant security issue, we still struggle with insecure dependencies and injection problems...
Brian Vermeer
6,856 viewsA lurking issue has been surprisingly overlooked: the continued use of vulnerable Log4j and Spring Framework versions in many projects.

Brian Vermeer
6,309 viewsNowadays, the security of your applications is just as important as the functionality they provide. Therefore, analyzing your code for …