Josh Grossman (tghosth ๐Ÿ‘ป)'s Avatar

Josh Grossman (tghosth ๐Ÿ‘ป)

@joshcgrossman.com

Friendly AppSec Ghost ๐Ÿ‘ป https://appsecg.host

1,273
Followers
431
Following
153
Posts
01.07.2023
Joined
Posts Following

Latest posts by Josh Grossman (tghosth ๐Ÿ‘ป) @joshcgrossman.com

Preview
Running two Claude Code accounts on one Windows PC (without them fighting) How I isolated Personal and Work Claude Code accounts on a single Windows machine by faking per-account home directories and a handful of symlinks.

I'm sure this blogpost will be interesting to the two or three other people people in the world who are using Claude Code on Windows and want to have multiple accounts active :)

Keen to hear feedback and experiences ๐Ÿ˜€

16.02.2026 10:15 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Running two Claude Code accounts on one Windows PC (without them fighting) How I isolated Personal and Work Claude Code accounts on a single Windows machine by faking per-account home directories and a handful of symlinks.

I'm sure this blogpost will be interesting to the two or three other people people in the world who are using Claude Code on Windows and want to have multiple accounts active :)

Keen to hear feedback and experiences ๐Ÿ˜€

09.02.2026 10:57 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image Post image

Starting off the year with the uno reverse card ๐Ÿคฃ๐Ÿคฃ๐Ÿคฃ

05.01.2026 16:24 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Registration โ‡ฝ London OWASP Training Days 2026 | The OWASP Foundation Inc. Register for "London OWASP Training Days 2026" hosted by OWASP Foundation Inc.

Register:
owasp.glueup.com/eve...

More details:
owasp.glueup.com/eve...
www.bouncesecurity.c...

01.12.2025 15:23 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Video thumbnail

LONDON, BABY!

I'm bringing my course "Building a High-Value AppSec Scanning Programme" to London as part of @OWASP's London training days, 23-24 February 2026.

As seen at OWASP Global conferences, @BlackHatEvents and @NDC_Conferences, don't miss your chance to attend!

01.12.2025 15:23 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

#justaithings

11.11.2025 09:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
So, you want to train at Black Hat (or other conferences)? An Introduction | Bounce Security Efficient, Value-Driven Product Security

CFTs for both @BlackHatEvents #BHUSA and @OWASP Global AppSec EU (Vienna) are now open and close in early December!

Thinking of submitting? Check out my blog series for @BounceSecurity "So you want to train at Black Hat (or other conferences)?"

04.11.2025 07:06 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

If you attended my vibe coding session at the @OWASP Community at @defcon (or you didn't but you are interested) and you want to continue the conversation, Emile Delcourt opened a dedicated channel on the @OWASP slack workspace:
owasp.slack.com/arch...

02.09.2025 18:20 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I can't bring myself to tag everyone but thanks to everyone I met and chatted to, every one of you enhanced the experience.

For those of you working as volunteers and organisers, you are the ones who make all of this happen and you have my undying respect and appreciation!

11.08.2025 02:07 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

4) Getting to switch things down a gear at the annual one-of-a-kind ShabbatCon with great conversations and the famous "no-fire" talks.

5) Crazy golf at the Chainguard/Orca party with Avi and Kim, I do love crazy golf!

11.08.2025 02:07 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

3a) Volunteering for the OWASP Community space at DEFCON to talk to people about the foundation and collect donations in exchange for t-shirts.

3b) Delivering a "What is OWASP" talk for the community space as well as leading a packed discussion about AppSec and vibe coding.

11.08.2025 02:07 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

1) Delivering another round of my training course about accelerating your AppSec programme.

2) Meeting loads of people at Black Hat, some intentionally and some by happy coincidence and building connections.

11.08.2025 02:07 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

About to head home after a packed week+ in Vegas for Hacker Summer Camp.

Some highlights for me:

11.08.2025 02:07 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

My point is not the content but rather the skillset.If I as a security person don't have those skills then people are going to listen to someone who does

06.08.2025 16:35 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Post image

My searing hot take for today is that everyone hitting out at "security influencer" culture might want to consider that being able to persuade and influence is probably the most important tool in your security skillset.

06.08.2025 15:34 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image Post image Post image

Excited to be back delivering my course again at Black Hat USA!

05.08.2025 00:28 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Making your preparations | Bounce Security Introduction

In "Making your preparations" I discuss some of the preparations you might need in the run-up to the course including materials and visa considerations.

Although visas are one of the last things I mention, it might be one of the first things to consider.
www.bouncesecurity.c...

17.07.2025 11:30 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Selling and Marketing your course | Bounce Security Introduction

In "Selling and Marketing your course", I talk about possibly the hardest part of the whole process, getting people to sign-up! I don't have all the answers but hopefully I have some ideas and thoughts that will be useful to you.
www.bouncesecurity.c...

17.07.2025 11:30 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

The final two parts of my blog series about delivering training at conferences have now been released!

You can check them out on the @BounceSecurity website now!

17.07.2025 11:30 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Most passkey implementations are tripping over themselves to fall back to sending you an email OTP as fast as possible...

Passkeys are for UX, not for security

02.07.2025 05:36 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
OWASP Cornucopia - Threat modeling for everyone everywhere - Don't gamble with your security play games with it OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, ...

cornucopia.owasp.org

@sydseter.com is probably one of the local experts :)

24.06.2025 18:39 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Black Hat Black Hat

Sign-up here:
www.blackhat.com/us-25/traini...

More information about the course:
www.bouncesecurity.com/training/acc...

24.06.2025 09:32 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Pulled last year's class workbook out so that I can prepare the updated version for this year.

You still have time to sign up for my updated course at @blackhatofficial.bsky.social #BHUSA, in person in Las Vegas, August 4-5.

24.06.2025 09:32 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
So, you want to train at Black Hat (or other conferences)? An Introduction | Bounce Security Efficient, Value-Driven Product Security

You can find the whole series here:
www.bouncesecurity.c...

12.06.2025 11:32 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

So you have a great training course with super-cool interactivity, now you have to get it accepted.

In my next blogpost, I talk about writing a proposal which appeals to both the review board and also your potential attendees.

Check it out here:
www.bouncesecurity.c...

12.06.2025 11:32 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image Post image Post image

Last week, I was honoured to received a Distinguished Lifetime Member award from OWASP at Global AppSec EU Barcelona 2025.

I wrote more about it here:
www.linkedin.com/pos...

11.06.2025 18:24 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image

So @ElarLang just published version 5.0.0 of OWASP ASVS, live on stage at @OWASP Global AppSec EU Barcelona 2025!

30.05.2025 10:06 ๐Ÿ‘ 12 ๐Ÿ” 9 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 2
Post image

In October, 2021, we released 4.0.3 of the OWASP ASVS Standard. This release marked the start of the Vanilla Ice (or 5.0 as everyone else called it) release.

A major rethink about how we use the standard and with feedback from the community.

30.05.2025 09:38 ๐Ÿ‘ 7 ๐Ÿ” 2 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Video thumbnail

Last week to save before prices go up on 23rd May!

Unless you Accelerate your AppSec Programme, you are going to get left behind..

Join me @blackhatofficial.bsky.social #BHUSA this summer in Las Vegas (4-5 Aug) for a practical guide on how to build bridges with developers and build securely!

19.05.2025 12:00 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Welcome @blackhatofficial.bsky.social ๐Ÿ™‚

You should probably report this account for impersonation though...

bsky.app/profile/blac...

13.05.2025 19:13 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0