2025-10-10 – Weekly Cybersecurity News : WAF blocked my unit tests

Last week, our discussions were buzzing with practical tips and strategic insights. Members delved into the nuances of OSCAL profiles in the context of NIST’s 800-53 Rev. 5, highlighting both challenges and potential solutions. There was also a lively exchange around certification values, sharing various perspectives on which credentials truly matter for career advancement. In addition, strategies for staying updated in the rapidly evolving cybersecurity landscape were thoroughly explored.


This Week’s Hot Topics

OSCAL profiles for 800–53 Rev. 5
Members are dissecting how OSCAL profiles can streamline compliance with NIST’s 800-53 Rev. 5, offering both technical and strategic angles.
Read more here

WAF blocked my unit tests
A fascinating thread on troubleshooting when Web Application Firewalls interfere with unit testing, offering practical advice for developers.
Read more here

Best Online Communities for Cyber Security Pros?
This discussion rounds up the best places online where cybersecurity professionals can connect, learn, and grow.
Read more here

Which Certifications Are Worth It in Cyber Security?
A deep dive into which cybersecurity certifications offer real value and how they align with career goals.
Read more here

How Do You Stay Current in Such a Fast-Moving Field?
Explore community strategies for keeping pace with new developments and maintaining cutting-edge skills.
Read more here

How Do You Organize and Monitor Your Security Stack?
Insights on organizing and monitoring security tools effectively to enhance protection.
Read more here

What Templates or Frameworks Help You With Incident Response?
Share and learn about the best templates and frameworks for incident response in this practical discussion.
Read more here

FAQ/Guidelines
A handy reference for new and existing members on how to make the most of the forum.
Read more here

Admin Guide: Getting Started
A useful guide for administrators to hit the ground running with our forum tools.
Read more here

Thinking About a Career in Cyber Security? Here’s What You Need to Know!
An informative thread for those considering a career in cybersecurity, covering essential starting points.
Read more here


We wrapped up another week with valuable exchanges and practical knowledge sharing. Keep contributing your thoughts and questions—your input is what makes our community thrive.

Same here with WAF killing unit tests; we allowlisted our CI runners’ egress IPs and flipped WAF to detection-only on the staging domain during test jobs. On the OSCAL/NIST 800–53 Rev. 5 side, we auto-generate profile diffs in PRs so reviewers catch control drift; caveat: time-box the allowlist and auto-revoke. If you’re on Cloudflare, this helped: https://developers.cloudflare.com/waf/managed-rules/managed-rulesets/testing/.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‍​⁠‍‌​⁠‍‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​​​⁠​‌​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠‍‌‍‍​‌‍‌‌​⁠‍‌‌‍​‌​⁠‍‌‌‍‌‍‌​​⁠‌​‌‍​⁠‌⁠‌​‌‍‌‌‍‌‌‍‌‌‌‍⁠‍‌‍‍⁠‌​‍‍​‍​‍‌⁠⁠‌​

We tag CI traffic with an ‘X-Unit-Test’ header and bypass only specific rule IDs, plus IP restrictions; safer, @Ravi.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‍​⁠‍‌​⁠‍‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​​​⁠​‌​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‍‌​⁠‌‌‌‍‍‍‌‍‍​‌‍⁠‌‌⁠‍‌​⁠‌​‌⁠‍‌‌‌‌⁠‌⁠​​‌‌‌‌​⁠‌‍‌‍⁠​‌‍‍​‌‍​‍‌​⁠‍​‍​‍‌⁠⁠‌​

We ended up using mTLS on a test-only subdomain: CI presents a client cert and the WAF bypasses just those requests on /e2e/*, then the rule auto-expires via API when the job ends (like a “VIP wristband” for the runner). @jpierce402 we also log the time-bound exception in OSCAL as a compensating control for SC-7/AC-3 so it doesn’t become a permanent hole; if mTLS isn’t an option, a short-lived OIDC-signed header is a decent fallback — anyone tried that?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‍​⁠‍‌​⁠‍‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​​​⁠​‌​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠⁠‌‌‍‌‌​‍⁠‌‍‍‌​⁠‍‌​⁠‍‌‌​​‌‌​​‌‌⁠‌‌‌​‌‌​⁠‌‍‌​‍‌​‍⁠‌‌‌⁠⁠‌‍​‌​⁠‌​​‍​‍‌⁠⁠‌​