๐งโ๐ Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the lab) and Claude (for more detailed explanation). #appsec #appsecurity
Dominique Righetto
@righettod.eu
๐จโ๐ป AppSec enthusiast | ๐ถ Addicted to Shetland Sheepdogs | ๐ Open Source/AppSec/OWASP junkie | ๐ OWASP Secure Headers Project Leader. ๐ฉ Opinions mentioned are mine.
๐๏ธ๐ป Les logiciels libres de l'รฉtรฉ, jour 35 Typer : une bibliothรจque Open Source pour crรฉer des applications en CLI que les utilisateurs adoreront utiliser et que les dรฉveloppeurs prendront plaisir ร concevoir. Elle repose sur les hints de type de Python.
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised. blog.pypi.org/posts/2026-0... #python #security #supplychain #pypi
Releases now reject new files after 14 days - The Python Package Index Blog
PyPI no longer allows publishing new files to releases older than 14 days.
blog.pypi.org
blog.elcomsoft.com/2026/07/an-a... an interesting point of view on the OpenAI/Hugging Face incident
An AI agent broke into Hugging Face. Five days later, OpenAI said it was theirs
On 16 July 2026, Hugging Face disclosed that an autonomous AI agent had been inside part of its production infrastructure. The company was clear about what it d
blog.elcomsoft.com
๐ก OWASP Secure Headers Project - update: 1) We added info about the header "Integrity-Policy". 2) We defined the rules about GenIA usage. 3) We also developed a AI agent to help us (beta). ๐ github.com/OWASP/www-pr... ๐ค github.com/righettod/os... #appsec #appsecurity #owasp_shp
Voxxed Days Luxembourg 2026 talks are now online for you to enjoy ๐ ! luxembourg.voxxeddays.com/en/#videos ---- Les prรฉsentations de Voxxed Days Luxembourg 2026 sont maintenant en ligne et prรชtes ร dรฉguster! ๐ luxembourg.voxxeddays.com/en/#videos
๐ก OWASP Secure Headers Project: We have completed the migration on our end, even though the foundation has postponed the release of the CMS. #appsec #appsecurity #owasp_shp ๐ github.com/OWASP/www-pr...
GitHub - OWASP/www-project-secure-headers: The OWASP Secure Headers Project
The OWASP Secure Headers Project. Contribute to OWASP/www-project-secure-headers development by creating an account on GitHub.
github.com
๐ก OWASP Secure Headers Project: We have been informed that the foundation will launch its new website on June 24; therefore, we have begun the migration process today. We apologize for any broken links that may occur over the next few days or weeks. #appsec #appsecurity #owasp_shp
Assessments of threats can be seen from different perspectives. Developers may come across privacy impact assessments (PIAs), where threats to users' data and the impact on those users are paramount. PIAs may additionally examine harms to organisations, third parties and wider society. (1/6) #games
Next week, at VOXXED Days Luxembourg @lu.voxxeddays.com , I will present a version of the "Die & Retry" concept applied to the file upload feature, specifically for cases where PDF files are accepted ๐ m.devoxx.com/events/voxxe... #appsec #voxxed_lu
๐ก OWASP Secure Headers Project - We have made the following updates: 1) Section "Code Snippets": The user prompt has been updated to allow direct generation of a web/application server configuration using the online JSON reference file. #appsec #appsecurity #owasp_shp
I needed code snippets for presentations. I was worried about pasting code snippets into untrusted sites. So I just wrote my own using AI. You can trust I won't be tracking your code. It's very customisable and the default is for presentations. hackvertor.co.uk/snippet
๐งโ๐ As part of my homework on AI from an application security perspective, I decided to investigate how AI, through a coding assistant (Claude Code in my case), can be used in the following areas: #appsec #appsecurity #ai
New badge: JavaScript Sandbox Escape! The first 4 labs are live. If you ship anything that evaluates untrusted or model-generated JavaScript, this badge is for you: pentesterlab.com/badges/javas...
PentesterLab: Learn with our JavaScript Sandbox Escaping
This badge covers JavaScript sandbox escape vulnerabilities. From prototype chain navigation and Function constructor abuse to vm module escapes, static-eval bypasses, real-world CVEs, and advanced pr...
pentesterlab.com
We've launched a new free Web Security Academy topic on exploiting AI-powered security scanners! Learn how to use indirect prompt injection to steal data, cause damage & trigger exploit chains! Dive in here: portswigger.net/web-security...
AI-powered scanner vulnerabilities | Web Security Academy
Application security teams often deploy AI-powered scanners that use Large Language Models (LLMs) to scan web applications for vulnerabilities. While ...
portswigger.net
With the new version of git, Welcome to the new "git history" command! ๐ Rewording and split commits will be finally easier than before. ๐ช github.blog/open-source/...
๐ก OWASP Secure Headers Project: We have refactored the section on the browserโs "Local Network Access" feature. #appsec #appsecurity #owasp_shp ๐ owasp.org/www-project-...
In collaboration with a couple of other leaders in the industry we are releasing securitytitles.com - It's an attempt to provide transparency about role levels, expectations and (just for the US market currently, salary ranges). For leaders writing JDs and candidates alike.
Home | Security Titles
securitytitles.com
๐ After a few years of refinement and close to 1 >> 9 commits, I'm pleased to announce the v1 release of my CORS middleware library for Go. Let me know whether it patches things up between you and CORS! github.com/jub0bs/cors #golang #CORS
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
github.com
Everyone is panicking about AI-generated zero days like it's an attacker story. It's not. Defenders can use the best models against their own code right now. Your progress compounds. Attackers' job gets harder. pentesterlab.com/blog/defende...
Defenders Finally Have the Edge - PentesterLab's Blog
AI agents are changing vulnerability research, but the real advantage goes to defenders. Attackers face air-gap constraints while defenders get full access to frontier models on their own code. Every ...
pentesterlab.com
The Cornucopia of Gamified Threat Modeling At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website App Edition v3.0! dev.to/owasp/the-co... #appsec #cybersecurity #gamedev #security
The Cornucopia of Gamified Threat Modeling
At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website...
dev.to
heads up: FreeBSD forums hacked. Be caeeful with your email or DMs coming from FreeBSD forum or freebsd{.}org for some time now. https:// forums {.} freebsd {.} org/
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ญ๐ฏ, ๐ฎ๐ฌ๐ฎ๐ฒ Only one entry but definitely worth reading! โ๏ธ ๐ฅ๐ฒ๐บ๐ผ๐๐ฒ ๐๐ผ๐บ๐บ๐ฎ๐ป๐ฑ ๐๐ ๐ฒ๐ฐ๐๐๐ถ๐ผ๐ป ๐ถ๐ป ๐๐ผ๐ผ๐ด๐น๐ฒ ๐๐น๐ผ๐๐ฑ ๐๐ถ๐๐ต ๐ฆ๐ถ๐ป๐ด๐น๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ฒ๐น๐ฒ๐๐ถ๐ผ๐ป This one is a real tour de force: flatt.tech/research/pos....
Remote Command Execution in Google Cloud with Single Directory Deletion
Introduction Hello, Iโm RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During...
flatt.tech
Dear contributors to Voxxed Days Luxembourg's renewed success: the call for your papers, supposedly closed tonight wil be extended by 2 weeks to accomodate latecomers. A small reminder: 15 min. lunch talks are often under-filled, to test your speaker abilities, this is a perfect opportunity!
๐งโ๐ Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation). #appsec #appsecurity
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ญ๐ฎ, ๐ฎ๐ฌ๐ฎ๐ฒ AI doing research, AI killing CTF ๐ค ๐ง๐ฒ๐๐๐ถ๐ป๐ด ๐๐ ๐ณ๐ผ๐ฟ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต: ๐ฐ ๐๐ฝ๐ฝ๐ฟ๐ผ๐ฎ๐ฐ๐ต๐ฒ๐ & ๐ช๐ต๐ฒ๐ฟ๐ฒ ๐ ๐๐ฎ๐ถ๐น๐ฒ๐ฑ If you can only read one thing this week, make it this article: xclow3n.github.io/post/7.
Testing AI for Vulnerability Research: 4 Approaches & Where I Failed | xclow3n
Tested 4 AI-assisted approaches for finding vulnerabilities over one week. Found real bugs โ 14 confirmed vulns in one target in 20 minutes. Also burned time on an approach that found nothing useful. ...
xclow3n.github.io
Le CFP des 10 ans de VoxxedDays Luxembourg est toujours ouvert, ne trainez plus :) โ voxxedlu2026.cfp.dev#/
๐งโ๐ Learning of the day for me thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation): #appsec #appsecurity
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ญ๐ฌ, ๐ฎ๐ฌ๐ฎ๐ฒ A great mix of content this week! ๐ ๐๐ฟ๐ผ๐ป๐๐๐ฟ๐๐ฎ๐ถ๐ป: ๐ ๐ฃ๐ฒ๐ฟ๐๐ผ๐ป๐ฎ๐น ๐๐ ๐๐๐๐ถ๐๐๐ฎ๐ป๐ ๐๐๐ถ๐น๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ณ๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ฟ๐ผ๐๐ป๐ฑ ๐จ๐ฝ Niels Provos (from OpenBSD's systrace) is sharing a new tool to sandbox your AI assistant: www.provos.org/p/ironcurtai....