Any decent AI security related book the anyone recommends?
Jack Black Amazed by Glowing Book
ALT: Jack Black Amazed by Glowing Book
static.klipy.com
SeanWrightSec
@seanwrightsec.com
Principal Application Security Engineer focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.
Any decent AI security related book the anyone recommends?
Jack Black Amazed by Glowing Book
ALT: Jack Black Amazed by Glowing Book
static.klipy.com
Been itching to share this the past few days, and now I can! Incredible effort by the team and all involved. The public announcement has all the details (and more), including the link to the open source project! corporate.visa.com/en/sites/vis...
Visa participates in Anthropic’s Project Glasswing
Visa participation reflects a proactive approach to testing advanced AI for cybersecurity and strengthening the global payments ecosystem
corporate.visa.com
Looks like the final OWASP Top 10 (2025) has been published: owasp.org/Top10/2025/. Based on commits, looks like this happened 5 days ago.
OWASP Top 10:2025
OWASP Top 10:2025
owasp.org
Surprised it’s taken this long! Microsoft has finally killed off the RC4 cipher. www.msn.com/en-gb/money/...
MSN
msn.com
So the release candidate has been will be released today (6 November 2025): owasp.org/www-project-... Comments until 20 November 2025.
OWASP Top Ten | OWASP Foundation
The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software devel...
owasp.org
Friendly reminder… the 2025 OWASP Top 10 should be dropping at the end of this week!
SANS Holiday Hack Challenge 2025 is now available! www.sans.org/cyber-ranges...
Holiday Hack Cybersecurity Challenge 2025 | SANS Institute
Join the global cybersecurity community in the most festive and challenging event of the year! The SANS Holiday Hack Challenge cyber range offers FREE, high-quality, and super fun hands-on cybersecuri...
sans.org
Friendly reminder… the 2025 OWASP Top 10 should be dropping at the end of this week!
This is a really tough time of the year for me. I lost my own father 7 years ago. And while it does become easier to cope over time, it’s still difficult. What makes it harder this time is seeing people celebrating the death of someone else’s father all because they don’t agree with their viewpoints
This is starting to look like this may have significant implications. 18 popular packages affected so far. www.bleepingcomputer.com/news/securit...
Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack
In a supply chain attack, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after compromising a maintainer's account in a phishing attack.
bleepingcomputer.com
Great article by @jpmjr.bsky.social on @reversinglabs.com blog. Thank you for including my comments. It’s going to be an interesting time ahead with AI now playing a larger role in development. www.reversinglabs.com/blog/modern-...
The state of software development: 5 action items for AppSec teams | ReversingLabs
Application security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.
reversinglabs.com
Proton have released a new Authenticator app. Looks pretty cool! proton.me/authenticato...
Authenticator app download: Get Proton Authenticator | Proton
Download Proton Authenticator app for Windows, macOS, Linux, Android, and iOS. Protect your accounts with secure two-factor codes. No ads, no tracking.
proton.me
A good example of why understanding what the code of AI is doing. www.bleepingcomputer.com/news/securit...
Amazon AI coding agent hacked to inject data wiping commands
A hacker planted data wiping code in a version of Amazon's generative AI-powered assistant, the Q Developer Extension for Visual Studio Code.
bleepingcomputer.com
I’m completely shocked! Would have never expected this to happen! www.techradar.com/vpn/vpn-priv...
VPN usage soars in Iran – but authorities may be trying to prevent it
Proton VPN confirmed an hourly increase in sign-ups of over 1,400% starting from July 25, 2025
techradar.com
Oh dear! What a shame… never mind 😁 The sweet taste of karma! www.techradar.com/pro/security...
This major cybercrime forum might have just exposed all its users
A leak forum did what leak forums do - but to its own users
techradar.com
Another reminder to revoke access immediately for former employees, especially ones who have been dismissed. www.theregister.com/2025/06/30/b...
Seven months for IT worker who trashed his work network
: Don't leave the door open to disgruntled workers
theregister.com
I’ve given this advice to several folk, and it’s worth sharing with others. Learning how to become comfortable with not knowing something is liberating. It’ll help give you the confidence to then do something about it.
While having something showing the likelihood of a vuln being exploited is good, I do worry this will end up being just another metric. I hope that I’m wrong, and this will prove helpful. www.darkreading.com/vulnerabilit...
NIST's LEV Equation to Rate Chances a Bug Was Exploited
The new equation, introduced by the National Institute of Standards and Technology (NIST), aims to offer a mathematical likelihood index that could be a game-changer for SecOps teams and vulnerability...
darkreading.com
A really important reason why it’s important to have security tooling working and operating as you expect. It’s already difficult to get other teams to buy into these tools so when they are constantly “wrong”, getting those teams onboard is almost impossible.
Important to note that CVE is not a database per se. This is why we have the likes of NVD. So if anything, ENISA would be competing with NVD. But I still have concerns of how this may fragment the ecosystem.
New EU vulnerability database will complement CVE program, not compete with it, says ENISA
See the EU Vulnerability Database is now live. While I get the desire to have this, the problem that I now worry about is that this is going to fragment vulnerabilities. So making an already difficult problem even harder. euvd.enisa.europa.eu
EUVD
European Vulnerability Database
euvd.enisa.europa.eu