Sign in

Dominique Righetto

@righettod.eu
1.3K followers 139 following 197 posts

👨‍💻 AppSec enthusiast | 🐶 Addicted to Shetland Sheepdogs | 🌏 Open Source/AppSec/OWASP junkie | 🐝 OWASP Secure Headers Project Leader. 🚩 Opinions mentioned are mine.

PostsRepliesMedia
Reposted by Dominique Righetto
Jeroen @commjoenie.bsky.social · 22/09/2026
We released a new version of #OWASP #Wrongsecrets ! With devcontainer and AI related challenges. Try it out at www.wrongsecrets.com and give the repo a ⭐️ if you like it!
wrongsecrets.com
OWASP WrongSecrets
066
Dominique Righetto @righettod.eu · 13/09/2026
📡 OWASP Secure Headers Project: The web user interface is back, we worked all weekend, after the OWAP Foundation's new website went live, to get it back online 😉 #appsec #appsecurity #owasp_shp
UI rendering overview
100
Dominique Righetto @righettod.eu · 06/09/2026
🧑‍🎓 As part of my homework on AI from an application security perspective: Since several month now I work on a collection of Claude code skills (such skills are compatible with other coding assistants) to generate code that include, by default, a set of security validations. #appsec #appsecurity #ai
140
Dominique Righetto @righettod.eu · 30/08/2026
📡 OWASP Secure Headers Project: - We have added information about the HTTP response headers supporting the "Report-Only" mode. - We have incorporated them into the statistical data, and a contributor has fixed a bug in the script that generates the statistics. #appsec #appsecurity #owasp_shp
120
Reposted by Dominique Righetto
Gareth Heyes @garethheyes.co.uk · 07/08/2026
If you want to see how to compromise an account from a paste and steal passwords in CSS and much more check out my paper "CSS: the bomb inside your inbox" 👇 portswigger.net/research/css...
portswigger.net
CSS:the bomb inside your inbox
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
163
Dominique Righetto @righettod.eu · 01/08/2026
🧑‍🎓 Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the lab) and Claude (for more detailed explanation). #appsec #appsecurity
POC
110
Reposted by Dominique Righetto
Bearstech @bearstech.com · 26/07/2026
🏖️🐻 Les logiciels libres de l'été, jour 35 Typer : une bibliothèque Open Source pour créer des applications en CLI que les utilisateurs adoreront utiliser et que les développeurs prendront plaisir à concevoir. Elle repose sur les hints de type de Python.
Now let's start using Typer in your own code, update main.py with:

import typer


def main(name: str):
    print(f"Hello {name}")


if __name__ == "__main__":
    typer.run(main)
Now you could run it with Python directly:

// Run your application
$ uv run python main.py

// You get a nice error, you are missing 'name'
Usage: main.py [OPTIONS] {name}
Try 'main.py --help' for help.
╭─ Error ───────────────────────────────────────────╮
│ Missing argument 'name'.                          │
╰───────────────────────────────────────────────────╯


// You get a --help for free
$ uv run python main.py --help

Usage: main.py [OPTIONS] {name}

╭─ Arguments ───────────────────────────────────────╮
│ *    name      <str>  [required]                  │
╰───────────────────────────────────────────────────╯
╭─ Options ─────────────────────────────────────────╮
│ --help          Show this message and exit.       │
╰───────────────────────────────────────────────────╯

// Now pass the 'name' argument
$
274
Reposted by Dominique Righetto
Python Package Index @pypi.org · 22/07/2026
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised. blog.pypi.org/posts/2026-0... #python #security #supplychain #pypi
blog.pypi.org
Releases now reject new files after 14 days - The Python Package Index Blog
PyPI no longer allows publishing new files to releases older than 14 days.
04517
Reposted by Dominique Righetto
Goupil @furaxfox.bsky.social · 22/07/2026
blog.elcomsoft.com/2026/07/an-a... an interesting point of view on the OpenAI/Hugging Face incident
blog.elcomsoft.com
An AI agent broke into Hugging Face. Five days later, OpenAI said it was theirs
On 16 July 2026, Hugging Face disclosed that an autonomous AI agent had been inside part of its production infrastructure. The company was clear about what it d
022
Dominique Righetto @righettod.eu · 19/07/2026
📡 OWASP Secure Headers Project - update: 1) We added info about the header "Integrity-Policy". 2) We defined the rules about GenIA usage. 3) We also developed a AI agent to help us (beta). 📖 github.com/OWASP/www-pr... 🤖 github.com/righettod/os... #appsec #appsecurity #owasp_shp
000
Reposted by Dominique Righetto
Voxxed Days Luxembourg @lu.voxxeddays.com · 05/07/2026
Voxxed Days Luxembourg 2026 talks are now online for you to enjoy 😀 ! luxembourg.voxxeddays.com/en/#videos ---- Les présentations de Voxxed Days Luxembourg 2026 sont maintenant en ligne et prêtes à déguster! 😀 luxembourg.voxxeddays.com/en/#videos
0139
Dominique Righetto @righettod.eu · 05/07/2026
📡 OWASP Secure Headers Project: We have completed the migration on our end, even though the foundation has postponed the release of the CMS. #appsec #appsecurity #owasp_shp 📖 github.com/OWASP/www-pr...
github.com
GitHub - OWASP/www-project-secure-headers: The OWASP Secure Headers Project
The OWASP Secure Headers Project. Contribute to OWASP/www-project-secure-headers development by creating an account on GitHub.
100
Dominique Righetto @righettod.eu · 20/06/2026
📡 OWASP Secure Headers Project: We have been informed that the foundation will launch its new website on June 24; therefore, we have begun the migration process today. We apologize for any broken links that may occur over the next few days or weeks. #appsec #appsecurity #owasp_shp
100
Reposted by Dominique Righetto
Uncle Joe @sydseter.com · 17/06/2026
Assessments of threats can be seen from different perspectives. Developers may come across privacy impact assessments (PIAs), where threats to users' data and the impact on those users are paramount. PIAs may additionally examine harms to organisations, third parties and wider society. (1/6) #games
284
Dominique Righetto @righettod.eu · 11/06/2026
Next week, at VOXXED Days Luxembourg @lu.voxxeddays.com , I will present a version of the "Die & Retry" concept applied to the file upload feature, specifically for cases where PDF files are accepted 😉 m.devoxx.com/events/voxxe... #appsec #voxxed_lu
010
Dominique Righetto @righettod.eu · 16/05/2026
📡 OWASP Secure Headers Project - We have made the following updates: 1) Section "Code Snippets": The user prompt has been updated to allow direct generation of a web/application server configuration using the online JSON reference file. #appsec #appsecurity #owasp_shp
110
Reposted by Dominique Righetto
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 05/05/2026
bleepingcomputer.com
The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check.
Critical vulnerabilities can exist in open source software your scanners don't check. HeroDevs reveals how EOL software creates blind spots in CVE feeds and SCA tools, and how you can receive a free end-of-life scan for your projects. [...]
011
Reposted by Dominique Righetto
Gareth Heyes @garethheyes.co.uk · 28/04/2026
I needed code snippets for presentations. I was worried about pasting code snippets into untrusted sites. So I just wrote my own using AI. You can trust I won't be tracking your code. It's very customisable and the default is for presentations. hackvertor.co.uk/snippet
172
Dominique Righetto @righettod.eu · 28/04/2026
🧑‍🎓 As part of my homework on AI from an application security perspective, I decided to investigate how AI, through a coding assistant (Claude Code in my case), can be used in the following areas: #appsec #appsecurity #ai
210
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 28/04/2026
New badge: JavaScript Sandbox Escape! The first 4 labs are live. If you ship anything that evaluates untrusted or model-generated JavaScript, this badge is for you: pentesterlab.com/badges/javas...
pentesterlab.com
PentesterLab: Learn with our JavaScript Sandbox Escaping
This badge covers JavaScript sandbox escape vulnerabilities. From prototype chain navigation and Function constructor abuse to vm module escapes, static-eval bypasses, real-world CVEs, and advanced pr...
044
Reposted by Dominique Righetto
James Kettle @jameskettle.com · 27/04/2026
We've launched a new free Web Security Academy topic on exploiting AI-powered security scanners! Learn how to use indirect prompt injection to steal data, cause damage & trigger exploit chains! Dive in here: portswigger.net/web-security...
portswigger.net
AI-powered scanner vulnerabilities | Web Security Academy
Application security teams often deploy AI-powered scanners that use Large Language Models (LLMs) to scan web applications for vulnerabilities. While ...
1159
Reposted by Dominique Righetto
Aurélie Vache @aurelievache.bsky.social · 21/04/2026
With the new version of git, Welcome to the new "git history" command! 🎉 Rewording and split commits will be finally easier than before. 💪 github.blog/open-source/...
36927
Dominique Righetto @righettod.eu · 12/04/2026
📡 OWASP Secure Headers Project: We have refactored the section on the browser’s "Local Network Access" feature. #appsec #appsecurity #owasp_shp 📖 owasp.org/www-project-...
110
Reposted by Dominique Righetto
Rob Fuller @mubix.com · 08/04/2026
In collaboration with a couple of other leaders in the industry we are releasing securitytitles.com - It's an attempt to provide transparency about role levels, expectations and (just for the US market currently, salary ranges). For leaders writing JDs and candidates alike.
securitytitles.com
Home | Security Titles
02011
Reposted by Dominique Righetto
jub0bs @jub0bs.com · 07/04/2026
🎉 After a few years of refinement and close to 1 >> 9 commits, I'm pleased to announce the v1 release of my CORS middleware library for Go. Let me know whether it patches things up between you and CORS! github.com/jub0bs/cors #golang #CORS
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
2205
Reposted by Dominique Righetto
Louis Nyffenegger @snyff.pentesterlab.com · 31/03/2026
Everyone is panicking about AI-generated zero days like it's an attacker story. It's not. Defenders can use the best models against their own code right now. Your progress compounds. Attackers' job gets harder. pentesterlab.com/blog/defende...
pentesterlab.com
Defenders Finally Have the Edge - PentesterLab's Blog
AI agents are changing vulnerability research, but the real advantage goes to defenders. Attackers face air-gap constraints while defenders get full access to frontier models on their own code. Every ...
032
Reposted by Dominique Righetto
Uncle Joe @sydseter.com · 24/03/2026
The Cornucopia of Gamified Threat Modeling At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website App Edition v3.0! dev.to/owasp/the-co... #appsec #cybersecurity #gamedev #security
dev.to
The Cornucopia of Gamified Threat Modeling
At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website...
2118
Reposted by Dominique Righetto
nixCraft @cyberciti.biz · 30/03/2026
heads up: FreeBSD forums hacked. Be caeeful with your email or DMs coming from FreeBSD forum or freebsd{.}org for some time now. https:// forums {.} freebsd {.} org/
14829
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 29/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟭𝟯, 𝟮𝟬𝟮𝟲 Only one entry but definitely worth reading! ☁️ 𝗥𝗲𝗺𝗼𝘁𝗲 𝗖𝗼𝗺𝗺𝗮𝗻𝗱 𝗘𝘅𝗲𝗰𝘂𝘁𝗶𝗼𝗻 𝗶𝗻 𝗚𝗼𝗼𝗴𝗹𝗲 𝗖𝗹𝗼𝘂𝗱 𝘄𝗶𝘁𝗵 𝗦𝗶𝗻𝗴𝗹𝗲 𝗗𝗶𝗿𝗲𝗰𝘁𝗼𝗿𝘆 𝗗𝗲𝗹𝗲𝘁𝗶𝗼𝗻 This one is a real tour de force: flatt.tech/research/pos....
flatt.tech
Remote Command Execution in Google Cloud with Single Directory Deletion
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During...
021
Reposted by Dominique Righetto
Voxxed Days Luxembourg @lu.voxxeddays.com · 29/03/2026
Dear contributors to Voxxed Days Luxembourg's renewed success: the call for your papers, supposedly closed tonight wil be extended by 2 weeks to accomodate latecomers. A small reminder: 15 min. lunch talks are often under-filled, to test your speaker abilities, this is a perfect opportunity!
076
Dominique Righetto @righettod.eu · 26/03/2026
🧑‍🎓 Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation). #appsec #appsecurity
121
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 22/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟭𝟮, 𝟮𝟬𝟮𝟲 AI doing research, AI killing CTF 🤖 𝗧𝗲𝘀𝘁𝗶𝗻𝗴 𝗔𝗜 𝗳𝗼𝗿 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵: 𝟰 𝗔𝗽𝗽𝗿𝗼𝗮𝗰𝗵𝗲𝘀 & 𝗪𝗵𝗲𝗿𝗲 𝗜 𝗙𝗮𝗶𝗹𝗲𝗱 If you can only read one thing this week, make it this article: xclow3n.github.io/post/7.
xclow3n.github.io
Testing AI for Vulnerability Research: 4 Approaches & Where I Failed | xclow3n
Tested 4 AI-assisted approaches for finding vulnerabilities over one week. Found real bugs — 14 confirmed vulns in one target in 20 minutes. Also burned time on an approach that found nothing useful. ...
142
Reposted by Dominique Righetto
Gildas Cuisinier @gcuisinier.net · 16/03/2026
Le CFP des 10 ans de VoxxedDays Luxembourg est toujours ouvert, ne trainez plus :) → voxxedlu2026.cfp.dev#/
185
Dominique Righetto @righettod.eu · 14/03/2026
🧑‍🎓 Learning of the day for me thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation): #appsec #appsecurity
Example of execution.
111
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 08/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟭𝟬, 𝟮𝟬𝟮𝟲 A great mix of content this week! 🔒 𝗜𝗿𝗼𝗻𝗖𝘂𝗿𝘁𝗮𝗶𝗻: 𝗔 𝗣𝗲𝗿𝘀𝗼𝗻𝗮𝗹 𝗔𝗜 𝗔𝘀𝘀𝗶𝘀𝘁𝗮𝗻𝘁 𝗕𝘂𝗶𝗹𝘁 𝗦𝗲𝗰𝘂𝗿𝗲 𝗳𝗿𝗼𝗺 𝘁𝗵𝗲 𝗚𝗿𝗼𝘂𝗻𝗱 𝗨𝗽 Niels Provos (from OpenBSD's systrace) is sharing a new tool to sandbox your AI assistant: www.provos.org/p/ironcurtai....
141
Reposted by Dominique Righetto
CryptoCat @cryptocat.me · 04/03/2026
My first @metasploit-r7.bsky.social module is live! You can now exploit CVE-2026-1731 (BeyondTrust command injection) with the latest version 😎
CVE-2026-1731 Metasploit module demo
132
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 01/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟵, 𝟮𝟬𝟮𝟲 Mostly AI... 💻 𝗕𝗿𝗼𝘄𝘀𝗲𝗿-𝗕𝗮𝘀𝗲𝗱 𝗣𝗼𝗿𝘁 𝗦𝗰𝗮𝗻𝗻𝗶𝗻𝗴 𝗶𝗻 𝘁𝗵𝗲 𝗔𝗴𝗲 𝗼𝗳 𝗟𝗡𝗔 Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....
wiki.notveg.ninja
Browser-Based Port Scanning in the Age of LNA
123
Reposted by Dominique Righetto
Louis Nyffenegger @snyff.pentesterlab.com · 02/03/2026
I wrote about what happens when you rewrite mature software with agents. You rebuild the features. You don't rebuild the scars. vinext: one engineer, one week, $1,100 in tokens. Then plenty of vulnerabilities found within days. pentesterlab.com/blog/what-yo...
pentesterlab.com
What you don't see - PentesterLab's Blog
More and more, with the progress of coding agents, people are rewriting software.And honestly, it looks easy. You write a good ...
045
Reposted by Dominique Righetto
Bearstech @bearstech.com · 28/02/2026
Zensical : un générateur de sites statiques qui permet de transformer rapidement une documentation Markdown en un site professionnel, personnalisable et multilingue. (Découvert via Mat V. ) 👉 Le projet : github.com/zensical/... 👉 En savoir plus : zensical.org
vue de zensical
23611
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 28/02/2026
6 new code review labs just dropped 🚀 +3 for JavaScript Code Review +3 for Python Code Review JS: pentesterlab.com/badges/javas... Python: pentesterlab.com/badges/pytho...
pentesterlab.com
PentesterLab: Learn with our JavaScript Code Review
The JavaScript Code Review Badge is our badge dedicated to security code review in JavaScript. It covers the discovery of weaknesses and vulnerabilities using source code review.
052
Dominique Righetto @righettod.eu · 26/02/2026
🧑‍🎓 As part of my homework on AI from an AppSec perspective, I have decided to gather all my content on GitHub so that I can share it in case anyone is interested. 📖 Cheat sheet, methodology and tools: github.com/righettod/to... 🔬 R&D: github.com/righettod/po... #appsec #appsecurity #ai
Overview of one repo
011
Reposted by Dominique Righetto
coreruleset.bsky.social @coreruleset.bsky.social · 18/02/2026
🔥 OWASP CRS is evolving! Introducing #CRSLang — a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors. Check it out 👉 coreruleset.org/2026... #WAF #AppSec #OWASP #ModSecurity
042
Reposted by Dominique Righetto
Voxxed Days Luxembourg @lu.voxxeddays.com · 15/02/2026
Erratum, it's opened tonight February the 15th 😂 -------------- Erratum, c'est ouvert ce soir le 15 février 😂
032
Reposted by Dominique Righetto
Voxxed Days Luxembourg @lu.voxxeddays.com · 15/02/2026
Voxxed Days Luxembourg's CFP will be opened from tonight February the 17th at 11:30 PM to March the 29th at midnight.Luxembourg ---------------- L'appel aux orateurs de Voxxed Days sera ouvert à partir de ce soir, le 17 février à 23h30 jusqu'au 29 mars à minuit. --- voxxedlu2026.cfp.dev
2610
Reposted by Dominique Righetto
Uncle Joe @sydseter.com · 10/02/2026
OWASP Cornucopia just release v2.6.0 github.com/OWASP/cornuc... The new release comes with support for continuing the game session even if players can not continue the game when playing on copi.owasp.org #owasp #appsec #security #cornucopia
github.com
Release Release v2.6.0 · OWASP/cornucopia
What's Changed Bump svelte from 5.49.2 to 5.50.0 in /cornucopia.owasp.org by @dependabot[bot] in #2188 Bump postgrex from 0.21.1 to 0.22.0 in /copi.owasp.org by @dependabot[bot] in #2186 Bump wait...
174
Reposted by Dominique Righetto
renniepak @renniepak.nl · 07/02/2026
Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically don’t need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.
075
Reposted by Dominique Righetto
Bearstech @bearstech.com · 06/02/2026
Sqldef : un outil CLI qui permet le "diffing" de deux schémas SQL et de générer automatiquement les instructions de migration nécessaires. 👉 sqldef.github.io/
1172
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 06/02/2026
MORE LABS IN OUR JAVASCRIPT CODE REVIEW BADGE: pentesterlab.com/badges/javas...
021
Reposted by Dominique Righetto
don-ho.bsky.social @don-ho.bsky.social · 05/02/2026
Important Clarification: Notepad++ Security Incident (Indicators of Compromise provided by our former hosting provider is included): notepad-plus-plus.org/news/clarifi...
notepad-plus-plus.org
Important Clarification: Notepad++ Security Incident | Notepad++
193
Dominique Righetto @righettod.eu · 02/02/2026
🧑‍🎓 Learning of the day for me thanks to @pentesterlab.com and Claude. 🔬 For the regular expression "[A-z]": In a character class [X-Y], it matches all characters with ASCII codes from X to Y inclusive. So [A-z] means all ASCII characters from 65 (A) to 122 (z). #appsec #appsecurity
Execution of the POC performed.
141