Sign in

Dominique Righetto

@righettod.eu
1.3K followers 139 following 197 posts

👨‍💻 AppSec enthusiast | 🐶 Addicted to Shetland Sheepdogs | 🌏 Open Source/AppSec/OWASP junkie | 🐝 OWASP Secure Headers Project Leader. 🚩 Opinions mentioned are mine.

PostsRepliesMedia
Reposted by Dominique Righetto
Jeroen @commjoenie.bsky.social · 22/09/2026
We released a new version of #OWASP #Wrongsecrets ! With devcontainer and AI related challenges. Try it out at www.wrongsecrets.com and give the repo a ⭐️ if you like it!
wrongsecrets.com
OWASP WrongSecrets
066
Dominique Righetto @righettod.eu · 13/09/2026
- Project page on the OWASP site: owasp.org/projects/sec... - Web rendering of the main site: owasp.github.io/www-project-... ℹ️ Redirection from owasp.org/www-project-... is in place. 🤝 Thanks to Alexandre ZANNI (www.linkedin.com/in/alexandre...) for the help.
001
Dominique Righetto @righettod.eu · 13/09/2026
📡 OWASP Secure Headers Project: The web user interface is back, we worked all weekend, after the OWAP Foundation's new website went live, to get it back online 😉 #appsec #appsecurity #owasp_shp
UI rendering overview
100
Dominique Righetto @righettod.eu · 06/09/2026
righettod.github.io/code-assista... 🤝 A huge thank you to @pentesterlab.com for all the training courses and labs about secure coding that often led to the creation of a new skill or the update of an existing one. #appsec #appsecurity #ai
010
Dominique Righetto @righettod.eu · 06/09/2026
🔬 The goal of this open source project is to propose them to help DevOps teams with which I have a chance to work with to handle issues identified during secure code review I perform for them. Currently, the collection includes 14 skills, that isn't very many yet, but the number will grow over time.
Overview
110
Dominique Righetto @righettod.eu · 06/09/2026
🧑‍🎓 As part of my homework on AI from an application security perspective: Since several month now I work on a collection of Claude code skills (such skills are compatible with other coding assistants) to generate code that include, by default, a set of security validations. #appsec #appsecurity #ai
140
Dominique Righetto @righettod.eu · 30/08/2026
📖 github.com/OWASP/www-pr...
github.com
000
Dominique Righetto @righettod.eu · 30/08/2026
📡 OWASP Secure Headers Project: - We have added information about the HTTP response headers supporting the "Report-Only" mode. - We have incorporated them into the statistical data, and a contributor has fixed a bug in the script that generates the statistics. #appsec #appsecurity #owasp_shp
120
Reposted by Dominique Righetto
Gareth Heyes @garethheyes.co.uk · 07/08/2026
If you want to see how to compromise an account from a paste and steal passwords in CSS and much more check out my paper "CSS: the bomb inside your inbox" 👇 portswigger.net/research/css...
portswigger.net
CSS:the bomb inside your inbox
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
163
Dominique Righetto @righettod.eu · 01/08/2026
📖 References used and credits: - pentesterlab.com/exercises/ph... - advisories.gitlab.com/composer/man...
pentesterlab.com
PentesterLab: PHP eval() Class Hoisting RCE
This challenge covers an unauthenticated remote code execution reproducing MantisBT CVE-2026-49273: a value is validated with eval('return; ...'), but PHP hoists class declarations past the return; at...
000
Dominique Righetto @righettod.eu · 01/08/2026
🔬 In PHP, the "return" statement is a runtime statement and not a compilation time statement so when used within eval("return;[user-controlled-code]") it do not always prevent execution of code after the "return;" statement.
100
Dominique Righetto @righettod.eu · 01/08/2026
🧑‍🎓 Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the lab) and Claude (for more detailed explanation). #appsec #appsecurity
POC
110
Reposted by Dominique Righetto
Bearstech @bearstech.com · 26/07/2026
🏖️🐻 Les logiciels libres de l'été, jour 35 Typer : une bibliothèque Open Source pour créer des applications en CLI que les utilisateurs adoreront utiliser et que les développeurs prendront plaisir à concevoir. Elle repose sur les hints de type de Python.
Now let's start using Typer in your own code, update main.py with:

import typer


def main(name: str):
    print(f"Hello {name}")


if __name__ == "__main__":
    typer.run(main)
Now you could run it with Python directly:

// Run your application
$ uv run python main.py

// You get a nice error, you are missing 'name'
Usage: main.py [OPTIONS] {name}
Try 'main.py --help' for help.
╭─ Error ───────────────────────────────────────────╮
│ Missing argument 'name'.                          │
╰───────────────────────────────────────────────────╯


// You get a --help for free
$ uv run python main.py --help

Usage: main.py [OPTIONS] {name}

╭─ Arguments ───────────────────────────────────────╮
│ *    name      <str>  [required]                  │
╰───────────────────────────────────────────────────╯
╭─ Options ─────────────────────────────────────────╮
│ --help          Show this message and exit.       │
╰───────────────────────────────────────────────────╯

// Now pass the 'name' argument
$
274
Reposted by Dominique Righetto
Python Package Index @pypi.org · 22/07/2026
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised. blog.pypi.org/posts/2026-0... #python #security #supplychain #pypi
blog.pypi.org
Releases now reject new files after 14 days - The Python Package Index Blog
PyPI no longer allows publishing new files to releases older than 14 days.
04517
Reposted by Dominique Righetto
Goupil @furaxfox.bsky.social · 22/07/2026
blog.elcomsoft.com/2026/07/an-a... an interesting point of view on the OpenAI/Hugging Face incident
blog.elcomsoft.com
An AI agent broke into Hugging Face. Five days later, OpenAI said it was theirs
On 16 July 2026, Hugging Face disclosed that an autonomous AI agent had been inside part of its production infrastructure. The company was clear about what it d
022
Dominique Righetto @righettod.eu · 19/07/2026
📡 OWASP Secure Headers Project - update: 1) We added info about the header "Integrity-Policy". 2) We defined the rules about GenIA usage. 3) We also developed a AI agent to help us (beta). 📖 github.com/OWASP/www-pr... 🤖 github.com/righettod/os... #appsec #appsecurity #owasp_shp
000
Reposted by Dominique Righetto
Voxxed Days Luxembourg @lu.voxxeddays.com · 05/07/2026
Voxxed Days Luxembourg 2026 talks are now online for you to enjoy 😀 ! luxembourg.voxxeddays.com/en/#videos ---- Les présentations de Voxxed Days Luxembourg 2026 sont maintenant en ligne et prêtes à déguster! 😀 luxembourg.voxxeddays.com/en/#videos
0139
Dominique Righetto @righettod.eu · 05/07/2026
All content is now centralized and stored in the GitHub repository in Markdown format. As a result, the content: - Can be used by a generative AI model. - Is displayed by GitHub when viewed in a browser. - Allows for the creation of stable external links.
000
Dominique Righetto @righettod.eu · 05/07/2026
📡 OWASP Secure Headers Project: We have completed the migration on our end, even though the foundation has postponed the release of the CMS. #appsec #appsecurity #owasp_shp 📖 github.com/OWASP/www-pr...
github.com
GitHub - OWASP/www-project-secure-headers: The OWASP Secure Headers Project
The OWASP Secure Headers Project. Contribute to OWASP/www-project-secure-headers development by creating an account on GitHub.
100
Dominique Righetto @righettod.eu · 20/06/2026
💡 See here for all the details: github.com/OWASP/www-pr...
github.com
⚠️ OWASP websites/projects/chapters migration. · OWASP www-project-secure-headers · Discussion #273
Hi, We (@riramar and myself) created this discussion to share/track with the OSHP community, in a open way, an important coming changes in the OSHP. The context 📍 The OWASP foundation has decided t...
000
Dominique Righetto @righettod.eu · 20/06/2026
📡 OWASP Secure Headers Project: We have been informed that the foundation will launch its new website on June 24; therefore, we have begun the migration process today. We apologize for any broken links that may occur over the next few days or weeks. #appsec #appsecurity #owasp_shp
100
Dominique Righetto @righettod.eu · 19/06/2026
static.klipy.com
The Office: Michael Scott Bows and Says Thank You
ALT: The Office: Michael Scott Bows and Says Thank You
100
Dominique Righetto @righettod.eu · 18/06/2026
static.klipy.com
Happy Valentines: I Can't Wait!
ALT: Happy Valentines: I Can't Wait!
000
Reposted by Dominique Righetto
Uncle Joe @sydseter.com · 17/06/2026
Assessments of threats can be seen from different perspectives. Developers may come across privacy impact assessments (PIAs), where threats to users' data and the impact on those users are paramount. PIAs may additionally examine harms to organisations, third parties and wider society. (1/6) #games
284
Dominique Righetto @righettod.eu · 11/06/2026
Next week, at VOXXED Days Luxembourg @lu.voxxeddays.com , I will present a version of the "Die & Retry" concept applied to the file upload feature, specifically for cases where PDF files are accepted 😉 m.devoxx.com/events/voxxe... #appsec #voxxed_lu
010
Dominique Righetto @righettod.eu · 16/05/2026
2) Section "Best Practices": Added information regarding the potential disclosure of technical information via the "WWW-Authenticate" header. #appsec #appsecurity #owasp_shp 📖 owasp.org/www-project-...
000
Dominique Righetto @righettod.eu · 16/05/2026
📡 OWASP Secure Headers Project - We have made the following updates: 1) Section "Code Snippets": The user prompt has been updated to allow direct generation of a web/application server configuration using the online JSON reference file. #appsec #appsecurity #owasp_shp
110
Reposted by Dominique Righetto
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 05/05/2026
bleepingcomputer.com
The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check.
Critical vulnerabilities can exist in open source software your scanners don't check. HeroDevs reveals how EOL software creates blind spots in CVE feeds and SCA tools, and how you can receive a free end-of-life scan for your projects. [...]
011
Dominique Righetto @righettod.eu · 02/05/2026
J'y ai passé 11 ans (Unilog, Logica, CGI) et j'en garde un excellent souvenir car cette boite m'a beaucoup apporté.
010
Reposted by Dominique Righetto
Gareth Heyes @garethheyes.co.uk · 28/04/2026
I needed code snippets for presentations. I was worried about pasting code snippets into untrusted sites. So I just wrote my own using AI. You can trust I won't be tracking your code. It's very customisable and the default is for presentations. hackvertor.co.uk/snippet
172
Dominique Righetto @righettod.eu · 28/04/2026
🤝 A big thank you to Jon Zeolla (www.linkedin.com/in/jonzeolla/) for the inspiration and his valuable technical advice. 😉 I'm sharing all this in case it might interest or help someone in a similar situation to mine.
000
Dominique Righetto @righettod.eu · 28/04/2026
🔬 For point 1, I created a collection of Claude Code skills: github.com/righettod/co... 🔬 For point 2, I created a POC to build a specialized Claude Code skill: github.com/righettod/po... 🔬 For point 3, I created a POC using Claude Code to validate the results: github.com/righettod/po...
100
Dominique Righetto @righettod.eu · 28/04/2026
1) Generating "secure by default" code. 2) Identifying vulnerabilities that could affect a feature and enriching the corresponding User Story with a set of associated Evil User Stories. 3) Filtering the results of a static code analysis.
100
Dominique Righetto @righettod.eu · 28/04/2026
🧑‍🎓 As part of my homework on AI from an application security perspective, I decided to investigate how AI, through a coding assistant (Claude Code in my case), can be used in the following areas: #appsec #appsecurity #ai
210
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 28/04/2026
New badge: JavaScript Sandbox Escape! The first 4 labs are live. If you ship anything that evaluates untrusted or model-generated JavaScript, this badge is for you: pentesterlab.com/badges/javas...
pentesterlab.com
PentesterLab: Learn with our JavaScript Sandbox Escaping
This badge covers JavaScript sandbox escape vulnerabilities. From prototype chain navigation and Function constructor abuse to vm module escapes, static-eval bypasses, real-world CVEs, and advanced pr...
044
Reposted by Dominique Righetto
James Kettle @jameskettle.com · 27/04/2026
We've launched a new free Web Security Academy topic on exploiting AI-powered security scanners! Learn how to use indirect prompt injection to steal data, cause damage & trigger exploit chains! Dive in here: portswigger.net/web-security...
portswigger.net
AI-powered scanner vulnerabilities | Web Security Academy
Application security teams often deploy AI-powered scanners that use Large Language Models (LLMs) to scan web applications for vulnerabilities. While ...
1159
Reposted by Dominique Righetto
Aurélie Vache @aurelievache.bsky.social · 21/04/2026
With the new version of git, Welcome to the new "git history" command! 🎉 Rewording and split commits will be finally easier than before. 💪 github.blog/open-source/...
36927
Dominique Righetto @righettod.eu · 12/04/2026
💡 Although the project is currently on hold due to the OWASP Foundation’s migration to a new CMS (we are waiting for it to go live before strongly updating our content structure), we continue to update and improve the content behind the scenes.
000
Dominique Righetto @righettod.eu · 12/04/2026
📡 OWASP Secure Headers Project: We have refactored the section on the browser’s "Local Network Access" feature. #appsec #appsecurity #owasp_shp 📖 owasp.org/www-project-...
110
Reposted by Dominique Righetto
Rob Fuller @mubix.com · 08/04/2026
In collaboration with a couple of other leaders in the industry we are releasing securitytitles.com - It's an attempt to provide transparency about role levels, expectations and (just for the US market currently, salary ranges). For leaders writing JDs and candidates alike.
securitytitles.com
Home | Security Titles
02011
Reposted by Dominique Righetto
jub0bs @jub0bs.com · 07/04/2026
🎉 After a few years of refinement and close to 1 >> 9 commits, I'm pleased to announce the v1 release of my CORS middleware library for Go. Let me know whether it patches things up between you and CORS! github.com/jub0bs/cors #golang #CORS
github.com
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go
perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.
2205
Reposted by Dominique Righetto
Louis Nyffenegger @snyff.pentesterlab.com · 31/03/2026
Everyone is panicking about AI-generated zero days like it's an attacker story. It's not. Defenders can use the best models against their own code right now. Your progress compounds. Attackers' job gets harder. pentesterlab.com/blog/defende...
pentesterlab.com
Defenders Finally Have the Edge - PentesterLab's Blog
AI agents are changing vulnerability research, but the real advantage goes to defenders. Attackers face air-gap constraints while defenders get full access to frontier models on their own code. Every ...
032
Reposted by Dominique Righetto
Uncle Joe @sydseter.com · 24/03/2026
The Cornucopia of Gamified Threat Modeling At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website App Edition v3.0! dev.to/owasp/the-co... #appsec #cybersecurity #gamedev #security
dev.to
The Cornucopia of Gamified Threat Modeling
At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website...
2118
Reposted by Dominique Righetto
nixCraft @cyberciti.biz · 30/03/2026
heads up: FreeBSD forums hacked. Be caeeful with your email or DMs coming from FreeBSD forum or freebsd{.}org for some time now. https:// forums {.} freebsd {.} org/
14829
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 29/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟭𝟯, 𝟮𝟬𝟮𝟲 Only one entry but definitely worth reading! ☁️ 𝗥𝗲𝗺𝗼𝘁𝗲 𝗖𝗼𝗺𝗺𝗮𝗻𝗱 𝗘𝘅𝗲𝗰𝘂𝘁𝗶𝗼𝗻 𝗶𝗻 𝗚𝗼𝗼𝗴𝗹𝗲 𝗖𝗹𝗼𝘂𝗱 𝘄𝗶𝘁𝗵 𝗦𝗶𝗻𝗴𝗹𝗲 𝗗𝗶𝗿𝗲𝗰𝘁𝗼𝗿𝘆 𝗗𝗲𝗹𝗲𝘁𝗶𝗼𝗻 This one is a real tour de force: flatt.tech/research/pos....
flatt.tech
Remote Command Execution in Google Cloud with Single Directory Deletion
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During...
021
Reposted by Dominique Righetto
Voxxed Days Luxembourg @lu.voxxeddays.com · 29/03/2026
Dear contributors to Voxxed Days Luxembourg's renewed success: the call for your papers, supposedly closed tonight wil be extended by 2 weeks to accomodate latecomers. A small reminder: 15 min. lunch talks are often under-filled, to test your speaker abilities, this is a perfect opportunity!
076
Dominique Righetto @righettod.eu · 26/03/2026
To make it visual, I made an example with a fictional function used to compare if two hosts have the same FQDN:
Example of execution
000
Dominique Righetto @righettod.eu · 26/03/2026
🔬 In Python, the zip() function consider the number of elements of the smallest of the both arrays passed. If the function is used against arrays with different sizes then the items that are parts of the largest array are skipped. 📖 References used: - pentesterlab.com #appsec #appsecurity
110
Dominique Righetto @righettod.eu · 26/03/2026
🧑‍🎓 Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation). #appsec #appsecurity
121
Reposted by Dominique Righetto
PentesterLab @pentesterlab.com · 22/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟭𝟮, 𝟮𝟬𝟮𝟲 AI doing research, AI killing CTF 🤖 𝗧𝗲𝘀𝘁𝗶𝗻𝗴 𝗔𝗜 𝗳𝗼𝗿 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵: 𝟰 𝗔𝗽𝗽𝗿𝗼𝗮𝗰𝗵𝗲𝘀 & 𝗪𝗵𝗲𝗿𝗲 𝗜 𝗙𝗮𝗶𝗹𝗲𝗱 If you can only read one thing this week, make it this article: xclow3n.github.io/post/7.
xclow3n.github.io
Testing AI for Vulnerability Research: 4 Approaches & Where I Failed | xclow3n
Tested 4 AI-assisted approaches for finding vulnerabilities over one week. Found real bugs — 14 confirmed vulns in one target in 20 minutes. Also burned time on an approach that found nothing useful. ...
142