Sign in

SeanWrightSec

@seanwrightsec.com
2K followers 124 following 305 posts

Principal Application Security Engineer focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.

PostsRepliesMedia
SeanWrightSec @seanwrightsec.com · 31/07/2026
Any decent AI security related book the anyone recommends?
static.klipy.com
Jack Black Amazed by Glowing Book
ALT: Jack Black Amazed by Glowing Book
020
SeanWrightSec @seanwrightsec.com · 10/06/2026
Been itching to share this the past few days, and now I can! Incredible effort by the team and all involved. The public announcement has all the details (and more), including the link to the open source project! corporate.visa.com/en/sites/vis...
corporate.visa.com
Visa participates in Anthropic’s Project Glasswing
Visa participation reflects a proactive approach to testing advanced AI for cybersecurity and strengthening the global payments ecosystem
010
SeanWrightSec @seanwrightsec.com · 29/12/2025
Looks like the final OWASP Top 10 (2025) has been published: owasp.org/Top10/2025/. Based on commits, looks like this happened 5 days ago.
owasp.org
OWASP Top 10:2025
OWASP Top 10:2025
071
SeanWrightSec @seanwrightsec.com · 19/12/2025
Surprised it’s taken this long! Microsoft has finally killed off the RC4 cipher. www.msn.com/en-gb/money/...
msn.com
MSN
141
SeanWrightSec @seanwrightsec.com · 12/12/2025
Mitre’s Top 25 list is out: cwe.mitre.org/top25/archiv...
cwe.mitre.org
CWE - 2025 CWE Top 25 Most Dangerous Software Weaknesses
Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.
020
SeanWrightSec @seanwrightsec.com · 06/11/2025
The candidate list for the OWASP Top 10 2025 list (owasp.org/Top10/2025/0...):
251
SeanWrightSec @seanwrightsec.com · 06/11/2025
So the release candidate has been will be released today (6 November 2025): owasp.org/www-project-... Comments until 20 November 2025.
owasp.org
OWASP Top Ten | OWASP Foundation
The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software devel...
000
SeanWrightSec @seanwrightsec.com · 05/11/2025
SANS Holiday Hack Challenge 2025 is now available! www.sans.org/cyber-ranges...
sans.org
Holiday Hack Cybersecurity Challenge 2025 | SANS Institute
Join the global cybersecurity community in the most festive and challenging event of the year! The SANS Holiday Hack Challenge cyber range offers FREE, high-quality, and super fun hands-on cybersecuri...
041
SeanWrightSec @seanwrightsec.com · 03/11/2025
Friendly reminder… the 2025 OWASP Top 10 should be dropping at the end of this week!
052
SeanWrightSec @seanwrightsec.com · 15/09/2025
2 update paths to go down today…
330
SeanWrightSec @seanwrightsec.com · 14/09/2025
This is a really tough time of the year for me. I lost my own father 7 years ago. And while it does become easier to cope over time, it’s still difficult. What makes it harder this time is seeing people celebrating the death of someone else’s father all because they don’t agree with their viewpoints
140
SeanWrightSec @seanwrightsec.com · 08/09/2025
This is starting to look like this may have significant implications. 18 popular packages affected so far. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack
In a supply chain attack, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after compromising a maintainer's account in a phishing attack.
140
SeanWrightSec @seanwrightsec.com · 20/08/2025
Great article by @jpmjr.bsky.social on @reversinglabs.com blog. Thank you for including my comments. It’s going to be an interesting time ahead with AI now playing a larger role in development. www.reversinglabs.com/blog/modern-...
reversinglabs.com
The state of software development: 5 action items for AppSec teams | ReversingLabs
Application security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.
011
SeanWrightSec @seanwrightsec.com · 19/08/2025
I’m hoping that this is true! www.theregister.com/2025/08/19/u...
theregister.com
US spy chief claims UK backdown on Apple backdoor demand
: Tulsi Gabbard boasts Washington forced Blighty to drop iPhone encryption fight
010
SeanWrightSec @seanwrightsec.com · 01/08/2025
Looks like you can import from other apps…
111
SeanWrightSec @seanwrightsec.com · 01/08/2025
Proton have released a new Authenticator app. Looks pretty cool! proton.me/authenticato...
proton.me
Authenticator app download: Get Proton Authenticator | Proton
Download Proton Authenticator app for Windows, macOS, Linux, Android, and iOS. Protect your accounts with secure two-factor codes. No ads, no tracking.
350
SeanWrightSec @seanwrightsec.com · 25/07/2025
A good example of why understanding what the code of AI is doing. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Amazon AI coding agent hacked to inject data wiping commands
A hacker planted data wiping code in a version of Amazon's generative AI-powered assistant, the Q Developer Extension for Visual Studio Code.
000
SeanWrightSec @seanwrightsec.com · 25/07/2025
I’m completely shocked! Would have never expected this to happen! www.techradar.com/vpn/vpn-priv...
techradar.com
VPN usage soars in Iran – but authorities may be trying to prevent it
Proton VPN confirmed an hourly increase in sign-ups of over 1,400% starting from July 25, 2025
010
SeanWrightSec @seanwrightsec.com · 25/07/2025
Oh dear! What a shame… never mind 😁 The sweet taste of karma! www.techradar.com/pro/security...
techradar.com
This major cybercrime forum might have just exposed all its users
A leak forum did what leak forums do - but to its own users
051
SeanWrightSec @seanwrightsec.com · 14/07/2025
Where to start 😁
210
SeanWrightSec @seanwrightsec.com · 10/07/2025
Source: caniphish.com/blog/cyber-s...
020
Reposted by SeanWrightSec
V_To_The_K 🅅 @v-to-the-k.bsky.social · 09/07/2025
Humble Bundle has an interesting bundle at the moment.
humblebundle.com
Humble Tech Book Bundle: The Pentesting & Hacking Toolkit by Packt
Learn how to test your cyber defenses with the Pentesting & Hacking Toolkit by Packt. Protect yourself from cyberattacks and support charity!
062
SeanWrightSec @seanwrightsec.com · 30/06/2025
Another reminder to revoke access immediately for former employees, especially ones who have been dismissed. www.theregister.com/2025/06/30/b...
theregister.com
Seven months for IT worker who trashed his work network
: Don't leave the door open to disgruntled workers
010
SeanWrightSec @seanwrightsec.com · 24/05/2025
I’ve given this advice to several folk, and it’s worth sharing with others. Learning how to become comfortable with not knowing something is liberating. It’ll help give you the confidence to then do something about it.
152
SeanWrightSec @seanwrightsec.com · 22/05/2025
While having something showing the likelihood of a vuln being exploited is good, I do worry this will end up being just another metric. I hope that I’m wrong, and this will prove helpful. www.darkreading.com/vulnerabilit...
darkreading.com
NIST's LEV Equation to Rate Chances a Bug Was Exploited
The new equation, introduced by the National Institute of Standards and Technology (NIST), aims to offer a mathematical likelihood index that could be a game-changer for SecOps teams and vulnerability...
000
SeanWrightSec @seanwrightsec.com · 21/05/2025
Anyone else seen this on Instagram?
120
SeanWrightSec @seanwrightsec.com · 15/05/2025
A really important reason why it’s important to have security tooling working and operating as you expect. It’s already difficult to get other teams to buy into these tools so when they are constantly “wrong”, getting those teams onboard is almost impossible.
010
SeanWrightSec @seanwrightsec.com · 15/05/2025
Important to note that CVE is not a database per se. This is why we have the likes of NVD. So if anything, ENISA would be competing with NVD. But I still have concerns of how this may fragment the ecosystem.
100
SeanWrightSec @seanwrightsec.com · 13/05/2025
Just patched my car 🚙 🤣 #VulnManagement
020
SeanWrightSec @seanwrightsec.com · 13/05/2025
See the EU Vulnerability Database is now live. While I get the desire to have this, the problem that I now worry about is that this is going to fragment vulnerabilities. So making an already difficult problem even harder. euvd.enisa.europa.eu
euvd.enisa.europa.eu
EUVD
European Vulnerability Database
394
SeanWrightSec @seanwrightsec.com · 11/05/2025
Anyone spot the flaw?
420
SeanWrightSec @seanwrightsec.com · 09/05/2025
One key item of security is accountability. Without it, there’s no single person to go to get a system patched. Processes and procedures don’t get revised or updated. The same procedures and processes are not followed. And the list goes on.
030
SeanWrightSec @seanwrightsec.com · 08/05/2025
A hard coded JWT. This is weird (and not mention extremely poor secure coding), never seen a hard coded JWT. These typically have a limited lifetime. This makes me think there might also be a bit more to this. sec.cloudapps.cisco.com/security/cen...
sec.cloudapps.cisco.com
Cisco Security Advisory: Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability
A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbit...
030
SeanWrightSec @seanwrightsec.com · 28/04/2025
I suppose that’s one way of securing the key 😁 www.bleepingcomputer.com/news/linux/k...
bleepingcomputer.com
Kali Linux warns of update failures after losing repo signing key
​Offensive Security warned Kali Linux users to manually install a new Kali repository signing key to avoid experiencing update failures.
140
SeanWrightSec @seanwrightsec.com · 27/04/2025
Space is something else! 😍
000
SeanWrightSec @seanwrightsec.com · 25/04/2025
A statement from CISA regarding the CVE program. Looks like the whole issue was blown out of proportion and many jumped to the wrong conclusion. www.cisa.gov/news-events/...
cisa.gov
Statement from Matt Hartman on the CVE Program | CISA
211
SeanWrightSec @seanwrightsec.com · 16/04/2025
This may actually be a good model to follow instead. Being reliant on a single source has its obvious risks. This is somewhat similar to Let’s Encrypt in some sense, and look at how that turned out and the change it is having. Perhaps this is a better path forward?
020
SeanWrightSec @seanwrightsec.com · 16/04/2025
Another great writeup by @kateoflaherty.bsky.social. Thank you for including my comments. I think it’s important to avoid speculation at this stage and wait for the details to come out. And then take it from there. Who knows what the eventual outcome may be.
010
SeanWrightSec @seanwrightsec.com · 15/04/2025
Already seen a lot of confusion going on. It’s important to understand that Mitre does not operate the National Vulnerability Database (NVD). While NVD does ingest CVE’s from Mitre, it does not operate this database…
152
SeanWrightSec @seanwrightsec.com · 15/04/2025
Interesting new risk from using LLMs to generate code. thecyberexpress.com/genai-llm-co...
thecyberexpress.com
LLMs Create a New Supply Chain Threat: Code Package Hallucinations
Code-generating large language models (LLMs) have introduced a new security issue into software development: Code package hallucinations. Package hallucinations occur
021
SeanWrightSec @seanwrightsec.com · 14/04/2025
Shorter lived certs are on the way! www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
SSL/TLS certificate lifespans reduced to 47 days by 2029
The CA/Browser Forum has voted to significantly reduce the lifespan of SSL/TLS certificates over the next 4 years, with a final lifespan of just 47 days starting in 2029.
001
SeanWrightSec @seanwrightsec.com · 14/04/2025
😂
020
Reposted by SeanWrightSec
Troy Hunt @troyhunt.com · 10/04/2025
I'm looking for some contacts at companies that provide identity protection services, any followers out there? Further, have you had good experiences with any specific companies? There are some product placement opportunities we're exploring in the updated @haveibeenpwned.com site.
035
SeanWrightSec @seanwrightsec.com · 03/04/2025
Interesting chain leading to the actual compromise. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Recent GitHub supply chain attack traced to leaked SpotBugs token
A cascading supply chain attack on GitHub that targeted Coinbase in March has now been traced back to a single token stolen from a SpotBugs workflow, which allowed a threat actor to compromise multipl...
011
SeanWrightSec @seanwrightsec.com · 13/02/2025
Myself and @lisaforte.bsky.social will doing our podcast tonight at 8pm (UK time), on Twitch. We also need some topics! twitch.tv/SeanWrightSec
twitch.tv
Twitch
Twitch is the world
031
SeanWrightSec @seanwrightsec.com · 12/02/2025
I’m so tired of finding that security tools, and some well established and known, simply don’t do the job they are supposed to. Paying a lot of money for them as well.
030
SeanWrightSec @seanwrightsec.com · 10/02/2025
Likely going to be FUD around the latest iOS update. Important things to remember, it’s a physical attack that appears difficult to exploit. So likely a highly targeted attack. For most folk, they have little to worry about. But still important to update. support.apple.com/en-us/122174
support.apple.com
About the security content of iOS 18.3.1 and iPadOS 18.3.1 - Apple Support
This document describes the security content of iOS 18.3.1 and iPadOS 18.3.1
041
SeanWrightSec @seanwrightsec.com · 09/02/2025
@lisaforte.bsky.social and myself kicking off with our first podcast of 2025! Join us this Thursday at 8pm (UK time) on Twitch: twitch.tv/SeanWrightSec.
082
SeanWrightSec @seanwrightsec.com · 28/01/2025
5am start tomorrow 😭 I’m not a morning person lol
020
SeanWrightSec @seanwrightsec.com · 23/01/2025
Well good luck for them using my messages. Most are pretty one sided and only involve sales pitches 😂
030