Sign in

SeanWrightSec

@seanwrightsec.com
2K followers 124 following 305 posts

Principal Application Security Engineer focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.

PostsRepliesMedia
SeanWrightSec @seanwrightsec.com · 31/07/2026
Any decent AI security related book the anyone recommends?
static.klipy.com
Jack Black Amazed by Glowing Book
ALT: Jack Black Amazed by Glowing Book
020
SeanWrightSec @seanwrightsec.com · 10/06/2026
Been itching to share this the past few days, and now I can! Incredible effort by the team and all involved. The public announcement has all the details (and more), including the link to the open source project! corporate.visa.com/en/sites/vis...
corporate.visa.com
Visa participates in Anthropic’s Project Glasswing
Visa participation reflects a proactive approach to testing advanced AI for cybersecurity and strengthening the global payments ecosystem
010
SeanWrightSec @seanwrightsec.com · 29/12/2025
Looks like the final OWASP Top 10 (2025) has been published: owasp.org/Top10/2025/. Based on commits, looks like this happened 5 days ago.
owasp.org
OWASP Top 10:2025
OWASP Top 10:2025
071
SeanWrightSec @seanwrightsec.com · 19/12/2025
Surprised it’s taken this long! Microsoft has finally killed off the RC4 cipher. www.msn.com/en-gb/money/...
msn.com
MSN
141
SeanWrightSec @seanwrightsec.com · 12/12/2025
Mitre’s Top 25 list is out: cwe.mitre.org/top25/archiv...
cwe.mitre.org
CWE - 2025 CWE Top 25 Most Dangerous Software Weaknesses
Common Weakness Enumeration (CWE) is a list of software and hardware weaknesses.
020
SeanWrightSec @seanwrightsec.com · 06/11/2025
The candidate list for the OWASP Top 10 2025 list (owasp.org/Top10/2025/0...):
251
SeanWrightSec @seanwrightsec.com · 06/11/2025
So the release candidate has been will be released today (6 November 2025): owasp.org/www-project-... Comments until 20 November 2025.
owasp.org
OWASP Top Ten | OWASP Foundation
The OWASP Top 10 is the reference standard for the most critical web application security risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing your software devel...
000
SeanWrightSec @seanwrightsec.com · 05/11/2025
SANS Holiday Hack Challenge 2025 is now available! www.sans.org/cyber-ranges...
sans.org
Holiday Hack Cybersecurity Challenge 2025 | SANS Institute
Join the global cybersecurity community in the most festive and challenging event of the year! The SANS Holiday Hack Challenge cyber range offers FREE, high-quality, and super fun hands-on cybersecuri...
041
SeanWrightSec @seanwrightsec.com · 03/11/2025
Friendly reminder… the 2025 OWASP Top 10 should be dropping at the end of this week!
052
SeanWrightSec @seanwrightsec.com · 15/09/2025
Was getting confused as well, 15.7 was released, but so was macOS 26! It initially wasn't available, but is now 😆
100
SeanWrightSec @seanwrightsec.com · 15/09/2025
Very true! Have that installing at this very moment as well.
110
SeanWrightSec @seanwrightsec.com · 15/09/2025
2 update paths to go down today…
330
SeanWrightSec @seanwrightsec.com · 14/09/2025
You don’t have to like or agree with others. But a simple bit of humanity can go a long way.
020
SeanWrightSec @seanwrightsec.com · 14/09/2025
This is a really tough time of the year for me. I lost my own father 7 years ago. And while it does become easier to cope over time, it’s still difficult. What makes it harder this time is seeing people celebrating the death of someone else’s father all because they don’t agree with their viewpoints
140
SeanWrightSec @seanwrightsec.com · 08/09/2025
So this does look to have limited impact. Looks to only target cryptocurrency, and the window for downloading most of the malicious packages is only a few hours.
000
SeanWrightSec @seanwrightsec.com · 08/09/2025
This is starting to look like this may have significant implications. 18 popular packages affected so far. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack
In a supply chain attack, attackers have injected malware into NPM packages with over 2.6 billion weekly downloads after compromising a maintainer's account in a phishing attack.
140
SeanWrightSec @seanwrightsec.com · 20/08/2025
Great article by @jpmjr.bsky.social on @reversinglabs.com blog. Thank you for including my comments. It’s going to be an interesting time ahead with AI now playing a larger role in development. www.reversinglabs.com/blog/modern-...
reversinglabs.com
The state of software development: 5 action items for AppSec teams | ReversingLabs
Application security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.
011
SeanWrightSec @seanwrightsec.com · 19/08/2025
I’m hoping that this is true! www.theregister.com/2025/08/19/u...
theregister.com
US spy chief claims UK backdown on Apple backdoor demand
: Tulsi Gabbard boasts Washington forced Blighty to drop iPhone encryption fight
010
SeanWrightSec @seanwrightsec.com · 01/08/2025
Looks like you can import from other apps…
111
SeanWrightSec @seanwrightsec.com · 01/08/2025
I like the ability to sync using things like my iCloud account, not to mention the support for multiple platforms and OS’s. It also looks slick as well.
100
SeanWrightSec @seanwrightsec.com · 01/08/2025
Proton have released a new Authenticator app. Looks pretty cool! proton.me/authenticato...
proton.me
Authenticator app download: Get Proton Authenticator | Proton
Download Proton Authenticator app for Windows, macOS, Linux, Android, and iOS. Protect your accounts with secure two-factor codes. No ads, no tracking.
350
SeanWrightSec @seanwrightsec.com · 25/07/2025
A good example of why understanding what the code of AI is doing. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Amazon AI coding agent hacked to inject data wiping commands
A hacker planted data wiping code in a version of Amazon's generative AI-powered assistant, the Q Developer Extension for Visual Studio Code.
000
SeanWrightSec @seanwrightsec.com · 25/07/2025
I’m completely shocked! Would have never expected this to happen! www.techradar.com/vpn/vpn-priv...
techradar.com
VPN usage soars in Iran – but authorities may be trying to prevent it
Proton VPN confirmed an hourly increase in sign-ups of over 1,400% starting from July 25, 2025
010
SeanWrightSec @seanwrightsec.com · 25/07/2025
Oh dear! What a shame… never mind 😁 The sweet taste of karma! www.techradar.com/pro/security...
techradar.com
This major cybercrime forum might have just exposed all its users
A leak forum did what leak forums do - but to its own users
051
SeanWrightSec @seanwrightsec.com · 14/07/2025
Never, totally legit 🤣
000
SeanWrightSec @seanwrightsec.com · 14/07/2025
Exactly my thoughts 😂
010
SeanWrightSec @seanwrightsec.com · 14/07/2025
Where to start 😁
210
SeanWrightSec @seanwrightsec.com · 10/07/2025
Source: caniphish.com/blog/cyber-s...
020
Reposted by SeanWrightSec
V_To_The_K 🅅 @v-to-the-k.bsky.social · 09/07/2025
Humble Bundle has an interesting bundle at the moment.
humblebundle.com
Humble Tech Book Bundle: The Pentesting & Hacking Toolkit by Packt
Learn how to test your cyber defenses with the Pentesting & Hacking Toolkit by Packt. Protect yourself from cyberattacks and support charity!
062
SeanWrightSec @seanwrightsec.com · 08/07/2025
Fingers crossed they see the errors of their way and improve. Sucks to be in these positions.
110
SeanWrightSec @seanwrightsec.com · 08/07/2025
Yikes! That doesn’t sound good. Hope it gets sorted out.
110
SeanWrightSec @seanwrightsec.com · 07/07/2025
Sorry to hear that. I hope it gets better! I would also say that often those postings are for the ideal candidate. So not always a case that you need to have everything on the job spec.
110
SeanWrightSec @seanwrightsec.com · 07/07/2025
Shout if there’s anything I can do help. Sorry you going through a rough patch. But you realise that you not alone 😀
110
SeanWrightSec @seanwrightsec.com · 07/07/2025
Also you likely brings to the table that others who have been solely based in security wouldn’t be able to. That’s so important! So don’t sell yourself short 😀
110
SeanWrightSec @seanwrightsec.com · 07/07/2025
You got this! I’d rather someone with rounded experience than some ninja who may be great from a technical perspective but isn’t so hot when dealing with others and business needs. Soft skills is often such an underrated aspect of our jobs.
120
SeanWrightSec @seanwrightsec.com · 30/06/2025
Another reminder to revoke access immediately for former employees, especially ones who have been dismissed. www.theregister.com/2025/06/30/b...
theregister.com
Seven months for IT worker who trashed his work network
: Don't leave the door open to disgruntled workers
010
SeanWrightSec @seanwrightsec.com · 24/05/2025
This is so important in our field as we have a constant barrage of new things (technology, attack types, etc). It’s not an easy thing to do, and does take time. But once you are at peace with it, it’ll help things for the better.
031
SeanWrightSec @seanwrightsec.com · 24/05/2025
I’ve given this advice to several folk, and it’s worth sharing with others. Learning how to become comfortable with not knowing something is liberating. It’ll help give you the confidence to then do something about it.
152
SeanWrightSec @seanwrightsec.com · 22/05/2025
Not sure. I don’t store my passwords on iCloud. But maybe they did a default message to everyone 🤷‍♂️
100
SeanWrightSec @seanwrightsec.com · 22/05/2025
While having something showing the likelihood of a vuln being exploited is good, I do worry this will end up being just another metric. I hope that I’m wrong, and this will prove helpful. www.darkreading.com/vulnerabilit...
darkreading.com
NIST's LEV Equation to Rate Chances a Bug Was Exploited
The new equation, introduced by the National Institute of Standards and Technology (NIST), aims to offer a mathematical likelihood index that could be a game-changer for SecOps teams and vulnerability...
000
SeanWrightSec @seanwrightsec.com · 21/05/2025
Anyone else seen this on Instagram?
120
SeanWrightSec @seanwrightsec.com · 15/05/2025
A really important reason why it’s important to have security tooling working and operating as you expect. It’s already difficult to get other teams to buy into these tools so when they are constantly “wrong”, getting those teams onboard is almost impossible.
010
SeanWrightSec @seanwrightsec.com · 15/05/2025
Also important to note that ENISA is a CNA (since Jan 2024), so can it can issue CVEs itself. www.enisa.europa.eu/topics/vulne...
enisa.europa.eu
Vulnerability Disclosure | ENISA
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
000
SeanWrightSec @seanwrightsec.com · 15/05/2025
Important to note that CVE is not a database per se. This is why we have the likes of NVD. So if anything, ENISA would be competing with NVD. But I still have concerns of how this may fragment the ecosystem.
100
SeanWrightSec @seanwrightsec.com · 13/05/2025
Just patched my car 🚙 🤣 #VulnManagement
020
SeanWrightSec @seanwrightsec.com · 13/05/2025
Having said that, I do like the critical and exploited vulnerabilities sections as well as the search functionality.
010
SeanWrightSec @seanwrightsec.com · 13/05/2025
See the EU Vulnerability Database is now live. While I get the desire to have this, the problem that I now worry about is that this is going to fragment vulnerabilities. So making an already difficult problem even harder. euvd.enisa.europa.eu
euvd.enisa.europa.eu
EUVD
European Vulnerability Database
394
SeanWrightSec @seanwrightsec.com · 11/05/2025
Yep!
020
SeanWrightSec @seanwrightsec.com · 11/05/2025
Super secure 😁
100
SeanWrightSec @seanwrightsec.com · 11/05/2025
Anyone spot the flaw?
420