๐ก Although the project is currently on hold due to the OWASP Foundationโs migration to a new CMS (we are waiting for it to go live before strongly updating our content structure), we continue to update and improve the content behind the scenes.
Posts by Dominique Righetto
๐ก OWASP Secure Headers Project: We have refactored the section on the browserโs "Local Network Access" feature.
#appsec #appsecurity #owasp_shp
๐ owasp.org/www-project-...
In collaboration with a couple of other leaders in the industry we are releasing securitytitles.com - It's an attempt to provide transparency about role levels, expectations and (just for the US market currently, salary ranges). For leaders writing JDs and candidates alike.
๐ After a few years of refinement and close to 1 >> 9 commits, I'm pleased to announce the v1 release of my CORS middleware library for Go.
Let me know whether it patches things up between you and CORS!
github.com/jub0bs/cors
#golang #CORS
Everyone is panicking about AI-generated zero days like it's an attacker story.
It's not.
Defenders can use the best models against their own code right now.
Your progress compounds. Attackers' job gets harder.
pentesterlab.com/blog/defende...
The Cornucopia of Gamified Threat Modeling
At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website App Edition v3.0!
dev.to/owasp/the-co...
#appsec #cybersecurity #gamedev #security
heads up: FreeBSD forums hacked. Be caeeful with your email or DMs coming from FreeBSD forum or freebsd{.}org for some time now.
https:// forums {.} freebsd {.} org/
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ญ๐ฏ, ๐ฎ๐ฌ๐ฎ๐ฒ
Only one entry but definitely worth reading!
โ๏ธ ๐ฅ๐ฒ๐บ๐ผ๐๐ฒ ๐๐ผ๐บ๐บ๐ฎ๐ป๐ฑ ๐๐
๐ฒ๐ฐ๐๐๐ถ๐ผ๐ป ๐ถ๐ป ๐๐ผ๐ผ๐ด๐น๐ฒ ๐๐น๐ผ๐๐ฑ ๐๐ถ๐๐ต ๐ฆ๐ถ๐ป๐ด๐น๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ฒ๐น๐ฒ๐๐ถ๐ผ๐ป
This one is a real tour de force: flatt.tech/research/pos....
Dear contributors to Voxxed Days Luxembourg's renewed success: the call for your papers, supposedly closed tonight wil be extended by 2 weeks to accomodate latecomers.
A small reminder: 15 min. lunch talks are often under-filled, to test your speaker abilities, this is a perfect opportunity!
Example of execution
To make it visual, I made an example with a fictional function used to compare if two hosts have the same FQDN:
๐ฌ In Python, the zip() function consider the number of elements of the smallest of the both arrays passed. If the function is used against arrays with different sizes then the items that are parts of the largest array are skipped.
๐ References used:
- pentesterlab.com
#appsec #appsecurity
๐งโ๐ Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation).
#appsec #appsecurity
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ญ๐ฎ, ๐ฎ๐ฌ๐ฎ๐ฒ
AI doing research, AI killing CTF
๐ค ๐ง๐ฒ๐๐๐ถ๐ป๐ด ๐๐ ๐ณ๐ผ๐ฟ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต: ๐ฐ ๐๐ฝ๐ฝ๐ฟ๐ผ๐ฎ๐ฐ๐ต๐ฒ๐ & ๐ช๐ต๐ฒ๐ฟ๐ฒ ๐ ๐๐ฎ๐ถ๐น๐ฒ๐ฑ
If you can only read one thing this week, make it this article: xclow3n.github.io/post/7.
Le CFP des 10 ans de VoxxedDays Luxembourg est toujours ouvert, ne trainez plus :)
โ voxxedlu2026.cfp.dev#/
๐ก The instruction "()" at the end is important otherwise the code is not executed.
๐ References used:
- pentesterlab.com
๐ฌ In JavaScript, the instruction "Function(inputString)()" cause the content of "inputString" to be executed. "Function()" is a constructor that creates a new function from a string of code, similar to "eval()", but slightly more contained.
#appsec #appsecurity
Example of execution.
๐งโ๐ Learning of the day for me thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation):
#appsec #appsecurity
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ญ๐ฌ, ๐ฎ๐ฌ๐ฎ๐ฒ
A great mix of content this week!
๐ ๐๐ฟ๐ผ๐ป๐๐๐ฟ๐๐ฎ๐ถ๐ป: ๐ ๐ฃ๐ฒ๐ฟ๐๐ผ๐ป๐ฎ๐น ๐๐ ๐๐๐๐ถ๐๐๐ฎ๐ป๐ ๐๐๐ถ๐น๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ณ๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ฟ๐ผ๐๐ป๐ฑ ๐จ๐ฝ
Niels Provos (from OpenBSD's systrace) is sharing a new tool to sandbox your AI assistant: www.provos.org/p/ironcurtai....
CVE-2026-1731 Metasploit module demo
My first @metasploit-r7.bsky.social module is live! You can now exploit CVE-2026-1731 (BeyondTrust command injection) with the latest version ๐
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ต, ๐ฎ๐ฌ๐ฎ๐ฒ
Mostly AI...
๐ป ๐๐ฟ๐ผ๐๐๐ฒ๐ฟ-๐๐ฎ๐๐ฒ๐ฑ ๐ฃ๐ผ๐ฟ๐ ๐ฆ๐ฐ๐ฎ๐ป๐ป๐ถ๐ป๐ด ๐ถ๐ป ๐๐ต๐ฒ ๐๐ด๐ฒ ๐ผ๐ณ ๐๐ก๐
Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....
I wrote about what happens when you rewrite mature software with agents. You rebuild the features. You don't rebuild the scars.
vinext: one engineer, one week, $1,100 in tokens. Then plenty of vulnerabilities found within days.
pentesterlab.com/blog/what-yo...
vue de zensical
Zensical : un gรฉnรฉrateur de sites statiques qui permet de transformer rapidement une documentation Markdown en un site professionnel, personnalisable et multilingue. (Dรฉcouvert via Mat V. )
๐ Le projet : github.com/zensical/...
๐ En savoir plus : https://zensical.org/
6 new code review labs just dropped ๐
+3 for JavaScript Code Review
+3 for Python Code Review
JS: pentesterlab.com/badges/javas...
Python: pentesterlab.com/badges/pytho...
Overview of one repo
๐งโ๐ As part of my homework on AI from an AppSec perspective, I have decided to gather all my content on GitHub so that I can share it in case anyone is interested.
๐ Cheat sheet, methodology and tools: github.com/righettod/to...
๐ฌ R&D: github.com/righettod/po...
#appsec #appsecurity #ai
๐ฅ OWASP CRS is evolving! Introducing #CRSLang โ a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors.
Check it out ๐ coreruleset.org/2026...
#WAF #AppSec #OWASP #ModSecurity
Erratum, it's opened tonight February the 15th ๐
--------------
Erratum, c'est ouvert ce soir le 15 fรฉvrier ๐
Voxxed Days Luxembourg's CFP will be opened from tonight February the 17th at 11:30 PM to March the 29th at midnight.Luxembourg
----------------
L'appel aux orateurs de Voxxed Days sera ouvert ร partir de ce soir, le 17 fรฉvrier ร 23h30 jusqu'au 29 mars ร minuit.
---
voxxedlu2026.cfp.dev
OWASP Cornucopia just release v2.6.0
github.com/OWASP/cornuc...
The new release comes with support for continuing the game session even if players can not continue the game when playing on copi.owasp.org
#owasp #appsec #security #cornucopia
Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically donโt need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.
Sqldef : un outil CLI qui permet le "diffing" de deux schรฉmas SQL et de gรฉnรฉrer automatiquement les instructions de migration nรฉcessaires.
๐ sqldef.github.io/