Profile avatar
seanwrightsec.com
Principal Application Security Engineer focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.
228 posts 1,793 followers 116 following
Prolific Poster
Conversation Starter

Myself and @lisaforte.bsky.social will doing our podcast tonight at 8pm (UK time), on Twitch. We also need some topics! twitch.tv/SeanWrightSec

I’m so tired of finding that security tools, and some well established and known, simply don’t do the job they are supposed to. Paying a lot of money for them as well.

Likely going to be FUD around the latest iOS update. Important things to remember, it’s a physical attack that appears difficult to exploit. So likely a highly targeted attack. For most folk, they have little to worry about. But still important to update. support.apple.com/en-us/122174

@lisaforte.bsky.social and myself kicking off with our first podcast of 2025! Join us this Thursday at 8pm (UK time) on Twitch: twitch.tv/SeanWrightSec.

5am start tomorrow 😭 I’m not a morning person lol

Well good luck for them using my messages. Most are pretty one sided and only involve sales pitches 😂

Heads up CVE-2020-11023 (a XSS vuln in jQuery) has been added to the CISA KEV list. If you probably want to see if you are affected by this. www.cve.org/CVERecord?id...

If you haven’t done so yet, drop what you doing right now and go patch your instance! securityonline.info/poc-exploit-...

This points to the absolute problem with some of the BS we see with security “products”. Roll up phishing-resistant next-generation MFA. Meanwhile many of us have been using FIDO for years without all the marketing BS.

Our new complete guide to running table top exercises is now out. No paywall, no email required. Just a resource if you want it. 🫡 red-goat.com/the-complete...

👀 go.theregister.com/feed/www.the...

Looks to be one of the early victims of the recent Invanti vulnerability. www.bleepingcomputer.com/news/securit...

Going to be really interested in the results of this!

Terrible news regarding the CEO of Tenable 😢 My thoughts and sympathies are with his family, loved ones and all employees. What a sad start to 2025. www.tenable.com/press-releas...

Stary night. Really cold out there, but was worth it 😀

Awesome! I’m getting to the restless stage, which means I’m ready to hit the new year next week at work (took today and tomorrow off at the last minute). An exciting 2025 ahead!

Currently what’s my biggest regret of 2024? Not taking tomorrow and Friday off 🤣

First #aurora shots of 2025 😍

Happy New Year! 🥳 Wish you all the best for the new year ahead and may 2025 be a rocking year for you and your loved ones.

Breaking News (again) 🤣

I wasn’t able to make it as I was busy. Have a watch if you interested seeing a reunion of the crew!

Changing things a bit. Instead of making new things for New Years, what’s the 1 thing you’d like to stay the same?

Want to know something… we are now very almost a quarter of the way through the century 😵‍💫

Sites like this 🙄

It’s now official, I’m now a Visa employee now that the Visa acquisition of Featurespace has now completed. I’ve been excited and waiting for this day for the past few weeks, and now extremely excited for the new chapter ahead! Featurespace has now become Featurespace A Visa Solution!

Remember Equifax? If you running Struts you may then want to look at this ASAP. www.theregister.com/2024/12/17/c...

Wrongs answers only. What does DORA stand for? I’ll go first: Didn’t Operate Really Accurately

Final release of Kali for 2024! www.bleepingcomputer.com/news/securit...

He’s doing such harm, while acting like a spoilt child who has a tantrum because he doesn’t get his way.

Let’s Encrypt will begin offering short lived certificates (6 days) next year! letsencrypt.org/2024/12/11/e...

A reminder to not blindly run any exploit PoCs from the Internet. Take time to review it, or only use from trusted sources. securityonline.info/hackers-hack...

The whole drone saga is a prime example of people jumping onto the bandwagon and not investigating or at least applying a bit of scrutiny on a topic.

Some worrying details in this, specifically lack of rate limiting as well as a 3 minute time window for a code that should only be valid for 30s. securityonline.info/critical-mic...

This is hardly surprising. If there’s a way, they will find it. Users are often the best testers 😁

Any end of the year cyber fiasco this year 🤔 We got off last year 😅

Another great writeup by @kateoflaherty.bsky.social. And if you need a reason to update here is an example 😁 Jokes aside, this update still contains important security related fixes.