Code Security & Digital Operational Resilience mercenary. TPRM code specialist. 1st step to digital trust begins w a shared SBOM. Trust & Verify. Continuously..Joined April 2025
NEW: we issued Emergency Directive 25-02 in response to a Microsoft Exchange Vulnerability. Federal agencies must take immediate action, and we urge all organizations to adopt the actions outlined here: go.dhs.gov/iwR
In case you missed my news elsewhere: This will be my last week at CISA. I’m sad to be leaving a great team, but very excited for some new projects. And don’t worry—I’ll be finding ways to help out with #SBOM!
meritalk.com/articles/cisa-…
🚨 Our Malware Intelligence team has detected an active and on-going attack against packages on npm against the @react-native-aria/ scope.
Combined, the 13 affected packages have more than 650.000 downloads per week each.
airandspaceforces.com/acting-pentago…#SBOM requirements are about to be everywhere.
AI-generated code produces more risks (+30%) compared to human generated code!
I see big corps/companies mandating shared-SBOMs for the software vendors being a new requirement soon, very soon!
🚨We have discovered a backdoor in the official #xrpl NPM package. This back door steals private keys and sends them to attackers. The affected versions 4.2.1 - 4.2.4, if you are using an earlier version, do not upgrade.
#crypto#malware#npm
Hello! I come bearing ("suspected") DPRK gifts. Including public Google Drive links they left open containing 🧁goodies. Copies have been made, don't worry!
My (safe) link for the research:
docs.google.com/document/d/1Id…
Quick pic..*WAY* data more in files!
BREAKING: NIST releases the final draft of SP 800-53, Revision 5. It is the first control catalog in the world with an integrated set of security and privacy controls that are ready to support the NIST Cybersecurity and Privacy Frameworks.
nist.gov/news-events/ne…#NISTCyber
So, what just happened with the CVE program?
- MITRE drops a letter saying funding ends tomorrow
- Everyone panics, assumes no more CVE numbers
- The community scrambles to organize
- The CVE Foundation appears, positioned as a vendor-neutral non-profit
- We all learn MITRE has…
Securing the software supply chain is crucial for our national security.
At Palantir, we take this responsibility seriously.
Discover our robust measures for protecting source code, from zero-trust development to commit signing in the latest installment of our Software Supply…
How do companies ship code to production?
The diagram below illustrates the typical workflow.
Step 1: The process starts with a product owner creating user stories based on requirements.
Step 2: The dev team picks up the user stories from the backlog and puts them into a…
🛑 CRITICAL ALERT → U.S. funding for MITRE’s CVE vulnerability database program ends Wednesday.
MITRE warns: no funding = no new CVEs, degraded threat advisories, and slower incident response.
🛠️ CVEs power security tools, alerts, and patching across critical infrastructure.…
105 Followers 269 FollowingA Founding Partner at Brentwood Ventures, LLC, we spend most of my time helping early stage technology start-ups find their way.
83 Followers 443 FollowingFreelance revolution: 13.5% vs 25% Others charge clients too. We don't. Zero client fees Built in 3 days Save $1,150 per $10K project
11K Followers 6K FollowingAppSec Village @DEFCON & @RSAConference
A volunteer-run, non-profit focused on education, awareness, and community. Founded by @erezyalon and @tzionit411.
14K Followers 11K FollowingCybersec. & Audit VP, Global CISO, Global Head MSS, Prof. Speaker, TV appearance, Top 10 UK security personality 2010, Compliance guru, AI, Followback Security.
88K Followers 50K FollowingGlobal business technology leader, VP at Forward Edge-AI, and Operations Executive at the National DigiFoundry https://t.co/ZUjjeJqYzh
76K Followers 609 FollowingI'm done with Musk and his Nazis, so I've moved to BlueSky (@allenholub.bsky.social) and LinkedIn (https://t.co/EBnkZ8qUC8). LinkedIn is more lively.
1K Followers 242 FollowingBuilder, infosec, SCA and SAST enthusiast, blue team.
Founder of OWASP dependency-check.
https://t.co/qXHWC2xdir
https://t.co/9xvA3nLzta
13K Followers 2K FollowingPresident @Infosecdiversty @infoseckids, Chair @owasp, RB @Blackhatevents ASIA @devseccon, #DevRel 🥑@snyksec Tweets are my own
386K Followers 622 FollowingLove Linux/Unix, open source, and programming? Into Sysadmin & DevOps? Follow us! Boost your IT career with daily new tools, apps, and humor ⤵️
7K Followers 655 FollowingAppSec Expert with over 15 yrs of experience | Author of 2 books and Black Hat Trainer | Building the world's best Security Training Platform, @AppSecEngineer
17K Followers 601 FollowingHead of Application Security focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.
275K Followers 447 FollowingCo-Founder of ByteByteGo | Author of the bestselling book series: ‘System Design Interview’ | YouTube: https://t.co/9gPSJSrtPU
141K Followers 139 FollowingWorking on a new terminal: Ghostty. 👻 Prev: founded @HashiCorp. Created Vagrant, Terraform, Vault, and others. Vision Jet Pilot. 👨✈️
30K Followers 258 FollowingBuilding crap with AI. Co-Founder @Obots_ai
Formerly @Rancher_Labs. k3s Creator. Member of The Church of Jesus Christ of Latter-Day Saints
13K Followers 1K FollowingOn a mission to help developers & operators be successful with Kubernetes, Cloud Native, Nix, Rust, and Server-Side WebAssembly.
He / Him / Husband / Father
18K Followers 4K FollowingNo time for trolls so play nicely or youI’ll be blocked. Sticking around until the bitter end, but you can find me on https://t.co/ltWpCrdm4O . He/him.
14K Followers 2K Followingsecurity! personal account. views are that of rustic australian countryside. nothing is an endorsement. why do you hate fun? for educational purposes only.