we45

2.6K posts

we45 banner
we45

we45

@we45

We are your partners in product security. Creators of @appsecengineer and @orchestronio. AppSec Training | Cloud & Kubernetes | Threat Modeling | DevSecOps

United States Beigetreten Kasım 2009
280 Folgt1.2K Follower
we45
we45@we45·
This is DevSecOps at machine speed. AI isn’t adding noise — it automates the basics, prioritizes real risk, and responds before issues escalate. One pipeline. Continuous security. Adaptive defense. Scaling without slowing delivery? Let’s connect.
we45 tweet media
English
0
0
0
15
we45
we45@we45·
Big milestone for us at @we45. We’re now a CREST-accredited Penetration Testing service provider — aligning our offensive security services with globally recognized standards. Onward to raising the bar in application security.
we45 tweet media
English
0
0
1
50
we45
we45@we45·
Want security that’s built to scale with your business, not slow it down? AI-driven Threat Modeling is the future of scalable AppSec. It’s faster, smarter, and always on. Here’s why it’s a game-changer for modern DevSecOps teams.
we45 tweet media
English
0
0
0
32
we45
we45@we45·
Scaling DevSecOps isn’t about more tools — it’s about the right sequence. 70% prioritize it. <40% automate security in CI/CD. The gap? Baselines, pilots, automation-first thinking, and teams that own security. #DevSecOps
we45 tweet media
English
0
0
0
37
we45
we45@we45·
From pentest orchestration to secure-by-default development — Ship Week is about rethinking how security actually works. Huge appreciation to our team for building tools that move security upstream.🔥 More coming.
Abhay Bhargav@abhaybhargav

"You can't scan your way out of bad security design" Is something I hear a lot from some of my biggest customers. They get it. Security needs to be baked in. Not sprinkled on as an afterthought. Even before vibe-coding this was hard to do. Teams struggled with security design reviews and threat models continuously as part of their backlog. I know firsthand. I helped build out "story-driven threat modeling" as a practice area. With vibe-coding, that problem has now gone turbo. Agents are writing code at massive scale. Developers really dont know what is being written. The whole system leads to a perfect storm of bad security decisions that compound downstream effects adversely. "We can run SAST on every commit", some people say. Yes, you can. But you'd then be inundated with security issues in code. But even if it were effective, is it enough? What about issues with your authorization design? The way you've implemented cryptography? The approaches you've taken to do validation? Have you implemented validation even? This is why vibe-coding needs vibe-security reviews. This happens when your AI IDE/Agent includes the capability to perform threat models and security reviews for the features you type into your agent as a prompt. It should analyze the security impact of it using methodology built for agents (our PWNISMS approach) and write code based on a plan that has security baked in. This is why I feel SecurityReview-Kit from @secreview_ai is so powerful. It helps you in Agent mode, it helps you design secure features in Planning mode across IDEs like @cursor_ai . Our latest drop on Ship-Week. I bring you SecurityReview-Kit

English
0
0
0
110
we45
we45@we45·
Ship Week at @we45🚢 Meet O2 — our AI-powered Pentest Orchestrator. Not a smarter scanner. Not blind spray-and-pray. O2 maps real attack paths, generates risk-based test cases, enables live validation, & blends AI with human depth. Watch @abhaybhargav demo PTaaS done right👇
Abhay Bhargav@abhaybhargav

First on the list in our Ship Week is our new PTaaS offering from @we45 . We take App Pentesting to the next level with a combination of ai offensive threat modeling + ai native pentesting delivering high quality, web and API pentesting as a service. Take a look! Give us a shout if you’d want one. Our customers have started using our O2 platform and results have been very positive!

English
0
0
0
122
we45
we45@we45·
Your AI didn’t misbehave. It trusted the wrong context. MCP security is about protecting how models see and act on information.
we45 tweet media
English
0
0
0
27
we45
we45@we45·
Your AI model might not crash when attacked. It might just… respond incorrectly. That’s why AI model security testing is about behavior, not breakage.
we45 tweet media
English
0
0
0
27
we45
we45@we45·
Think your dependencies are safe because they’re “popular”? Think again. 18 widely used npm packages—downloaded billions of times—were hijacked. Trust became the attack vector. How confident are you in the supply chain behind your code?
we45 tweet media
English
0
0
1
38
we45
we45@we45·
AI agents are already plugged into your systems, querying data, triggering workflows, and making decisions. But they don’t behave like users, and your existing security stack isn’t built to stop them.
we45 tweet media
English
0
0
0
26
we45
we45@we45·
Sending warm holiday wishes to you and your loved ones. Hope this season brings happiness, rest, and cheer. 🎄
English
0
0
0
23
we45
we45@we45·
Worth watching if Claude Code is used in your environment. Permissions, sandboxes, MCP tools, and threat modeling — all explained clearly. 👉 youtu.be/0UrYqScyjLE
YouTube video
YouTube
Security Blueprint Society@sec_blueprint

Claude Code is powerful — but only if it’s secured properly. @abhaybhargav breaks down permissions, sandboxing, MCP tools, and how to threat model @claudeai Code and the Claude Agent SDK. If AI writes and runs code, it needs a security model. youtu.be/0UrYqScyjLE

English
0
0
0
113
we45
we45@we45·
As multi-cloud adoption grows, so do its challenges. From AWS to GCP to Azure, organizations are juggling unique implementations while trying to maintain robust security. Sound familiar? Here’s the good news: a centralized and simplified approach works best.
we45 tweet media
English
0
0
0
21
we45 retweetet
SecurityReviewAI
SecurityReviewAI@secreview_ai·
Thank you to the @SANSInstitute for the recognition and to every single person who voted for us. This win motivates us even more to keep building, improving, and pushing the boundaries of application security. Let’s keep going! 💪
SANS Institute@SANSInstitute

The Innovation of the Year Award goes to the individual or team who uses unique approaches to succeed through innovation and risk-taking and/or creating an open-source tool of significant value. This year's Community Winners are the team for @secreview_ai! Congratulations! 👏 #SANSDMA

English
1
2
3
224
we45
we45@we45·
Cybercriminals love weak links in your supply chain. A single compromised vendor can put your entire business at risk. That’s why a proactive approach to supply chain security isn’t optional, it’s essential. Is your security team assessing these risks?
we45 tweet media
English
0
0
0
32
we45
we45@we45·
Wishing you a Diwali filled with light, laughter, and new beginnings. Here’s to brighter ideas, stronger teams, and endless inspiration. ✨
English
0
0
0
26
we45
we45@we45·
To the heroes who won our freedom and the heroes who protect it today, we salute you. 🇮🇳
GIF
English
0
0
1
37
we45
we45@we45·
Prevention. Automation. Collaboration. Burnout happens when security is reactive. Flip the script, and you’ll start seeing progress.
English
0
0
0
25
we45
we45@we45·
4️⃣ Get leadership buy-in. Talk in terms of impact, numbers, and compliance. Yes, you’re selling security. But leadership needs to understand it to support you.
English
1
0
0
23
we45
we45@we45·
Burned-out security teams can’t fix growing backlogs. Here’s how to flip the script, get ahead, and actually prevent security problems. 🧵
English
1
0
1
50