Denis Makrushin

1.6K posts

Denis Makrushin banner
Denis Makrushin

Denis Makrushin

@makrushind

Here to save the world. Tweets are my own. https://t.co/J4fzcKzcMO

Se unió Kasım 2009
622 Siguiendo11.1K Seguidores
Denis Makrushin
Denis Makrushin@makrushind·
Most clouds share one access layer across regions. One breach, lateral movement everywhere. We made fully autonomous regions with shadow org that auto-replicates all resources. No difference for UX. Patented. Compromising the area gives attacker nothing. yandex.cloud/ru/blog/multir…
English
0
0
0
141
Denis Makrushin
Denis Makrushin@makrushind·
AI agents ship and test code in production. Next frontier: trustworthy across SDL. RepoAudit reduces LLM hallucinations by feeding data-flow paths instead of raw code, reducing false positives and improving agentic code review. Binary analysis is coming: repoaudit-home.github.io
English
1
0
1
195
Denis Makrushin
Denis Makrushin@makrushind·
It’s time to move beyond 'shift left'. The next strategic move is 'shift down', embedding security directly into dev platforms. So, let's define the 2026 agenda for security leaders: bring security controls closer to dev platforms.
Denis Makrushin tweet media
English
0
0
1
167
Denis Makrushin
Denis Makrushin@makrushind·
A small step in the large open-source: CVSS integration in Trivy. At the heart of our #AppSec platform is an open-source SCA project called Trivy. This time, we are not only integrating, but also contributing: in Trivy 0.65.0 release we added the CVSS vector support.
Denis Makrushin tweet media
English
0
0
1
273
Denis Makrushin
Denis Makrushin@makrushind·
Secret detection is easy in single repo and deterministic pattern. It gets tricky at enterprise scale monorepos + non-deterministic strings. We benchmarked engines, mapped their limits and defined use-cases with highest precision/recall/perf: medium.com/p/0cf351e74250 #AppSec
English
0
0
0
250
Denis Makrushin
Denis Makrushin@makrushind·
Advanced Research Review 2024 Let's review last year's perspective research reports. Use the knowledge to refine your strategies, strengthen defenses, and take your findings forward in 2025. makrushin.com/advanced-resea…
English
0
0
1
212
Denis Makrushin
Denis Makrushin@makrushind·
I've compiled a collection of vulnerabilities and an overview of attack methods against Github users identified in 2024. The material will be helpful for both developers, #devsecops and #appsec engineers in protecting their projects. medium.com/yandex/securit…
English
0
0
1
261
Denis Makrushin
Denis Makrushin@makrushind·
Together with the Bauman Moscow State Technical University team, we've upgraded the "Information Security" program, equipping developers with new superpowers. By students, for students—with a “secure-by-design” mindset from day one.
Denis Makrushin tweet media
English
0
0
2
291
Denis Makrushin
Denis Makrushin@makrushind·
report_v.2023.4: release candidate Sit next to me. Let's discuss and prepare our annual report. Highlight the ones that made you feel the most, not just list the results. Let's do it in “parameter: value” format. linkedin.com/posts/makrushi…
English
0
0
0
361
Denis Makrushin
Denis Makrushin@makrushind·
ML models have proven effective in automating the onboarding process, saving 30 out of 50 hours of experienced staff time per new hire by generating training content based on job descriptions and internal materials.
Denis Makrushin tweet media
English
0
0
0
313
Denis Makrushin
Denis Makrushin@makrushind·
On time management for leaders: "it is not time but energy that should be managed" and "in intellectual work, inspiration is much more important than time".
Denis Makrushin tweet media
English
1
0
0
454
Denis Makrushin
Denis Makrushin@makrushind·
Weekend in Serbia: CTO Day From the closed-door event in Belgrade, which brings together CTOs of IT companies every year, here are my takeaways.
Denis Makrushin tweet media
English
1
0
0
961
Denis Makrushin
Denis Makrushin@makrushind·
eBPF program debugger On the way from a small script to a full-fledged application developer spends half his time on debugging. The tool is useful for anyone developing security and observability applications based on eBPF. Credits to Alex Kalinin. github.com/ph1048/ebpfdbg
English
0
0
3
340