Paul

2.5K posts

Paul banner
Paul

Paul

@ismisepaul

Application Security | Software Dev | DevSecOps | Contributor @OwaspShepherd | @[email protected] #appsec #devsecops #infosec #owasp

Baile Átha Cliath, Éire Katılım Şubat 2009
980 Takip Edilen330 Takipçiler
Paul retweetledi
Tib3rius
Tib3rius@0xTib3rius·
THEY MADE A WORM IN NPM THEY MADE A WORM IN NPM THEY MADE A WORM IN NPM THEY MADE A WORM IN NPM THEY MADE A WORM IN NPM
English
70
151
2.1K
240.6K
Paul retweetledi
JFrog Security
JFrog Security@JFrogSecurity·
🚨We're continuing to track the unfolding compromise of npm packages with a new data exfiltrating malware, in the new campaign dubbed Shai Hulud. Our monitoring infrastructure has detected 31 additional malicious packages with the same payload with hundreds of versions. New malicious packages are still being uploaded continuously, follow this thread to get the latest news on this ongoing campaign as it unfolds.
English
6
158
293
42.5K
Paul retweetledi
Charlie Marsh
Charlie Marsh@charliermarsh·
Oh wow, a popular GitHub Action (tj-actions/changed-files) was fully compromised. Someone committed a base64-encoded payload that runs a script that in turn prints out encoded secrets… Stay safe out there!
English
31
335
2.5K
498.1K
Paul retweetledi
Thomas Roccia 🤘
Thomas Roccia 🤘@fr0gger_·
🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)! I hope it helps to make sense of the information out there. Please treat the information "as is" while the analysis progresses! 🧐 #infosec #xz
Thomas Roccia 🤘 tweet media
English
100
3.1K
12.4K
1.1M
Paul retweetledi
Matt Johansen
Matt Johansen@mattjay·
A new container escape vulnerability just dropped. It gives an attacker the ability to hop from container to host OS via runc.
GIF
English
7
239
1K
153.3K
Paul retweetledi
Daniel Lemire
Daniel Lemire@lemire·
We should reject the culture of laziness and/or incompetence. "Some tool somewhere report something and so we must do what it suggests right away". Yes. We care about security. Yes. We care about bugs. Yes. We want good tools, good reports. But blindly following flags and tools? No. It does not make you safer. Take time to understand the issues first.
English
4
5
48
27.7K
Paul retweetledi
Steve Wilson
Steve Wilson@virtualsteve·
It's official! Version 1.0 of the OWASP Top 10 for LLMs is here covering the top security risks for AI developers today. Please check it out! linkedin.com/pulse/official…
English
2
34
68
10.4K
Paul
Paul@ismisepaul·
@zaproxy Best of luck folks!
English
0
0
3
488
Paul retweetledi
Chainguard ⛓️
Chainguard ⛓️@chainguard_dev·
Elastic enlisted us to engage in an assessment of their software supply chain using the SLSA framework-- the largest one we've done to date! 🌟 chainguard.dev/unchained/elas…
Chainguard ⛓️ tweet media
English
0
8
18
2.7K
Paul retweetledi
Gareth Rushgrove
Gareth Rushgrove@garethr·
I wrote some code! Introducing Parlay, a CLI tool for enriching an SBOM with extra information about the compinents github.com/snyk/parlay
English
3
9
36
13.7K
Paul retweetledi
Dan Lorenc
Dan Lorenc@lorenc_dan·
The hardest problem in supply chain security is explaining what supply chain security is.
English
12
8
56
14.9K