Ken Johnson

8.7K posts

Ken Johnson banner
Ken Johnson

Ken Johnson

@cktricky

Co-Founder & CTO @DryRunSecurity. AppSec. BJJ Black Belt. Podcast: https://t.co/lNWxkUndEZ. - '85 Champion Chubby Winner.

Northern VA Katılım Haziran 2009
2.3K Takip Edilen4K Takipçiler
Ken Johnson retweetledi
DryRun Security
DryRun Security@dryrunsec·
PR FEEDBACK IS LIVE IN DRYRUN SECURITY 🔥🔥🔥 When a security finding shows up in a pull request, it shouldn’t turn into a side quest. PR Feedback closes that loop. Now when DryRun Security flags something, developers can reply directly in the thread to mark a false positive or nitpick. DryRun updates the findings instantly, regenerates the PR summary, and logs the action for a clean audit trail. No tickets to file. No separate workflow to manage. No chasing someone down to clear it. Read how it works → dryrun.security/blog/security-…
DryRun Security tweet media
English
0
2
3
194
Ken Johnson retweetledi
DryRun Security
DryRun Security@dryrunsec·
Next week, @jcran and @cktricky are doing Security Reviews, IRL: a live GitHub PR walkthrough with real agent-generated changes (Claude, Cursor, Devin) and the logic flaws that almost shipped. 🗓️ Join us: Feb 25, 1 PM EST Register at dryrun.security/webinar/securi…
DryRun Security tweet media
English
0
3
5
356
Ken Johnson retweetledi
DryRun Security
DryRun Security@dryrunsec·
Developers are already using AI in production, but most AppSec programs were not designed to see or control what happens inside LLM workflows causing blind spots across prompts, generated code, and tool calls. Join this live fireside chat "Code Velocity in an AI-era: How AppSec Teams Can Stay Ahead" with Adam Dyche, @wickett, @cktricky, and Zac F. They will explore how real teams are applying existing AppSec fundamentals to secure AI powered applications without rebuilding their entire stack. 🗓️ Feb 4 | 1:00 PM ET Save your spot and join the conversation 👉 lnkd.in/gpxEBNA9
DryRun Security tweet media
English
0
2
3
193
Ken Johnson retweetledi
DryRun Security
DryRun Security@dryrunsec·
AI did not create entirely new AppSec problems. It changed where they show up. Prompts. Generated code. Tool calls. Model integrations. The risks are familiar. The workflows are not. Join our live fireside chat, Code Velocity in an AI-era: How AppSec Teams Can Stay Ahead, with Adam Dyche with @poweredbyCMRC, @wickett , @cktricky, and Zac Fowler with DryRun Security. They'll unpack how real teams are securing LLM-powered applications without rebuilding their entire AppSec stack. 🗓️ Feb 4 | 1PM ET Register 👉 na2.hubs.ly/H037Qhw0
DryRun Security tweet media
English
0
2
3
189
Ken Johnson
Ken Johnson@cktricky·
I posted this last Friday on LinkedIn, do you disagree? Let me hear you if so 😄
Ken Johnson tweet media
English
1
0
3
160
Ken Johnson retweetledi
Ed Newton-Rex
Ed Newton-Rex@ednewtonrex·
Absolutely brilliant detail from the new Reddit AI copyright lawsuit vs. Perplexity. They set a trap for Perplexity - a test post only crawlable by Google, existing nowhere else on the internet. Within hours, it was on Perplexity 😳 nytimes.com/2025/10/22/tec…
Ed Newton-Rex tweet media
English
98
725
7.3K
521.9K
Ken Johnson
Ken Johnson@cktricky·
Nearly spit out my coffee this morning when I read: "The World’s First Agentic Security Orchestration System" 🤣
GIF
English
0
0
0
75
Ken Johnson retweetledi
DryRun Security
DryRun Security@dryrunsec·
From alert to assurance in minutes. CTO and Co-founder @cktricky walks through how DryRun Security Code Insights MCP helps teams investigate NPM supply chain threats without manual toil, saving hours of effort. Teams use Code Insights MCP to move faster during incidents and reduce noisy, repetitive work from audits to alerts. 👀 Watch the rundown and see how to apply it in your environment.
English
0
4
5
186
Ken Johnson retweetledi
DryRun Security
DryRun Security@dryrunsec·
CodeRabbit RCE wasn’t prompt injection—it was tool execution + isolation drift + secrets exposure. We’ve stumbled too (IDOR in closed beta), which is why our sandboxed approach avoids this class of risk. 🔗Read more: na2.hubs.ly/y0S7hz0
DryRun Security tweet media
English
0
3
4
324
Ken Johnson
Ken Johnson@cktricky·
One of my favorite features and something we've been delivering & improving on for over a year now. I wish this was available to me when I worked as a defender - could have saved us from sooooo many bug bounty submissions.
DryRunSecurity@DryRunSecurity

Still chasing false positives with regex? 😵‍💫 Our NLCPs treat code as context, not just text—so you catch real risk, fast. See how AppSec teams are spotting auth gaps, insecure workflows & PII leaks 🔍 👇 Read the blog na2.hubs.ly/y0kSB50 #AppSec #DevSecOps #AI

English
0
1
2
231