Anant Shrivastava
anantshri.info
Anant Shrivastava
@anantshri.info
300 followers 230 following 120 posts
Researcher | Trainer | Security Professional | Developer | Admin
Posts Media Videos Starter Packs
Reposted by Anant Shrivastava
#DEFCON34 Call for #CTF Organizers is OPEN!

After four excellent years, Nautilus Institute is retiring from running the official #DEFCON CTF. The search is on for the next team. Is it your turn? Is your crew the future of live hacking competitions?

defcon.org/html/links/d...
DEF CON® Hacking Conference - Call for CTF Organizers
Nautilus Institute is passing the torch, will your group be the next CTF Overlords?.
defcon.org
Final hours for Black Hat EU Early Bird! 🚨

Save £300 today and join my 0wning the Cloud training this December in London.

We’ll cover AWS, Azure, GCP, DigitalOcean & Aliyun with hands-on attack + defense labs.

🔗 Register before midnight: www.blackhat.com/eu-25/traini...
Black Hat
Black Hat
www.blackhat.com
We just dropped GH Navigator 🎉
Paired with KeyChecker, it gives full GitHub coverage:

Data plane: what can be read

Control plane: what can be changed

Check out the release post 👉 cyfinoid.com/gh-navigator...
Introducing GH Navigator: Optimizing GitHub Security Tools
Discover how GH Navigator and KeyChecker enhance GitHub security by providing visibility and testing for both data and control planes.
cyfinoid.com
Reposted by Anant Shrivastava
Everyone talking about npm hacks. But is it really more attacks or just more visibility?

Maybe attackers are piling on npm
Maybe the ecosystem is just easier to monitor
Maybe sloppy practices make it an easy catch

What nags me more: silence in PyPI, RubyGems, Maven.
No attacks, or no one looking?
am i the only one who goes like lets finish all updates on one version then do version upgrade.
Reposted by Anant Shrivastava
#BSidesLDN205 Call for Workshops is still open!
Want to pass on the knowledge you have?

Here's your chance: cfp.bsides.london/bsides-londo...
Any topic.
2-4hrs long
Not a commercial presentation
30 people minimum audience (mixed experienced levels)

#Security #BSIdes #London
Reposted by Anant Shrivastava
To all of the people pushing hard to coin the term “vibe security,” the joke is on you. Security has always been about vibes. 😆
Most say ‘think like a hacker,’ but infosec fights adversaries with goals, not curiosity. Real defense means blending hacker creativity with adversary realism.
Hacker Vs Adversary
Most say ‘think like a hacker,’ but infosec fights adversaries with goals, not curiosity. Real defense means blending hacker creativity with adversary realism.
blog.anantshri.info
Readwise reader is replacing google reader for me plus some more stuff.
Reader.readwise.com
Its funny how current ai tooling plays out and a few years ago self help courses use to use this same tactic. We are giving you tool if you dont use it properly it will not give you result. So user pays you for stuff and if it doesnt work its their problem not yours.
Making Security Tools Accessible: Why I Chose the Browser

Tired of tools that need Docker to read a JSON file? I built browser-native, client-side tools like SBOMPlay and 3ptracer to prove you don’t need servers, tracking, or setup. Just open index.html and go. Minimalist, secure, and surprisingly…
Making Security Tools Accessible: Why I Chose the Browser
Tired of tools that need Docker to read a JSON file? I built browser-native, client-side tools like SBOMPlay and 3ptracer to prove you don’t need servers, tracking, or setup. Just open index.html and go. Minimalist, secure, and surprisingly powerful.
blog.anantshri.info
Vibe coding with AI feels magical until your project spirals into chaos. This guide explores how to stay grounded while building with AI tools; covering minimalism, context limits, testing, & code hygiene. A practical read for developers navigating the fine line between productivity & hallucination.
A Rational Survival Guide to Vibe Coding with AI
Vibe coding with AI feels magical until your project spirals into chaos. This guide explores how to stay grounded while building with AI tools, covering minimalism, context limits, testing, and code hygiene. A practical read for developers navigating the fine line between productivity and hallucination.
blog.anantshri.info
If anyone here is already on @peerlist.bsky.social connect with me and if you are not signup here peerlist.io/anantshri/si... seems like a fun place especially if you want to be connected to builders.
Anant has invited you to join Peerlist!
peerlist.io
As i finalize my "Attack and Defend Software Supply Chain" Training. I am sprinkling newer content and one of the thing would be AI supply chain attacks.

Join me @ Defcon 2025 : training.defcon.org/collections/...

for a deep dive into the amazing world of software supply chain security.
I can understand your side of concern too. its not about who is right or wrong. we all look at the elephant from our sides. Now a days i tell the camera person to keep the camera not too tight, i try to stick within a big box of 4-5 fts to allow movement yet stable but i ensure i stand in center.
however if I as a speaker is part of the whole game then its like performance art you cant ask an artist to stick to conforming norms, they need to be able to freely express themselves. and walking is one way of expression.

hope that makes sense.