Some highlights for me:
Some highlights for me:
You can check them out on the @BounceSecurity website now!
You can check them out on the @BounceSecurity website now!
You still have time to sign up for my updated course at @blackhatofficial.bsky.social #BHUSA, in person in Las Vegas, August 4-5.
You still have time to sign up for my updated course at @blackhatofficial.bsky.social #BHUSA, in person in Las Vegas, August 4-5.
In my next blogpost, I talk about writing a proposal which appeals to both the review board and also your potential attendees.
Check it out here:
www.bouncesecurity.c...
In my next blogpost, I talk about writing a proposal which appeals to both the review board and also your potential attendees.
Check it out here:
www.bouncesecurity.c...
I wrote more about it here:
www.linkedin.com/pos...
I wrote more about it here:
www.linkedin.com/pos...
Unless you Accelerate your AppSec Programme, you are going to get left behind..
Join me @blackhatofficial.bsky.social #BHUSA this summer in Las Vegas (4-5 Aug) for a practical guide on how to build bridges with developers and build securely!
Unless you Accelerate your AppSec Programme, you are going to get left behind..
Join me @blackhatofficial.bsky.social #BHUSA this summer in Las Vegas (4-5 Aug) for a practical guide on how to build bridges with developers and build securely!
My latest post dives into creative ways to get students' hands dirty, from cloud-hosted labs to simulated stakeholder exercises. Learn how to make practical exercises the highlight of your course, not just an afterthought.
My latest post dives into creative ways to get students' hands dirty, from cloud-hosted labs to simulated stakeholder exercises. Learn how to make practical exercises the highlight of your course, not just an afterthought.
But how did I get to this stage?
The short answer is a lot of thought and hard work.
And the long answer?
Well I thought I'd write some thoughts down...
🧵 1/x
But how did I get to this stage?
The short answer is a lot of thought and hard work.
And the long answer?
Well I thought I'd write some thoughts down...
🧵 1/x
This course helps you build a successful programme to bridge the gap between developers and security, without losing speed.
4/5
This course helps you build a successful programme to bridge the gap between developers and security, without losing speed.
4/5
If you want to build effective and valuable processes around tools like SAST, DAST and SCA, this is the course for you.
2/5
If you want to build effective and valuable processes around tools like SAST, DAST and SCA, this is the course for you.
2/5
Want to hear more? Keep reading...
1/5
Want to hear more? Keep reading...
1/5
This course helps you build a successful programme to bridge the gap between developers and security, without losing speed.
4/5
This course helps you build a successful programme to bridge the gap between developers and security, without losing speed.
4/5
If you want to build effective and valuable processes around tools like SAST, DAST and SCA, this is the course for you.
2/5
If you want to build effective and valuable processes around tools like SAST, DAST and SCA, this is the course for you.
2/5
Want to hear more? Keep reading...
1/5
Want to hear more? Keep reading...
1/5
And where is my Right-Ctrl!!!
And where is my Right-Ctrl!!!
Eliminate entire classes of vulnerabilities in your app by learning which findings from your SAST are always nonsense and ignoring them...
Eliminate entire classes of vulnerabilities in your app by learning which findings from your SAST are always nonsense and ignoring them...
Some of it is more relevant when contracting but a lot of it is relevant to internal people as well.
Some of it is more relevant when contracting but a lot of it is relevant to internal people as well.
On a scale of 1 to 10, how high would you rate the risk for: "library is hosted on SourceForge"
Is the library considered "end of life"?
Never mind that, is the platform which hosts it considered "end of life"....?!?!?
On a scale of 1 to 10, how high would you rate the risk for: "library is hosted on SourceForge"
Is the library considered "end of life"?
Never mind that, is the platform which hosts it considered "end of life"....?!?!?
There are some nuances that got lost in this story but overall I think this is a positive thing for the Semgrep engine.
There are some nuances that got lost in this story but overall I think this is a positive thing for the Semgrep engine.