CISO at @sardineai. Treasurer of @OWASP Board of Directors. (he/him) qatta' mIghtaHghach.

Phoenix, AZ
Joined July 2009
Bil Corry retweeted
🎉GREAT NEWS! #OWASP is hosting our first ever VIRTUAL CAREER FAIR on Feb. 22. Event is complimentary to all job seekers / small fee requested for participating companies. REGISTER TODAY to connect with numerous companies and/or job seekers owaspcareerfair.vfairs.com/ #devsecops
1
4
16
My toothbrush gives me a sad face when I don’t brush long enough. I’m not sure how I feel being shamed by my appliance, but given it isn’t working, I guess I don’t feel THAT bad. I now am tempted to see if I can game the system by letting it run for an hour.
2
Looking for a role in AppSec? Here's a free job fair for job seekers (and it's only a small fee for companies).
Are you looking for a career in cybersecurity or interested in advancing your career, we invite you to join OWASP at our February 2022 Career Fair! Learn more and REGISTER TODAY owaspcareerfair.vfairs.com/ #cybersecurity #devsecops #infosec
Replying to @maddy_mantsch @GOP
This is the history they want taught. (from The Philadelphia Times, March 7, 1897)
Canon sharing how to break their DRM. #lulz petapixel.com/2022/01/09/can…
1
2
Replying to @yaelwrites
Agreed! The book has so many interesting insights, I might re-read it a second time when I’m done.
Replying to @yaelwrites
That looks really interesting! I’m in the middle of ‘Range’ and it is excellent. But given I’m a generalist and not a specialist, I’m biased toward the premise. goodreads.com/en/book/show/4…
1
1
FTC is threatening fines if you don’t remediate your Log4J vulns.
FTC warns companies to remediate Log4j security vulnerability: bit.ly/31oEKxB
1
Replying to @wagatwe
And chocolate, brought to American consumers by exploiting African child slave labor. washingtonpost.com/graphics/…
TIL there’s a ‘strict’ mode for Microsoft’s Authenticode signature verification. It’s off by default and is actively being exploited. Turning it on has the side effect of rendering some executables as untrusted. Fun choice.
A new Zloader #banking trojan campaign is now exploiting the #Microsoft Signature Verification system to evade detection and steal cookies, passwords and other sensitive data. Read details - thehackernews.com/2022/01/ne… It already has over 2,000 victims in 111 countries.
1
At work, we have a dedicated slack channel for this game.
Josh Wardle, a software engineer in Brooklyn, knew his partner loved word games and created a guessing game for the two of them called Wordle. Just over two months after releasing it to the rest of the world, the once-a-day game has over 300,000 players. nyti.ms/32JuOiY
4
Great article on why curl will never have "easter eggs" with important lessons for any project. And if you ever get the chance to meet @bagder, you should, super nice guy and super modest for someone that has code running on Mars. daniel.haxx.se/blog/2021/12/…
2
27
Bil Corry retweeted
Following public consultation, the final version of the EDPB Guidelines on examples regarding data breach notifications is now available here: europa.eu/!Kvc4xU
2
78
11
96
Welcome to Twitter! You may notice “over generalization” is a recurring theme on Twitter given the constraints on message size.
1
Replying to @alfiekohn
Ackward.
3
Bil Corry retweeted
I've officially have spent one year on the OWASP board, and every day that goes by, I'm in awe about what OWASP can accomplish. There are many great security organizations out there.
1
9
20
Tickets are free, hope to see all of you at @CactusCon !
AHHHHH, IT'S HAPPENING; CactusCon 10 registration is open! eventbrite.com/e/cactuscon-1… So excited to have you join us physically or virtually in the new year. #cc10 #cybersecurity
Little know fact about #DontLookUp, Meryl Streep was not supposed to get the role as President. They settled on her as their last choice. (source: youtube.com/XYWq1SP4r-c?t=150)
2
0
Pretty sure it's called the 'pockette'