We are all made of stars, but your RBAC shouldn’t be
Day two at #Kawaiicon :D
(watch the livestream here: kawaiicon.org/livestream/)
Here's the link to the #Kawaiicon livestream if anyone wants to attend remotely, starting soon: www.twitch.tv/kawaiiconnz
Oh wow! I’ve missed Danner megathreads!
To implement robust mitigations across Geomys, I did a survey of open source project compromises in 2024/2025.
Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided.
words.filippo.io/compromise-s...
> Long-lived credential exfiltration
OpenSSF's Trusted Publishing is a partial solution here. repos.openssf.org/trusted-publ...
i.e. NPM recommends disabling long-lived credential publishing once Trusted Publishing is activated
docs.npmjs.com/trusted-publ...
Special 40th edition of @phrack.org at @bsidescbr.bsky.social #bsidesCBR
$9!! That’s an expensive visit 😝
For those in Melbourne, Ruxmon is on tomorrow:
www.meetup.com/ruxmon/event...
Excuse me. How have I missed the grimace-posting?!
@berduck.deepfates.com
_
<(o )___
( ._> /
`----'
Genuinely quite cool: github.com/threatcl/thr... + LLM to automatically generate threat models as code @xntrik.wtf
I know right!! Also, only 10% of the audience was permanently blinded by the lasers. Big improvement from last year!
A+ Dad Joke game:
“It’s only officially called Formal Threat Modelling if you’re wearing a tuxedo” - the Tao of @xntrik.wtf
When the vuvuzela harmonies joined in… truly sublime. Brought a tear to my eye
Back due to popular demand! For those that missed yesterday’s talk… bsky.app/profile/fre....
Xntrik on stage at CyberCon
@xntrik.wtf on stage once again for an interpretive dance/drum solo encore!
You need an updated profile pic however mate…
Will there be an encore to the drum solo?
Truly inspirational drum solo mate, thank you
bsky.app/profile/fre....
I’m still wrapping my head around his metaphor of:
“Extra extra small spandex bike shorts: 3 lessons this taught me about B2B sales & post-breach incident response at a large professional social media tech company”
Xntrik on stage
Front row seats for @xntrik.wtf’s CyberCon Keynote!
It was a pleasure to hear about his long & illustrious career.
The 17-minute avant-garde- jazz drum solo certainly was… certainly unique!