Michele Spagnuolo's Avatar

Michele Spagnuolo

@miki.it

πŸ’Ό: Staff Information Security Engineer at Google. πŸ› οΈ: Rosetta Flash, BitIodine. πŸ’›: web security, ⟠, β‚Ώ, finance. Data is the most dangerous form of opinion.

903
Followers
1,116
Following
3
Posts
17.11.2024
Joined
Posts Following

Latest posts by Michele Spagnuolo @miki.it

Preview
Security Signals: Making Web Security Posture Measurable At Scale

Excited to present Security Signals with @ddworken.bsky.social and @webappsec.dev, my primary project at Google for the past five years. Thanks, @madwebwork.bsky.social!

Paper: research.google/pubs/securit...
Slides: speakerdeck.com/mikispag/sec...

01.03.2025 07:51 πŸ‘ 12 πŸ” 4 πŸ’¬ 0 πŸ“Œ 1
CyberChef The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

One of the best tools I've seen to convert between various encodings.

Thanks @miki.it for suggesting it.

gchq.github.io/CyberChef/

14.12.2024 09:06 πŸ‘ 9 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

That's nice!

22.11.2024 14:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Security Signals: Making Web Security Posture Measurable At Scale

Happy to publish the effort of my last five years: Security Signals.

research.google/pubs/securit...

17.11.2024 13:02 πŸ‘ 27 πŸ” 7 πŸ’¬ 0 πŸ“Œ 1

I'm in the process of creating a *web security* starter pack and need your help finding more webbies here. Please share and recommend folks passionate about web security in comments below so we can get this community started here πŸ™‚
go.bsky.app/Uf8dZhz

17.11.2024 10:12 πŸ‘ 55 πŸ” 25 πŸ’¬ 16 πŸ“Œ 0
Post image

1/ X's algorithm was changed in mid-July 2024 to systematically boost Republican-leaning accounts and Elon Musk's own account following his endorsement of Donald Trump, according to a newly released computational study of engagement from the Queensland University of Technology.⬇️

16.11.2024 10:39 πŸ‘ 7109 πŸ” 3018 πŸ’¬ 282 πŸ“Œ 606

XSS vulnerabilities keeping you up at night? 😱 Google's new "Commitment to Secure by Design" whitepaper has answers! Safe Coding and web platform improvements are key. Read more (page 7):
static.googleusercontent.com/media/public...

16.11.2024 21:31 πŸ‘ 8 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Retrofitting Spatial Safety to hundreds of millions of lines of C++ Posted by Alex Rebert and Max Shavrick, Security Foundations, and Kinuko Yasada, Core Developer Attackers regularly exploit spatial mem...

Excited to share our latest blog post on memory safety! We’re tackling spatial safety in our massing C++ codebase by hardening live++ by default. It adds bounds checks to things like std::vector, preventing a fair bit of out-of-bounds vulnerabilities: security.googleblog.com/2024/11/retr...

15.11.2024 19:02 πŸ‘ 28 πŸ” 8 πŸ’¬ 1 πŸ“Œ 1