EdOverflow's profile picture. Web developer & security researcher. Senior Pentester @cure53berlin. Author of @securitytxt.

➡️ https://www.linkedin.com/in/edoverflow

Ed

@EdOverflow

Web developer & security researcher. Senior Pentester @cure53berlin. Author of @securitytxt. ➡️ https://www.linkedin.com/in/edoverflow

置頂

After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: rfc-editor.org/rfc/rfc9116. I would like to use this opportunity to thank those who made this possible. Thank you. ❤️

EdOverflow's tweet image. After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: rfc-editor.org/rfc/rfc9116.

I would like to use this opportunity to thank those who made this possible. Thank you. ❤️

Ed 已轉發

The Swiss Federal Government has adopted a report on ethical hacking referencing two @swisscyberstorm 2023 speakers: @EdOverflow and @_oakgul. Read the report here (in German and French): lnkd.in/dye5-qkY Watch all SCS talks here: youtube.com/@swisscybersto… #SCS23 #bugbounty


I will be giving a talk on Coordinated Vulnerability Disclosure (CVD) at Swiss Cyber Storm. If you are interested in attending, please find additional information below.

Speaking @swisscyberstorm 2023 Edwin Foudil (@cure53berlin): “Navigating The Coordinated Vulnerability Disclosure Landscape” Demystifying concepts surrounding CVD and showing solutions to overcome challenges Program: lnkd.in/d52RpEnH Tickets: lnkd.in/eTXQRjnP #SCS23

swisscyberstorm's tweet image. Speaking @swisscyberstorm 2023
Edwin Foudil (@cure53berlin): “Navigating The Coordinated Vulnerability Disclosure Landscape”
Demystifying concepts surrounding CVD and showing solutions to overcome challenges
Program: lnkd.in/d52RpEnH
Tickets: lnkd.in/eTXQRjnP
#SCS23


I have set up a LinkedIn profile if people want to stay connected: linkedin.com/in/edoverflow/.


Ed 已轉發

Where did you first hear about security.txt?


Ed 已轉發

How do you pronounce "security.txt"?


I am working on something fun with @KarimPwnz to address the challenge of repetitive security questionnaires: @BlueMagnetIO (bluemagnet.io).

EdOverflow's tweet image. I am working on something fun with @KarimPwnz to address the challenge of repetitive security questionnaires: @BlueMagnetIO (bluemagnet.io).

Ed 已轉發

Exciting news! @Apple joins the list of companies with a security.txt file. Now, we only need @netflix to complete the FAANG list. 🙌

securitytxt's tweet image. Exciting news! @Apple joins the list of companies with a security.txt file. Now, we only need @netflix to complete the FAANG list. 🙌

I have been playing around with SvelteKit a lot recently. I wrote a short blog post on adding security headers to SvelteKit applications: edoverflow.com/2023/sveltekit…. I might do a more long-form one on the security pitfalls of SvelteKit applications at some point.

EdOverflow's tweet image. I have been playing around with SvelteKit a lot recently. I wrote a short blog post on adding security headers to SvelteKit applications: edoverflow.com/2023/sveltekit….

I might do a more long-form one on the security pitfalls of SvelteKit applications at some point.

Reminder: if you would like to follow my blog via RSS, I have a feed at edoverflow.com/index.xml. :)


Nice blog post by @KarimPwnz on the security implications of command injection in GitHub Actions.

You have command injection in a GitHub Actions workflow. Now what? Read my blogpost on leaking secrets from GitHub Actions workflows: karimrahal.com/2023/01/05/git…



Retweeting this because I know BSides London tickets are hard to come by. :)

Security BSides London: Are you a woman who works (or wants to work) in tech? We have FIVE tickets to give away for the Security BSides London conference, Saturday 10 December. Just DM us to get one. Please RT. @BSidesLondon #BSidesLDN2022 #WomenInTech

controlplaneio's tweet image. Security BSides London: Are you a woman who works (or wants to work) in tech? We have FIVE tickets to give away for the Security BSides London conference, Saturday 10 December. Just DM us to get one.

Please RT.

@BSidesLondon #BSidesLDN2022 #WomenInTech


Ed 已轉發

I love that the Dutch government is actively promoting security.txt and encouraging companies to establish a route for reporting security incidents 😊 /cc @EdOverflow digitaltrustcenter.nl/nieuws/interne…


Ed 已轉發

Where can ethical hackers report vulnerabilities at your organization? Publish a security.txt file and test it with Internet․nl. Check the new @securitytxt test: en.internet.nl/article/securi… @DTC_NL @AlertOnline #cybersecuritymonth

internet_nl's tweet image. Where can ethical hackers report vulnerabilities at your organization? Publish a security.txt file and test it with Internet․nl. 

Check the new @securitytxt test: en.internet.nl/article/securi…

@DTC_NL @AlertOnline #cybersecuritymonth

This looks like a fun chain by @fransrosen. If readers are interested in rapidly checking CSP hosts, I wrote a tool for grabbing them concurrently: github.com/EdOverflow/csp.

EdOverflow's tweet image. This looks like a fun chain by @fransrosen. If readers are interested in rapidly checking CSP hosts, I wrote a tool for grabbing them concurrently: github.com/EdOverflow/csp.

Dropbox disclosed a bug submitted by fransrosen: hackerone.com/reports/1590794 - Bounty: $6,909 #hackerone #bugbounty

disclosedh1's tweet image. Dropbox disclosed a bug submitted by fransrosen: hackerone.com/reports/1590794 - Bounty: $6,909 #hackerone #bugbounty


Loading...

Something went wrong.


Something went wrong.