Craig Ingram (@cji) 's Twitter Profile
Craig Ingram

@cji

Cloud Threat Detection @google. Kubernetes SRC. πŸ¦‹ cji.bsky.social

ID: 144330495

linkhttps://bsky.app/profile/cji.bsky.social calendar_today16-05-2010 00:35:30

5,5K Tweet

1,1K Followers

795 Following

Tim Nguyen (@methodtim) 's Twitter Profile Photo

I lead a team of 100 brilliant Security Engineers so I feel confident to speak with some leadership experience here: Being told you’re wrong by your team is a feature not a bug and should be rewarded with gratitude and praise and never penalized.

Greg Castle (@mrgcastle) 's Twitter Profile Photo

Aditi ran a *very* complex vulnerability management program across several major Google cloud products like GKE and Anthos. She is an excellent TPM and a rare find, if you’re looking to hire a program manager please get in touch with her.

Matthias Luft (@uchi_mata) 's Twitter Profile Photo

Hi friends! I had the privilege of enjoying a bit of funemployment. I'm starting to look for the next adventure and would be excited to have a chat about (EMEA-remote) leadership positions in the product/cloud security space. RTs would be greatly appreciated πŸ™

Hi friends! I had the privilege of enjoying a bit of funemployment. I'm starting to look for the next adventure and would be excited to have a chat about (EMEA-remote) leadership positions in the product/cloud security space. RTs would be greatly appreciated πŸ™
Greg Castle (@mrgcastle) 's Twitter Profile Photo

Google Cloud is hiring security engineers in the Product Security Assurance team (not my team but we work with them closely). Find and fix vulns, help products build in security by default. Seattle and Bay Area. #infosecjobs careers.google.com/jobs/results/1…

KT (@koczkatamas) 's Twitter Profile Photo

Our Linux Kernel 0-day / 1-day "CI/CD" for kernelCTF on Github is up and running. See exploit builds and repros publicly there. βœ…οΈ / ❌️ github.com/google/securit…

Craig Ingram (@cji) 's Twitter Profile Photo

This Sneakers computer press kit floppy from Jonathan Schnittger is such a cool piece of memorabilia from one of my favorite movies. These came out great - thank you Jonny!

This Sneakers computer press kit floppy from <a href="/JonnySchnittger/">Jonathan Schnittger</a> is such a cool piece of memorabilia from one of my favorite movies. These came out great - thank you Jonny!
Anthony Weems (@amlweems) 's Twitter Profile Photo

I've been reverse engineering the xz backdoor this weekend and have documented the payload format and written a proof-of-concept exploit for the RCE. The payloads are signed with an ED448 key, so I patched my own key into the backdoor for testing. :-) github.com/amlweems/xzbot

I've been reverse engineering the xz backdoor this weekend and have documented the payload format and written a proof-of-concept exploit for the RCE. The payloads are signed with an ED448 key, so I patched my own key into the backdoor for testing. :-)

github.com/amlweems/xzbot
Craig Ingram (@cji) 's Twitter Profile Photo

I’m very excited to be speaking at Google Cloud Next β€˜24 about Google Kubernetes Engine Threat Detection with Daniel L'Hommedieu on April 9, 2024. Join the discussion with @GoogleCloud β†’ g.co/cloudnext

I’m very excited to be speaking at Google Cloud Next β€˜24 about Google Kubernetes Engine Threat Detection with <a href="/danlhommedieu/">Daniel L'Hommedieu</a> on April 9, 2024. Join the discussion with @GoogleCloud β†’ g.co/cloudnext
Natalie Godec πŸ‡ΊπŸ‡¦ (@ouvessvit) 's Twitter Profile Photo

"We'll just get it running for now, and see how it goes later" - famous last words πŸ˜‚ First session of the day for me - watching Craig Ingram compromise k8s on GKE #googlecloudnext

"We'll just get it running for now, and see how it goes later" - famous last words πŸ˜‚ First session of the day for me - watching <a href="/cji/">Craig Ingram</a> compromise k8s on GKE  
#googlecloudnext
Google Cloud Security (@googlecloudsec) 's Twitter Profile Photo

Today our Cloud Vulnerability Research (CVR) team shared this research into LLM security, which is broadly applicable to AI domain security practitioners working in this rapidly evolving space. Learn more: bit.ly/3TWYrF3

Craig Ingram (@cji) 's Twitter Profile Photo

Thank you for the care package jericho and congrats on 25 years! The top sticker is very fitting given my current relationship with the neighborhood squirrels and my bird feeder.

Thank you for the care package <a href="/attritionorg/">jericho</a> and congrats on 25 years! The top sticker is very fitting given my current relationship with the neighborhood squirrels and my bird feeder.