Nir Valtman (@valtmanir) 's Twitter Profile
Nir Valtman

@valtmanir

information security junkie. public speaker. open source fan. co-founder at @ArnicaIO. my publications are my own opinions.

ID: 578869213

linkhttps://valtman.org/ calendar_today13-05-2012 11:11:05

1,1K Tweet

664 Takipçi

215 Takip Edilen

Arnica (@arnicaio) 's Twitter Profile Photo

Lemonade + CISO Jonathan Jaffe have been instrumental in helping Arnica address key issues "most CISOs are dealing with:" • 10x better permissions management • Frictionless access approvals • Easy compliance & reporting • Happy developers! arnica.io/case-studies/l…

Arnica (@arnicaio) 's Twitter Profile Photo

Today on CHAOSS Project's Podcast Arnica's CEO Nir Valtman and Head of Data Science discuss how #opensource projects secure their code! podcast.chaoss.community/65?utm_source=…

Arnica (@arnicaio) 's Twitter Profile Photo

In Arnica's new blog, Eran Medan discusses the different components of software supply chain security and how a zero trust approach can help you secure your development environments more effectively! Check it out 👇 arnica.io/blog/hardening…

Nir Valtman (@valtmanir) 's Twitter Profile Photo

Threat actors identified themselves as recruiters. As part of the interview, they asked each #developer/#devops candidate to install a pre-configured known #opensource software, but the installer included a #malware that stole users’ credentials. arstechnica-com.cdn.ampproject.org/c/s/arstechnic…

Nir Valtman (@valtmanir) 's Twitter Profile Photo

Is it a #softwaresupplychain #security issue? Don't jump into conclusions! Comm100 needs time to investigate the root cause. I encourage them to disclose the results - users will gain #trust, the market will be educated & employees will appreciate it. crowdstrike.com/blog/new-suppl…

Nir Valtman (@valtmanir) 's Twitter Profile Photo

Yet another exploit against the #development ecosystem. This time it’s on #BitBucket. It definitely shows that the tools in the development ecosystem are a good target for #softwaresupplychain #security attacks. …eepingcomputer-com.cdn.ampproject.org/c/s/www.bleepi…

Nir Valtman (@valtmanir) 's Twitter Profile Photo

SBOM SBOM SBOM... this is the time to be excited about the year 2033! Here is a realistic blog post about where #SBOM is today.  lnkd.in/gE2xuCaR

Nir Valtman (@valtmanir) 's Twitter Profile Photo

The 3 quick wins in this article will cost you nothing, except spending 1 hour on pasting the shared code samples, configuring GitHub, and setting up Tines. Any feedback is welcome... #devsecops lnkd.in/gjWW28Tv

Arnica (@arnicaio) 's Twitter Profile Photo

Everything we do at Arnica is oriented toward a future in which software development is unimpeded by risk. TY TechCrunch for detailing a major step along this journey! techcrunch.com/2022/10/31/arn… #softwaresupplychainsecurity #devops #devsecops #codesecurity #shiftleft

OWASP® Foundation (@owasp) 's Twitter Profile Photo

Visit the Arnica Diamond Expo at booth #D11 at the #OWASP 2022 Global AppSec San Francisco event next week! sf.globalappsec.org/schedule/ #appsec #sanfran #security #conference #globalappsec

Visit the <a href="/ArnicaIO/">Arnica</a> Diamond Expo at booth #D11 at the #OWASP 2022 Global AppSec San Francisco event next week! sf.globalappsec.org/schedule/ #appsec #sanfran #security #conference #globalappsec
Nir Valtman (@valtmanir) 's Twitter Profile Photo

What is #pipelineless #security? In short, automated guardrails with all benefits from security scans in IDE, CI/CD pipelines and Checks. #cicdpipelines #devsecops #appsec lnkd.in/gRgKsDPE

Nir Valtman (@valtmanir) 's Twitter Profile Photo

Critique alert: this is how companies should NOT communicate about a #security #breach / #vulnerability What happened? CircleCI published an alert to rotate the #secrets stored in the system. What didn’t happen? - No backgroun…lnkd.in/gAiVmbhb lnkd.in/gDZpBFzw

Arnica (@arnicaio) 's Twitter Profile Photo

Congrats Mike Doyle on being selected as a speaker at @OWASP OWASP Israel ! May 17 @ 13:45 IDT "Introducing SafePackage, an open-source security wrapper for all kinds of package managers that neutralizes malicious dependency attacks against developer ecosystems."

Congrats <a href="/Fe3Mike/">Mike Doyle</a> on being selected as a speaker at @OWASP <a href="/OWASP_IL/">OWASP Israel</a> ! 

May 17 @ 13:45 IDT 

"Introducing SafePackage, an open-source security wrapper for all kinds of package managers that neutralizes malicious dependency attacks against developer ecosystems."
Arnica (@arnicaio) 's Twitter Profile Photo

Last week, Sourcegraph announced a #hack stemming from an admin token being exposed in source code. Over the weekend, we added a custom validator for Sourcegraph tokens. Read more from Arnica CEO Nir Valtman here: arnica.io/blog/how-to-en…

Arnica (@arnicaio) 's Twitter Profile Photo

Securing user access to source code management tools like GitHub doesn't have to come at the expense of #DevEx. Check the latest guide from Arnica CEO, Nir Valtman, on evaluating an Enterprise Managed Users vs. Bring Your Own Users approach. arnica.io/blog/a-complet…

1Password (@1password) 's Twitter Profile Photo

We detected suspicious activity on our Okta instance but confirmed no user data was accessed. Pedro Canahuati, our CTO, provides more information in this blog post blog.1password.com/okta-incident/, which includes our internal Okta Incident Report for additional details.