
Clint Gibler
@clintgibler
๐ก๏ธ Head of Security Research @semgrep
๐ Creator of tldrsec.com newsletter
ID: 720576770
https://tldrsec.com/subscribe 27-07-2012 17:49:39
9,9K Tweet
21,21K Takipรงi
563 Takip Edilen

During RSA week I had the pleasure of interviewing Phil Venables (former Google Cloud & Goldman Sachs CISO) on effectively scaling security programs, how Google leverages AI for security, and more. We discussed: * The challenge of scaling security from artisanal to industrial *





โ๏ธ ๐๐๐ ๐ซ๐:๐๐ง๐๐จ๐ซ๐๐ 2025 ๐๐๐ฅ๐ค ๐๐ฎ๐ฆ๐ฆ๐๐ซ๐ข๐๐ฌ Don't have time to watch 163 talks? โก๏ธ Repo with summaries, transcripts, key points, and other useful insights. Across: * AI/ML security and GenAI * IaC and DevSecOps * IAM * Multi-Account & Enterprise Security *


๐ฌWhat is a Detection Engineer, and how do you become one? New blog series by Datadog, Inc.'s Head of Detection & Research Zack Allen, covering: An overview of what is a detection engineer and how they fit into a cybersecurity function. Within the NIST Cybersecurity Framework


Out of scope, low impact self-XSS got you down? ๐ช ๐๐๐ค๐ ๐๐๐ฅ๐-๐๐๐ ๐๐ซ๐๐๐ญ ๐๐ ๐๐ข๐ง How to transform stored self-XSS into regular stored XSS. Using credentialless iframes and modern browser capabilities. The post walks through examples of CSRF on login forms


Vibe coding IDEs like Cursor, Microsoft Copilot, and RooCode have empowered developers to ship code significantly faster. However, if LLMs produce bugs at the same density per line of code as humans, that means more bugs are being introduced faster than ever. Join Clint Gibler


๐ฟ ๐๐ข๐ฃ๐๐๐ค๐ข๐ง๐ ๐๐ฆ๐๐ณ๐จ๐ง ๐๐ฏ๐๐ง๐ญ๐๐ซ๐ข๐๐ ๐ ๐๐จ๐ซ ๐ฅ๐๐ฎ๐ง๐๐ก๐ข๐ง๐ ๐๐ซ๐จ๐ฌ๐ฌ-๐๐๐๐จ๐ฎ๐ง๐ญ ๐๐ญ๐ญ๐๐๐ค๐ฌ Square's Ramesh Ramani describes six attack patterns leveraging EventBridge's cross-account capabilities for infiltration and exfiltration. AWS


๐๐๐ฑ๐๐๐ง๐๐ก: ๐๐๐ง ๐๐๐๐ฌ ๐๐๐ง๐๐ซ๐๐ญ๐ ๐๐๐๐ฎ๐ซ๐ ๐๐ง๐ ๐๐จ๐ซ๐ซ๐๐๐ญ ๐๐๐๐ค๐๐ง๐๐ฌ? A new benchmark by Mark Vero et al to evaluate LLMs on secure and correct code generation. My initial thoughts: Itโs awesome that they released the code and dataset. Thereโs
