Tony Torralba
@_atorralba
Breaking builds and building breakages. He/him. ProdSec Engineer @okta. Opinions are my own. Mastodon: infosec.exchange/@atorralba
ID: 442612877
https://atorralba.github.io 21-12-2011 08:45:54
326 Tweet
401 Followers
370 Following
Ever wondered how the GitHub Security Lab performs security research? Find out how they leverage code scanning, CodeQL, Codespaces and moreš ā¬ļø github.blog/2024-04-03-secā¦
This is my favorite kind of talk: great storytelling, cool visuals, technically interesting scenarios, and inspiring discourse. Consider me impressed Jason Lang :D youtube.com/watch?v=i2cJ1vā¦
Happy to share that Alvaro MuƱoz and I will be presenting our talk "Finding vulnerabilities at scale in Jenkins plugins with CodeQL" at BSides Barcelona, happening on May 29-30. Join us to learn about CodeQL, vulnerability research at scale, and the Jenkins plugin ecosystem!
šØ New Blog Alert! šØ Can an attacker execute commands by sending JSON? Learn how unsafe deserialization vulnerabilities in Ruby can be exploited and how they can be detected with CodeQL. š Read the full post: github.blog/2024-06-20-exe⦠Stay safe and code responsibly! š”ļøš»
Security in Action(s): extending CodeQL to detect Workflow vulnerabilities š¤ Ćlvaro MuƱoz Protege tus pipelines de CI/CD con detección avanzada de vulnerabilidades en GitHub Actions. --- SALA A2 - MiĆ©rcoles 13 Noviembre de 14:45 a 15:30 hs Ekoparty | Hacking everything CEC Buenos Aires