James Berthoty (@jamesberthoty) 's Twitter Profile
James Berthoty

@jamesberthoty

Security Engineer Turned Analyst @latiotech

ID: 3237609351

calendar_today06-05-2015 01:42:15

274 Tweet

367 Followers

397 Following

James Berthoty (@jamesberthoty) 's Twitter Profile Photo

AppSec hates this one easy trick: x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware you're not allowed to do that!

James Berthoty (@jamesberthoty) 's Twitter Profile Photo

Plenty of good content out there on 𝗶𝗻𝗴𝗿𝗲𝘀𝘀-𝗻𝗶𝗴𝗵𝘁𝗺𝗮𝗿𝗲 ⛈️ 😱 but I didn't think any of it really broke down in plain English what the vulnerabilities are and what your exposure is like, so I wanted to make a video showing it. youtu.be/9U222M-oAJQ

James Berthoty (@jamesberthoty) 's Twitter Profile Photo

The Latio AI security scanner has been updated to use ✨ agentic AI ✨ so you can test the differences these approaches make: github.com/latiotech/LAST

James Berthoty (@jamesberthoty) 's Twitter Profile Photo

I'm convinced about.01% of people talking about MCP clients and servers have tried making one or, even worse, getting someone to use theirs. It's gonna be a little bit before these things take off, and in my opinion it's really a race to be baked into the most popular clients.

James Berthoty (@jamesberthoty) 's Twitter Profile Photo

Extended the PoC of CVE-2025-32433 to test runtime tools by having it run in Kubernetes and grab environment variables github.com/latiotech/inse…

James Berthoty (@jamesberthoty) 's Twitter Profile Photo

Spent two hours today troubleshooting with cursor and then finally just read the code and fixed it in 15 minutes. Vibe coding rules!