Jean-Baptiste Maillet
jbm@infosec.exchange
<p>Hardcore embedded C/C++ caveman.<br />Supply chain cybersecurity, SBOM , vulnerability management.<br /><a href="https://infosec.exchange/tags/embedded" class="mention hashtag" rel="tag">#<span>embedded</span></a> <a href="https://infosec.exchange/tags/linux" class="mention hashtag" rel="tag">#<span>linux</span></a> <a href="https://infosec.exchange/tags/oss" class="mention hashtag" rel="tag">#<span>oss</span></a> <a href="https://infosec.exchange/tags/psirt" class="mention hashtag" rel="tag">#<span>psirt</span></a></p>
Posts
-
Post #4481134
RE: https://mastodon.social/@bouletcorp2/117061351342436113 Dilemme moral de l'utilisateur d'intelligence artificielle.
-
Post #3133394
Anyone can now declare a KEV to the CISA. #CISA #KEV
-
Post #3133393
A juicy report that, sadly, won&#39;t teach you much if you&#39;re in the vulnerability management business. At least, you can say: &quot;see? I told you&quot; 🤬 https://cyberscoop.com/nist-nvd-audit-mismanagement-duplication/?utm_campaign=CyberScoop%20-%20Edito
-
Post #3133392
RE: https://mastodon.social/@andrewnez/116674596440323949 Some pearls of wisdom here. 😂 My favs: * Defense in depth: coding. * Attack surface: your code. * Blast radius: everyone else’s code. * Shift left: make it the developer’s problem. * Compensating control: we didn’t fix it. * Risk acceptance: we didn’t fix it, in writing.
-
Post #3133391
RE: https://mastodon.social/@CVE_Program/116686502518980062 2,000+ CVE in a CISA weekly bulletin? Unless I&#39;m mistaken this is the all-time record (so far). 🤯 #cve
-
Post #1157678
I&#39;ll be at the VulnCon next week (remotely that is, from Paris). Maybe we&#39;ll met in the chats? https://www.first.org/conference/vulncon26/ #vulncon26