Elektrine lite

← Feed

Jean-Baptiste Maillet

jbm@infosec.exchange

<p>Hardcore embedded C/C++ caveman.<br />Supply chain cybersecurity, SBOM , vulnerability management.<br /><a href="https://infosec.exchange/tags/embedded" class="mention hashtag" rel="tag">#<span>embedded</span></a> <a href="https://infosec.exchange/tags/linux" class="mention hashtag" rel="tag">#<span>linux</span></a> <a href="https://infosec.exchange/tags/oss" class="mention hashtag" rel="tag">#<span>oss</span></a> <a href="https://infosec.exchange/tags/psirt" class="mention hashtag" rel="tag">#<span>psirt</span></a></p>

Posts

  • Post #4481134

    RE: https://mastodon.social/@bouletcorp2/117061351342436113 Dilemme moral de l&#39;utilisateur d&#39;intelligence artificielle.

  • Post #3133394

    Anyone can now declare a KEV to the CISA. #CISA #KEV

  • Post #3133393

    A juicy report that, sadly, won&amp;#39;t teach you much if you&amp;#39;re in the vulnerability management business. At least, you can say: &amp;quot;see? I told you&amp;quot; 🤬 https://cyberscoop.com/nist-nvd-audit-mismanagement-duplication/?utm_campaign=CyberScoop%20-%20Edito

  • Post #3133392

    RE: https://mastodon.social/@andrewnez/116674596440323949 Some pearls of wisdom here. 😂 My favs: * Defense in depth: coding. * Attack surface: your code. * Blast radius: everyone else’s code. * Shift left: make it the developer’s problem. * Compensating control: we didn’t fix it. * Risk acceptance: we didn’t fix it, in writing.

  • Post #3133391

    RE: https://mastodon.social/@CVE_Program/116686502518980062 2,000+ CVE in a CISA weekly bulletin? Unless I&amp;#39;m mistaken this is the all-time record (so far). 🤯 #cve

  • Post #1157678

    I&amp;#39;ll be at the VulnCon next week (remotely that is, from Paris). Maybe we&amp;#39;ll met in the chats? https://www.first.org/conference/vulncon26/ #vulncon26