‼️🚨 BREAKING: GitHub has been compromised by TeamPCP. GitHub has confirmed the internal breach. A poisoned VS Code extension on an employee device exfiltrated ~3,800 internal repositories.
TeamPCP is already selling the data on a cybercrime forum.
@dradisfw New in Dradis 5 - Inline Comments for QA
GitHub style inline-comments for more precise and easier to follow QA conversations
It's easier to discuss different sections of your assessment, resolve conversations, and jump back and forth the pending items.
10/10
@dradisfw New in Dradis 5 - Personal Access Tokens (PAT)
More and more users are connecting their agents to the platform. We've introduced Personal Access Tokens so you can conveniently scope access: each agent restricted to the minimum privilege needed for the task at hand.
9/10
I shipped @dradisfw publicly at DEF CON 17 in 2009. The commercial version followed in 2010.
Every pentest management platform on the market today launched after that.
1/2
Turns out Dradis is in 20+ cybersecurity text books.
Authors included it because they could look at the code, run the tool, try for themselves. It passed the quality bar.
That's different from a vendor-issued case study.
https://t.co/2kYdK1J1oS
A big team is running a "vendor risk assessment" (I know). It means separating authentic validation from marketing arrangements.
For @dradisfw, the evidence is in places we don't control: certification study guides, Kali Linux's, Black Hat's Arsenal selection committee, books...
@dradisfw from zero to ready in 60s:
curl -fsSL https://t.co/ir7nSuR3dG | /bin/bash
New kits:
- Infrastructure pentest
- OWASP 2025 webapp
- Red Team assessment
@lkr Projects, agents, or an organised .claude/ help.
I like how OpenClaw puts it:
> Each session, you wake up fresh. These files _are_ your memory. Read them. Update them. They're how you persist.