@kstewart@harvest Congratulations! Is it too soon to ask about that chair? Looks super comfy. What kind is it? I am In the market for a good office chair
Hey @SpotifyCares is there a way to use Spotify kids without a phone (using web browser)? My kids don't have a phone but love to listen to music on Spotify.
Incredible research: $75,000 bounty🤯
"My research uncovered 7 0day vulnerabilities in Safari (CVE-2020-3852, CVE-2020-3864, CVE-2020-3865, CVE-2020-3885, CVE-2020-3887, CVE-2020-9784, & CVE-2020-9787), 3 were used in kill chain to access the camera."
https://t.co/78Jrsz8eFV
@TheSweetKat Yes! Super useful. My manager did it for me and I continue the tradition with new hires. I share a google doc with administration stuff, links, KB and a list of people to meet with & why
I never announced my move last October but I relocated to Austin, TX to accept a role as the Security Manager at YETI.
With that said, who wants to join me?
I am working on a req to hire a traditional blue team Security Engineer. My DMs are open if you'd like to chat.
@SuchiPahi The trick was to have the "right" ratio of bitter gourd to long beans. I go with about twice the long beans for Indian karela. The Chinese bittergourd is less bitter and hence I use more of it. Hope you enjoy 😋
@shehackspurple This is much needed. I would love to build some short courses to help our engineers with specific problems. My previous methods have been very Meh. Would love to learn about this.
How we trust libraries:
- number of users
- authority of author(s)
- last change was recent
- number of commits
- number of issues
- readme/changelog/releases maturity
- number of blogs
What did I miss? And is it different from selecting Saas Services?
How do new libs grow this
@sawaba Agree 100%. The security culture in new companies gives me great hope. On the same note, Is "legacy tech" one of the biggest dangers to security?
Great content and food for thought. Agree with the article about making security everyone's responsibility. How to do it within the culture of a company is the tough bit
@thepacketrat Also, I've been thinking about why we imitate Groundhog Day in our industry for 7 years now, happy to chat. Part of this thinking is here: https://t.co/M18MUBsG6b
Awesome CodeQL query from @ggolawski that detects many variants of LDAP Injections in Java: Plain Java JNDI, UnboundID, Spring LDAP and Apache LDAP API. We are pleased to award him our maximum bounty reward $3000
https://t.co/rvdMkektz2