Today, we announced the official release of OSV-SCALIBR, Google's software composition analysis library. If you are working in vuln management / security scanning, SCALIBR is for you! SCALIBR is powering most of Google's vuln scanning. Please RT
https://t.co/Xk95hlSQwd
The vulnapocalypse is here, but Opus 4.7 still routinely confuses the direction of a wild memcpy.
LLMs are super crazy powerful, and in many ways superhuman, but in some ways ... well, not quite there yet.
Got a knack for security? We've launched a rewards program for OSV-SCALIBR and want your help!
Earn cash 💰 for creating new plugins that detect vulnerabilities, secrets, or extract software inventory.
https://t.co/jvtVTSpCXs
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥
The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇
https://t.co/SgsSyxoEMR
1/4
Protect your systems from leaked credentials! 🚨 We're excited to announce Veles, a new open-source secret and credential scanner from Google. Veles helps you find and fix sensitive data exposures in your source code and artifacts, with more features on the way!
Learn how Veles is battle-tested at Google and how it can help secure your organization: https://t.co/ARXh6sWPuB #Veles #OpenSource #Security #Cybersecurity #SecretsScanning
Veles, Google's new open-source secret scanner, is now available. This tool, built into our SCALIBR scanner, identifies exposed credentials with an extensible architecture for new secret types. We'd love to hear your feedback and answer any questions. https://t.co/ioLF1EQnBz
Today Google announced a new OSV-SCALIBR: A library for Software composition analysis. It allows to extract software dependencies, generate SBOM’s and scan them via https://t.co/TyHMfmbPP6!
More details in our blogpost: https://t.co/sG2ninnRPc
Google has launched OSV-SCALIBR, an open-source library for software composition analysis! It identifies vulnerabilities and generates SBOMs, supporting various OS and languages. 🛡️🔍 #OpenSource#Google#SoftwareSecurity#CybersecurityNews
link: https://t.co/SjqlXnydvH
Google’s New OSV-SCALIBR: Your Software’s Superhero or Just Another Sidekick?
Hot Take:
Google's OSV-SCALIBR: Because keeping tabs on your software vulnerabilities should be as easy as keeping tabs on your ex's Instagram story. With this new tool, Google is basically saying, "Don't worry, we got your back (and your code's back)!"
https://t.co/vb3yH3P7EM
Today, we announced the official release of OSV-SCALIBR, Google's software composition analysis library. If you are working in vuln management / security scanning, SCALIBR is for you! SCALIBR is powering most of Google's vuln scanning. Please RT
https://t.co/Xk95hlSQwd
SCALIBR is a library that allows you to enumerate all software installed in a given file system, such as containers, VMs, running machines, or code repositories. Additionally, it offers extensible vulnerability scanning capabilities. Reach out in case you have questions.
⚒️ SCALIBR (Software Composition Analysis Library)
An extensible file system scanner used to extract software inventory data (e.g. installed language packages) and detect vulnerabilities
By @Google
https://t.co/3WJ8AIVRv8
"OSV-SCALIBR combines Google’s internal vulnerability management expertise into one scanning library with significant new capabilities ..." https://t.co/rWbXWcclBt < it's open source, and you can use what Google uses for software composition analysis
@we1x@arthursonzogni@manicode I.e start with opt out, after x years you have to opt-in and after another x years you drop that too.
What’s an acceptable usage percentage to phase out a browser feature btw?
@we1x@arthursonzogni@manicode There seems to be a depreciation problem for outdated web tech. Would be nice if there was a mechanism / policy / standard that allows browsers vendors to phase out old tech. Opt out seems to be the easiest, but I wonder if the opt out could be turned into opt-in over time.