Security Researcher @ Veracode & Familyman|Renovator @ N28

Nederland
Joined January 2010
Time to listen to @LDuys talking about mission-critical systems on Azure. #UpdateConference
6
🗝️ Security, security, security… Come join us on a talk about security provided by WebAssembly with @nielstanis, or learn about network-level security features in Azure PaaS services by @erwin_staal. 👉 updateconference.net/en #UpdateConference #UpdateConferencePrague #dotnet
4
1
4
Hitting the road to travel to Sydney! If you're attending NDC Sydney hope to see you there @NDC_Conferences #NDCSydney
1
12
Niels Tanis retweeted
Veracode is shifting container security left in a developer friendly way, scanning for OSS vulns on all layers, configuration (Kubernetes manifests, Helm charts, Pod Security Standards/Policies, Terraform, CloudFormation, AWS CIS 1.2), and secrets. containerjournal.com/feature…
4
9
Niels Tanis retweeted
I'm looking forward to discussing cyber hygiene and cyber resilience on stage at Microsoft Ignite with @vasujakkal next week. You can sign up for an in person or virtual ticket here: aka.ms/ignite-security-fy23
1
3
5
Niels Tanis retweeted
. @nielstanis on software supply chain attacks at @devNetNoord
3
6
Niels Tanis retweeted
Op 29 september organiseren we weer een #DevNetNoord meetup met vier prachtige sessies, waaronder @nielstanis met zijn sessie ' #Securing your .NET application software #SupplyChain'. Check voor het hele programma en hoe je je kan aanmelden: buff.ly/3JFKMLV #Dotnet
3
2
World's oddly relaxed about recent CSRF bypass in csurf express middleware. It does require cookie tossing which limits the blast radius but for multi-tenant apps using subdomains it could be deadly -> fortbridge.co.uk/research/cs….
Niels Tanis retweeted
npm Best Practices for the Supply-Chain is out! openssf.org/blog/2022/09/01/… Thanks everyone who got involved @MylesBorins @ljharb @jeffmendoza @erezrokah @liran_tal @theopenssf and many more!
Definitely stoked about the fact I'll be traveling to Sydney in October and doing two sessions at NDC Sydney! I'm going to talk about sandboxing .NET assemblies and of course supply-chain security. ndcsydney.com/speakers/niels… #ndcsydney @NDC_Conferences
1
3
Niels Tanis retweeted
We wrote about these issues with matching vulnerabilities based on CPEs almost 7 years ago - veracode.com/blog/managing-a…
Following @lorenc_dan’s thread on vulnerability scanners, I wanted to share what I think is a core problem in this space: CPEs. They’re broken right now, but could be better in the future. 🧵 nvd.nist.gov/Products/CPE
1
2
Niels Tanis retweeted
Op 29 september organiseren we weer een #DevNetNoord meetup met vier prachtige sessies, waaronder @nielstanis met zijn sessie ' #Securing your .NET application software #SupplyChain'. Check voor het hele programma en hoe je je kan aanmelden: buff.ly/3JFKMLV #Dotnet
3
2
Niels Tanis retweeted
"Password expiration requirements do more harm than good, because these requirements make users select predictable passwords" Thank you Microsoft. NIST agrees. Everyone who attacks password auth agrees. Can we get compliance to update their requirements. docs.microsoft.com/en-us/mic…
29
429
65
1,390
One of the BEST @dotnet tools that more folks don't know about is "dotnet outdated" github.com/dotnet-outdated/d… Why is it amazing? Check this screenshot then thank @coderpatros and @jerriepelser
Niels Tanis retweeted
My defcon30 workshop contents available here. fuzzing.in/codelabs/finding_…