Advertisement · 728 × 90

Posts by

SSTIC2026 » Programme du 3 au 5 juin 2026

Le #SSTIC ne semble toujours pas sur BlueSky 😢
Programme en ligne :
www.sstic.org/2026/program...

4 weeks ago 7 8 0 0

Dependency cooldowns, redux
https://blog.yossarian.net/2025/12/13/cooldowns-redux
#security #oss

4 months ago 4 1 0 0
Preview
PyPI and Shai-Hulud: Staying Secure Amid Emerging Threats - The Python Package Index Blog Shai-Hulud is a great worm, not yet a snake. Attack on npm ecosystem may have implications for PyPI.

There's a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects.

TL,DR: Adopt Trusted Publishing 🔐🚀📦

blog.pypi.org/posts/2025-1...

4 months ago 25 17 1 2

I'm thrilled to announce that after months of intensive work, the complete materials for my Applied Cryptography course at the American University of Beirut are now finished: both Part 1 (Provable Security) and Part 2 (Real-World Cryptography)!

8 months ago 32 9 4 1
Preview
Making PyPI's test suite 81% faster See how we slashed PyPI’s test suite runtime from 163 to 30 seconds. The techniques we share can help you dramatically improve your own project’s testing performance without sacrificing coverage.

my colleague @darkamaul.bsky.social has a new blog post on the @trailofbits.bsky.social blog about how we worked with @pypi.org's maintainers to slash test times on PyPI by over 80%:

blog.trailofbits.com/2025/05/01/m...

11 months ago 6 3 0 1
Post image

Fuzzing Windows ARM64 binaries with a DBI and LLVM?
Here we go: www.romainthomas.fr/post/25-04-w...

11 months ago 4 5 0 0

zizmor would have caught the Ultralytics workflow vulnerability blog.yossarian.net/2024/12/06/zizmor-ultral... #security #oss

1 year ago 17 7 2 2
Advertisement

Excited to be part of the lineup at @districtcon.bsky.social first conference! Can't wait to see everyone in Washington DC

1 year ago 1 0 0 0