Daniel Pendolino
@dpendolino.bsky.social
Security Engineer at Ibotta. Single Dad. Nerd.
Reposted by Daniel Pendolino
The Evolution of Offensive Security: Insights from Dave Mayer podcasters.spotify.c...
The Evolution of Offensive Security: Insights from Dave Mayer by Phillip Wylie Show
About The Guest(s):Dave Mayer is an Offensive Security professional with extensive experience in Red Teaming and Penetration Testing. He has a background in computer science and has worked for companies like Citibank and Grim before founding Neuvik. Dave is also a mentor and educator in the field of Offensive Security.
Summary:Dave Mayer, an experienced Red Team professional, shares his journey in the field of Offensive Security. He discusses his background in computer science, his transition from development to Red Teaming, and his work at Citibank and other consulting firms. Dave emphasizes the difference between Red Teaming and Penetration Testing, highlighting the intent and level of detail involved in each. He also provides insights into when organizations should consider conducting a Red Team operation and the importance of cloud security in today's hybrid environments. Dave recommends learning programming and scripting languages like Python and PowerShell to excel in Offensive Security. He also discusses the role of bug bounties and disclosure programs in finding vulnerabilities and improving security.
Key Takeaways:
Red Teaming is focused on remaining undetected and achieving a specific objective, while Penetration Testing aims to find as many vulnerabilities as possible across multiple systems.
Red Teaming should be conducted after organizations have matured their vulnerability scanning and Penetration Testing processes.
Cloud security is crucial in today's hybrid environments, and understanding cloud platforms and APIs is essential for Offensive Security professionals.
Learning programming and scripting languages like Python and PowerShell is important for automating tasks and building tools in Offensive Security.
Bug bounties and disclosure programs can be valuable for finding vulnerabilities and improving security, but organizations should provide clear contact information for researchers to report vulnerabilities.
Dave's social media and Neuvik website:
https://twitter.com/dmay3r
https://www.linkedin.com/in/dmay3r/
https://www.neuvik.com/
podcasters.spotify.com
May 20, 2025 at 12:30 AM
The Evolution of Offensive Security: Insights from Dave Mayer podcasters.spotify.c...
Reposted by Daniel Pendolino
I can confirm that this is an awesome place to work!
May 15, 2025 at 4:25 PM
I can confirm that this is an awesome place to work!
Reposted by Daniel Pendolino
Over 1000 players and 600 teams registered and 48 challenges up at #BsidesSF #CTF
Join them at ctf.bsidessf.net
Join them at ctf.bsidessf.net
April 26, 2025 at 11:44 PM
Over 1000 players and 600 teams registered and 48 challenges up at #BsidesSF #CTF
Join them at ctf.bsidessf.net
Join them at ctf.bsidessf.net
Reposted by Daniel Pendolino
Last wave for the day for #BSidesSF #CTF
* pascals-homomorphism-1
* pascals-homomorphism-2
* slackblock-steg
* amd
* dating
* goto-zero
Check out: ctf.bsidessf.net
* pascals-homomorphism-1
* pascals-homomorphism-2
* slackblock-steg
* amd
* dating
* goto-zero
Check out: ctf.bsidessf.net
Spyro Waving GIF
ALT: Spyro Waving GIF
media.tenor.com
April 26, 2025 at 10:59 PM
Last wave for the day for #BSidesSF #CTF
* pascals-homomorphism-1
* pascals-homomorphism-2
* slackblock-steg
* amd
* dating
* goto-zero
Check out: ctf.bsidessf.net
* pascals-homomorphism-1
* pascals-homomorphism-2
* slackblock-steg
* amd
* dating
* goto-zero
Check out: ctf.bsidessf.net
Reposted by Daniel Pendolino
Reposted by Daniel Pendolino
You are in for a punny time until launch!
Join us at ctf.bsidessf.net/register, the #BSidesSF #CTF kicks off at 4:00pm PDT tomorrow!
Join us at ctf.bsidessf.net/register, the #BSidesSF #CTF kicks off at 4:00pm PDT tomorrow!
April 25, 2025 at 3:52 AM
You are in for a punny time until launch!
Join us at ctf.bsidessf.net/register, the #BSidesSF #CTF kicks off at 4:00pm PDT tomorrow!
Join us at ctf.bsidessf.net/register, the #BSidesSF #CTF kicks off at 4:00pm PDT tomorrow!
Reposted by Daniel Pendolino
I feel more excited about BsidesSF and RSA this year than I have in other years.
Excited to see people.
Excited to see people.
April 25, 2025 at 4:28 AM
I feel more excited about BsidesSF and RSA this year than I have in other years.
Excited to see people.
Excited to see people.
Reposted by Daniel Pendolino
Check out Michael + @itsjordyn.bsky.social this Thursday at Noon ET for another episode of GreyNoise University LIVE! 🎙️ Join us as we let you know whats next for GreyNoise, give a product demo, + answer all your questions.
GreyNoise University LIVE
www.greynoise.io
April 22, 2025 at 6:38 PM
Check out Michael + @itsjordyn.bsky.social this Thursday at Noon ET for another episode of GreyNoise University LIVE! 🎙️ Join us as we let you know whats next for GreyNoise, give a product demo, + answer all your questions.
Let's gooooo! This year is going to be fantastic!
I'm so frickin' excited by this year's BSidesSF CTF! We went all out
What's in the cards for this year? Join us next week at ctf.bsidessf.net and find out! #CTF #BSidesSF
April 19, 2025 at 5:17 PM
Let's gooooo! This year is going to be fantastic!
Reposted by Daniel Pendolino
current status: putting a few weird terminal facts that I do not have any practical use for into the terminal zine
(mostly I’m keeping it extremely practical but I think it's fun to have SOME weird stuff)
(mostly I’m keeping it extremely practical but I think it's fun to have SOME weird stuff)
April 17, 2025 at 6:31 PM
current status: putting a few weird terminal facts that I do not have any practical use for into the terminal zine
(mostly I’m keeping it extremely practical but I think it's fun to have SOME weird stuff)
(mostly I’m keeping it extremely practical but I think it's fun to have SOME weird stuff)
Reposted by Daniel Pendolino
Reposted by Daniel Pendolino
End-to-end encryption is secure because it protects the contents of your communications in transit between the endpoints. If you make one of those endpoints an editor at The Atlantic, no amount of encryption is going to save you from your own stupidity.
March 25, 2025 at 11:28 PM
End-to-end encryption is secure because it protects the contents of your communications in transit between the endpoints. If you make one of those endpoints an editor at The Atlantic, no amount of encryption is going to save you from your own stupidity.
Reposted by Daniel Pendolino
I'd like to bring this video to your attention.
www.youtube.com/watch?v=hyco...
It's doing pretty significant numbers for what it is, so while I understand sharing it won't make a difference for those knee-deep in the cult of personality, I'd say it has a better-than-average chance of resonating.
www.youtube.com/watch?v=hyco...
It's doing pretty significant numbers for what it is, so while I understand sharing it won't make a difference for those knee-deep in the cult of personality, I'd say it has a better-than-average chance of resonating.
Murphy: Six Weeks In, This White House Is On Its Way To Being The Most Corrupt In U.S. History
YouTube video by Senator Chris Murphy
www.youtube.com
March 8, 2025 at 8:02 PM
I'd like to bring this video to your attention.
www.youtube.com/watch?v=hyco...
It's doing pretty significant numbers for what it is, so while I understand sharing it won't make a difference for those knee-deep in the cult of personality, I'd say it has a better-than-average chance of resonating.
www.youtube.com/watch?v=hyco...
It's doing pretty significant numbers for what it is, so while I understand sharing it won't make a difference for those knee-deep in the cult of personality, I'd say it has a better-than-average chance of resonating.
Reposted by Daniel Pendolino
The Planetary Society strongly opposes the sudden, indiscriminate dismissal of more than 1,000 scientists, engineers, and explorers at NASA — the largest involuntary workforce reduction since the end of the Apollo program.
Read more on our stance. ⬇️
Read more on our stance. ⬇️
The Planetary Society Strongly Opposes Mass Layoffs of Probationary…
Sudden, indiscriminate layoffs at NASA do not serve the national interests in space leadership.
www.planetary.org
February 18, 2025 at 4:47 PM
The Planetary Society strongly opposes the sudden, indiscriminate dismissal of more than 1,000 scientists, engineers, and explorers at NASA — the largest involuntary workforce reduction since the end of the Apollo program.
Read more on our stance. ⬇️
Read more on our stance. ⬇️
Reposted by Daniel Pendolino
🧪🌊🦑⚒️
Ending the week with a little motivation from our office mural. 💙 We hope you all have a great weekend. 🦈
February 23, 2025 at 3:37 PM
🧪🌊🦑⚒️
Reposted by Daniel Pendolino
This video does such a good job saying what I have been trying to say about commercial AI.
An AI can write a 10th grade lit essay, but the point of an essay assignment is not to produce an essay. The essay teaches critical thinking, research skills, etc. The effort is the point.
An AI can write a 10th grade lit essay, but the point of an essay assignment is not to produce an essay. The essay teaches critical thinking, research skills, etc. The effort is the point.
Algorithms are breaking how we think
YouTube video by Technology Connections
www.youtube.com
February 23, 2025 at 12:13 PM
This video does such a good job saying what I have been trying to say about commercial AI.
An AI can write a 10th grade lit essay, but the point of an essay assignment is not to produce an essay. The essay teaches critical thinking, research skills, etc. The effort is the point.
An AI can write a 10th grade lit essay, but the point of an essay assignment is not to produce an essay. The essay teaches critical thinking, research skills, etc. The effort is the point.
Reposted by Daniel Pendolino
Hacking is NOT a crime
February 22, 2025 at 12:19 PM
Hacking is NOT a crime
Reposted by Daniel Pendolino
February 20, 2025 at 5:25 PM
Reposted by Daniel Pendolino
My favorite happy fact that I got from @ologies.bsky.social today, that's totally worth sharing and making someone smile. Thanks Alie!
February 20, 2025 at 3:31 AM
My favorite happy fact that I got from @ologies.bsky.social today, that's totally worth sharing and making someone smile. Thanks Alie!
Reposted by Daniel Pendolino
I spoke to the woman holding the sign and got more backstory.
Her son has just gotten his PhD in neuroscience, to help find a cure for the epilepsy that killed his sister. His postdoc funding came through right before Trump stopped funds, so he can do his research, but others in his field can’t.
Her son has just gotten his PhD in neuroscience, to help find a cure for the epilepsy that killed his sister. His postdoc funding came through right before Trump stopped funds, so he can do his research, but others in his field can’t.
February 18, 2025 at 12:49 AM
I spoke to the woman holding the sign and got more backstory.
Her son has just gotten his PhD in neuroscience, to help find a cure for the epilepsy that killed his sister. His postdoc funding came through right before Trump stopped funds, so he can do his research, but others in his field can’t.
Her son has just gotten his PhD in neuroscience, to help find a cure for the epilepsy that killed his sister. His postdoc funding came through right before Trump stopped funds, so he can do his research, but others in his field can’t.
Reposted by Daniel Pendolino
The measles outbreak in Texas is reminding me of the public letter Roald Dahl wrote about losing his daughter to measles in 1962, just before the vaccine was publicly available.
February 15, 2025 at 5:49 PM
The measles outbreak in Texas is reminding me of the public letter Roald Dahl wrote about losing his daughter to measles in 1962, just before the vaccine was publicly available.
Reposted by Daniel Pendolino
The men and women of our military have endured many hardships and even many shameful humiliations at the hands of their country but surely they don’t deserve being put in Cybertrucks.
After reports circulated Wednesday night of the State Department's intent to purchase Tesla vehicles, the document was edited, at 9:12 p.m., and now says the federal contract is for $400 million worth of "armored electric vehicles," but the word "Tesla" was removed.
www.npr.org/2025/02/13/g...
www.npr.org/2025/02/13/g...
Trump administration set to purchase $400 million worth of armored Teslas
That's according to a public State Department procurement document. It comes as ethics experts raise conflict of interest questions about the chief executive of Tesla, Elon Musk, who is a top White Ho...
www.npr.org
February 13, 2025 at 5:45 AM
The men and women of our military have endured many hardships and even many shameful humiliations at the hands of their country but surely they don’t deserve being put in Cybertrucks.
Reposted by Daniel Pendolino
Valentine’s Day is Friday.
February 11, 2025 at 3:04 AM
Valentine’s Day is Friday.
Reposted by Daniel Pendolino
It’s been a tough few weeks. My 10yo daughter was diagnosed with a very rare, aggressive cancer called interdigitating dendritic cell sarcoma (IDCS). I’m reaching out to identify clinicians/patients who have encountered pediatric IDCS or other (non-LCH) dendritic or histiocytic sarcomas cases.
February 8, 2025 at 9:21 PM
It’s been a tough few weeks. My 10yo daughter was diagnosed with a very rare, aggressive cancer called interdigitating dendritic cell sarcoma (IDCS). I’m reaching out to identify clinicians/patients who have encountered pediatric IDCS or other (non-LCH) dendritic or histiocytic sarcomas cases.