Frenchie
@fre.bsky.social
540 followers 260 following 45 posts
InfoSec geek for Cloud/Clusters/Containers/Credentials/CI/CD/things-starting-with-C working on something new… Honk the planet. Twitter: @nfFrenchie
Posts Media Videos Starter Packs
Reposted by Frenchie
filippo.abyssdomain.expert
To implement robust mitigations across Geomys, I did a survey of open source project compromises in 2024/2025.

Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided.

words.filippo.io/compromise-s...
A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises
Project compromises have common root causes we can mitigate: phishing, control handoff, and unsafe GitHub Actions triggers.
words.filippo.io
fre.bsky.social
> Long-lived credential exfiltration

OpenSSF's Trusted Publishing is a partial solution here. repos.openssf.org/trusted-publ...

i.e. NPM recommends disabling long-lived credential publishing once Trusted Publishing is activated
docs.npmjs.com/trusted-publ...
Trusted publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
docs.npmjs.com
fre.bsky.social
$9!! That’s an expensive visit 😝
fre.bsky.social
Excuse me. How have I missed the grimace-posting?!
fre.bsky.social
_
<(o )___
( ._> /
`----'
fre.bsky.social
Genuinely quite cool: github.com/threatcl/thr... + LLM to automatically generate threat models as code @xntrik.wtf
fre.bsky.social
I know right!! Also, only 10% of the audience was permanently blinded by the lasers. Big improvement from last year!
fre.bsky.social
A+ Dad Joke game:

“It’s only officially called Formal Threat Modelling if you’re wearing a tuxedo” - the Tao of @xntrik.wtf
fre.bsky.social
When the vuvuzela harmonies joined in… truly sublime. Brought a tear to my eye
fre.bsky.social
Back due to popular demand! For those that missed yesterday’s talk… bsky.app/profile/fre....
fre.bsky.social
@xntrik.wtf on stage once again for an interpretive dance/drum solo encore!

You need an updated profile pic however mate…
Xntrik on stage at CyberCon
fre.bsky.social
@xntrik.wtf on stage once again for an interpretive dance/drum solo encore!

You need an updated profile pic however mate…
Xntrik on stage at CyberCon
fre.bsky.social
Will there be an encore to the drum solo?
fre.bsky.social
Truly inspirational drum solo mate, thank you

bsky.app/profile/fre....
fre.bsky.social
Front row seats for @xntrik.wtf’s CyberCon Keynote!

It was a pleasure to hear about his long & illustrious career.

The 17-minute avant-garde- jazz drum solo certainly was… certainly unique!
Xntrik on stage
fre.bsky.social
I’m still wrapping my head around his metaphor of:

“Extra extra small spandex bike shorts: 3 lessons this taught me about B2B sales & post-breach incident response at a large professional social media tech company”
fre.bsky.social
Front row seats for @xntrik.wtf’s CyberCon Keynote!

It was a pleasure to hear about his long & illustrious career.

The 17-minute avant-garde- jazz drum solo certainly was… certainly unique!
Xntrik on stage
Reposted by Frenchie
mccune.org.uk
Very handy tool I came across today github.com/mike-engel/j... from @mike-engel.com , useful for viewing k8s service account tokens!
Screenshot of decoding a Kubernetes service account token using the jwt utility described in the skeet.