
Ed
@EdOverflow
Followers
20K
Following
3K
Media
186
Statuses
1K
Web developer & security researcher. Senior Pentester @cure53berlin. Author of @securitytxt. ➡️ https://t.co/BOy1tiLLBr
Joined October 2016
After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: I would like to use this opportunity to thank those who made this possible. Thank you. ❤️
43
971
3K
RT @swisscyberstorm: The Swiss Federal Government has adopted a report on ethical hacking referencing two @swisscyberstorm 2023 speakers: @….
0
3
0
I will be giving a talk on Coordinated Vulnerability Disclosure (CVD) at Swiss Cyber Storm. If you are interested in attending, please find additional information below.
Speaking @swisscyberstorm 2023.Edwin Foudil (@cure53berlin): “Navigating The Coordinated Vulnerability Disclosure Landscape”.Demystifying concepts surrounding CVD and showing solutions to overcome challenges.Program: Tickets: #SCS23
1
2
15
I am working on something fun with @KarimPwnz to address the challenge of repetitive security questionnaires: @BlueMagnetIO (.
0
4
15
RT @securitytxt: Exciting news! @Apple joins the list of companies with a security.txt file. Now, we only need @netflix to complete the FAA….
0
87
0
I have published a new blog post on my bug bounty methodology: "Learn to build it, then break it" —
edoverflow.com
Learn security by building. Embrace application-specific insights over checklists. Recognise patterns for effective vulnerability discovery.
4
40
192
Nice blog post by @KarimPwnz on the security implications of command injection in GitHub Actions.
You have command injection in a GitHub Actions workflow. Now what?. Read my blogpost on leaking secrets from GitHub Actions workflows:.
0
1
11
Retweeting this because I know BSides London tickets are hard to come by. :).
Security BSides London: Are you a woman who works (or wants to work) in tech? We have FIVE tickets to give away for the Security BSides London conference, Saturday 10 December. Just DM us to get one. Please RT. @BSidesLondon #BSidesLDN2022 #WomenInTech
0
1
8
It was a pleasure presenting with @jschreuder and @DTC_NL at @OneConferenceNL. The work they are doing to promote security.txt in the Netherlands is amazing. You can read more about their work here:
1
2
13
RT @troyhunt: I love that the Dutch government is actively promoting security.txt and encouraging companies to establish a route for report….
0
19
0
RT @internet_nl: Where can ethical hackers report vulnerabilities at your organization? Publish a security.txt file and test it with Intern….
0
41
0
And here are some photos from the trip. Thank you, @spaceraccoonsec, for being an excellent tour guide. :)
0
0
6
Thank you, @fbsecurity, for organising another fantastic event. I thoroughly enjoyed BountyCon and exploring Singapore. Team BBAC members (@xdavidhu, @_zulln, @ElSec_, @spaceraccoonsec, @rub003, @EdOverflow) managed to find valid vulnerabilities with @rub003 finishing #3 overall.
4
4
62
This looks like a fun chain by @fransrosen. If readers are interested in rapidly checking CSP hosts, I wrote a tool for grabbing them concurrently:
2
31
110