
Graham Bleaney
@GrahamBleaney
Followers
272
Following
226
Media
8
Statuses
61
Security Engineering Manager @meta, leading a team scaling the detection and prevention of web vulnerabilities
New York, New York
Joined March 2011
We have a draft PEP up for adding a new Literal[str] type to #Python3:.When used correctly, this type can prevent all kinds of injection vulnerabilities. We've been experimenting with this at Meta for a while, and are excited to share with the world.
1
0
2
I'll be presenting "Teaching an old dog new tricks: Reusing security tools in novel domains" at #Enigma2022 in Santa Clara, February 1–3, 2022. It provides case studies of how security tools like Pysa have been used in non-security applications at Facebook
1
1
7
RT @OrenHafif: We are looking for an experienced application security engineer to help build a world where everyone, everywhere has secure….
0
6
0
Our #PyCon 2021 talk "Unexpected Execution: Wild Ways Code Execution can Occur in Python" is now on YouTube:.I guarantee there will be at least one RCE vector in there that you weren't aware of. It also comes with demos:.
0
5
17
RT @NAKsecurity: The second round of our RFP is now published, with proposals being accepted until July 14! . "Towards Trustworthy Products….
0
10
0
To go with the #PyConUS2021 talk, we've also got a demo repo with examples of functions that enable code execution in python: There's a UI to test exploits against and a machine-readable dump of sinks to feed to your static analyzers (including Pysa 😀 ).
1
2
7
RT @fbOpenSource: 🤔 Explain Like I’m 5 🤔. In just over a minute, Jessica (@hey_its_jlin) gives an overview of #Pysa, an #OpenSource Python….
0
18
0
For those attending @pycon (it's too late to sign up!), check out the out the talk @the_st0rm and I are giving on the myriad of APIs that can enable remote code execution in Python: These examples were originally compiled as a part of our work on Pysa.
1
7
16
RT @libber: A decade of facebook bug bounty. 130,000 reports, 6,900 valid, 11.7million paid out. An incredible t….
0
7
0
RT @libber: Sometimes we find bugs in code that isn't ours, now (following the p0 playbook) we have a pathway to disclose them https://t.co….
0
6
0