_atorralba Profile Banner
Tony Torralba Profile
Tony Torralba

@_atorralba

Followers
411
Following
870
Media
17
Statuses
338

Breaking builds and building breakages. He/him. ProdSec Engineer @okta. Opinions are my own. Mastodon: https://t.co/oFZdTxYDMJ

Barcelona
Joined December 2011
Don't wanna be here? Send us removal request.
@gothburz
Peter Girnus 🦅
5 days
Last quarter I rolled out Microsoft Copilot to 4,000 employees. $30 per seat per month. $1.4 million annually. I called it "digital transformation." The board loved that phrase. They approved it in eleven minutes. No one asked what it would actually do. Including me. I
5K
24K
163K
@maple3142
maple3142
12 days
A POC for CVE-2025-55182 https://t.co/BcyJ1UbivA
34
430
2K
@togelius
Julian Togelius
4 months
I remember being excited about AI. I remember 20 years ago, being excited about neuroevolutionary methods for learning adaptive behaviors in video games. And I remember three years ago, mouth watering at the thought of tasty experiments in putting language models inside
49
63
377
@_atorralba
Tony Torralba
7 months
Looking forward to day 2 talks today!
0
0
0
@_atorralba
Tony Torralba
7 months
"Beyond the Surface: Exploring Attacker Persistence Strategies in Kubernetes" by @raesene. Live demos are always a sign of bravery, and I personally love talks where the narrative revolves around red team-style engagements and operational tricks. https://t.co/PgQyAugLtY
owasp2025globalappseceu.sched.com
View more about this event at OWASP 2025 Global AppSec EU
1
0
0
@_atorralba
Tony Torralba
7 months
"Friend or foe? TypeScript security fallacies" by @liran_tal. Engaging talk about how TypeScript doesn't automatically prevent security issues, sometimes very counter-intuitively! Good memes as well :P https://t.co/ZEuHh2dQVl
owasp2025globalappseceu.sched.com
View more about this event at OWASP 2025 Global AppSec EU
1
0
1
@_atorralba
Tony Torralba
7 months
"Securing cross-platform mobile applications" by @Dauntless. Really well thought and presented, with experiments comparing the output of the most popular cross-platform mobile app frameworks out there and common mobile vulnerabilities. https://t.co/cskKKM6vEC
owasp2025globalappseceu.sched.com
View more about this event at OWASP 2025 Global AppSec EU
1
0
0
@_atorralba
Tony Torralba
7 months
My highlights from yesterday's talks at @owasp AppSec Global Barcelona:
1
0
0
@samwcyo
Sam Curry
11 months
New blog post with @infosec_au: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. The issue was reported and patched. Full post here:
Tweet card summary image
samcurry.net
On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK admin panel that gave us unrestricted access to all vehicles and customer accounts in the United...
47
315
1K
@DevSecOps_eko
DevSecOps Space
1 year
Security in Action(s): extending CodeQL to detect Workflow vulnerabilities 🎤 Álvaro Muñoz Protege tus pipelines de CI/CD con detección avanzada de vulnerabilidades en GitHub Actions. --- SALA A2 - Miércoles 13 Noviembre de 14:45 a 15:30 hs @ekoparty CEC Buenos Aires
0
2
3
@_atorralba
Tony Torralba
1 year
As someone who has always toyed with the idea of learning more about low-level exploitation (but is currently very bad at), I enjoyed this post a whole lot. Not only because of the insights about the whats and whys, but also because of the transversal look at the offsec industry.
@gynvael
Gynvael Coldwind
1 year
So you want to make a career in low-level exploitation? Well, there is some bad news and some good news. Either way, here is some information to equip you on your way: "FAQ: The tragedy of low-level exploitation" https://t.co/R7pQjWXcaw
0
0
3
@GHSecurityLab
GitHub Security Lab
1 year
🚨 New Blog Alert! 🚨 Can an attacker execute commands by sending JSON? Learn how unsafe deserialization vulnerabilities in Ruby can be exploited and how they can be detected with CodeQL. 🔗 Read the full post: https://t.co/tdumVwrfKC Stay safe and code responsibly! 🛡️💻
Tweet card summary image
github.blog
Can an attacker execute arbitrary commands on a remote server just by sending JSON? Yes, if the running code contains unsafe deserialization vulnerabilities. But how is that possible? In this blog...
0
20
46
@_atorralba
Tony Torralba
2 years
This is happening today at 1pm CET. Those of you attending, see you there!
@_atorralba
Tony Torralba
2 years
Happy to share that @pwntester and I will be presenting our talk "Finding vulnerabilities at scale in Jenkins plugins with CodeQL" at @BarcelonaBsides, happening on May 29-30. Join us to learn about CodeQL, vulnerability research at scale, and the Jenkins plugin ecosystem!
0
4
13
@_atorralba
Tony Torralba
2 years
Happy to share that @pwntester and I will be presenting our talk "Finding vulnerabilities at scale in Jenkins plugins with CodeQL" at @BarcelonaBsides, happening on May 29-30. Join us to learn about CodeQL, vulnerability research at scale, and the Jenkins plugin ecosystem!
0
6
26
@BlazingWindSec
/* BlazingWind */
2 years
Learn to audit applications for vulnerabilities with CodeQL and find them in thousands of GitHub repositories at once. 🚀 My blog, CodeQL zero to hero part 3: Security research with CodeQL is out! https://t.co/Xt4xAJ5S8h
Tweet card summary image
github.blog
Learn how to use CodeQL for security research and improve your security research workflow.
1
11
11
@_atorralba
Tony Torralba
2 years
This is my favorite kind of talk: great storytelling, cool visuals, technically interesting scenarios, and inspiring discourse. Consider me impressed @curi0usJack :D https://t.co/yLQOMgk3lb
1
0
4
@github
GitHub
2 years
Ever wondered how the @GHSecurityLab performs security research? Find out how they leverage code scanning, CodeQL, Codespaces and more🔒 ⬇️ https://t.co/nTxq1iLBMd
Tweet card summary image
github.blog
This blog post is an in-depth walkthrough on how we perform security research leveraging GitHub features, including code scanning, CodeQL, and Codespaces.
8
21
76
@GHSecurityLab
GitHub Security Lab
2 years
Level up your security game on GitHub with seamless security research! Discover code scanning, CVE management, and more within GitHub's ecosystem. Check out this insightful blog post now! 🔒 #GitHub #SecurityResearch #CodeScanning #CVEManagement https://t.co/XDXhepHZgX
Tweet card summary image
github.blog
This blog post is an in-depth walkthrough on how we perform security research leveraging GitHub features, including code scanning, CodeQL, and Codespaces.
0
9
18