
Gianluca Varisco
@gvarisco
Followers
4K
Following
27K
Media
384
Statuses
10K
I work at @Google on @googlecloud. Formerly @arduino, @ITdigitalteam, @RocketBerlin, @RedHat. Tweets are my own.
Paris, France
Joined March 2007
Following last week's provisional agreement between @EUCouncil and @Europarl_EN on the NIS Directive revision (#NIS2), I'm thrilled to report that it will provide guidance for EU countries to implement a national Coordinated Vulnerability Disclosure (CVD) policy. A thread 🧵👇.
1
28
65
“The hacker spirit guides us through situations once thought hopeless. Hacking is a way to answer your own burning questions, a way to discover your own potential, and a way to create a world you want to live in.”. ❤️.
0
6
30
RT @5aelo: We released our Fuzzilli-based V8 Sandbox fuzzer: It explores the heap to find interesting objects and c….
github.com
This is a basic fuzzer for the V8 Sandbox. It uses the memory corruption API to implement a random-but-deterministic (given a seed) traversal through the V8 heap object graph and corrupts some obje...
0
73
0
RT @cryps1s: We just removed a feature from @ChatGPTapp that allowed users to make their conversations discoverable by search engines, such….
0
152
0
RT @msftsecresponse: Microsoft is aware of active attacks targeting on-premises SharePoint Server customers, exploiting a variant of CVE-20….
0
108
0
Getting the chance to work alongside many of the people across @Google, @GoogleCloudSec, @Mandiant, @GoogleDeepMind that I considered childhood heroes has been a particular highlight, and it's an incredible opportunity I definitely won't take for granted. I'll miss you all.
1
0
3
After five rewarding years here at @Google, I've decided it's time for me to move on. I am incredibly grateful for the opportunities I've been given during my time here. I've learned a great deal, worked on challenging and exciting projects, and truly valued the experience.
3
0
37
RT @GoogleVRP: Developers, tired of DOM XSS in your web applications? 😩 We were too. See how we refactored our code to solve Trusted Types….
bughunters.google.com
Join us as we take a closer look at the technical details of how we identified the root causes for TT violations in two flagship rollouts: Gmail and AppSheet.
0
24
0
RT @GoogleVRP: ❌ Eliminating almost all exploitable web vulnerabilities? This blog post covers how the Google security team implemented a h….
bughunters.google.com
Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.
0
45
0
RT @itswillis: Two new posts from @tiraniddo today:. on reviving a memory trapping primitive from his 2021 post.….
0
98
0
RT @GoogleVRP: 🛡️Want to help make the open source world safer and earn up to $45k 💰? . We've revamped our Patch Rewards Program, extending….
bughunters.google.com
This blog post takes you through everything you need to know about the Patch Rewards Program, including our newly introduced focus on memory safety (including reward multipliers!), recently increased...
0
30
0
RT @slekies: Today, we announced the official release of OSV-SCALIBR, Google's software composition analysis library. If you are working in….
security.googleblog.com
Posted by Erik Varga, Vulnerability Management, and Rex Pan, Open Source Security Team In December 2022, we announced OSV-Scanner , a tool t...
0
75
0
RT @AustinLarsen_: 🚨 New: Zero-day vulnerability CVE-2025-0282.in Ivanti Connect Secure VPN is being actively exploited, including by suspe….
cloud.google.com
Zero-day exploitation of Ivanti Connect Secure VPN vulnerabilities since as far back as December 2024.
0
40
0
RT @CISACyber: #Ivanti released security updates to address CVE-2025-0282—being actively exploited—and CVE-2025-0283, affecting Connect Sec….
0
121
0
RT @GoogleVRP: Introducing InternetCTF! 🤯 Earn up to $10,000 for finding RCE vulnerabilities in open-source software AND creating Tsunami p….
bughunters.google.com
The InternetCTF offers a total reward of up to $10,000 to bug hunters who not only discover novel code execution vulnerabilities in Open Source Software, but also provide Tsunami plugin patches for...
0
115
0
RT @GoogleVRP: Can you believe it's already been one year of generative AI bug bounties at Alphabet 🥳? . Besides awarding over $50k for 140….
bughunters.google.com
This blog discusses what one year of AI bug bounties has taught us and where we're planning to go from here.
0
15
0