
Lukas Weichselbaum
@we1x
Followers
2K
Following
3K
Media
99
Statuses
1K
Leading @Google's web security team. Opinions are my own. Bluesky: @webappsec.dev
Joined January 2011
My @LocoMocoSec keynote slides on "Google's Recipe for Scaling (Web) Security" are online now:
3
13
40
RT @SecurityMB: Google CTF is on! Here's a challenge that I created: . Good luck π.
0
27
0
RT @SecurityMB: Here's my blog post about escaping `<>` in attributes and why it makes mXSS harder to exploit!.
0
19
0
RT @GoogleVRP: π¨ Heads up for web devs! π¨ . The HTML spec just got an important update to protect against mutation XSS (mXSS). Find out hoβ¦.
bughunters.google.com
The HTML specification has been updated to escape '<' and '>' in attributes to prevent mutation XSS (mXSS) vulnerabilities. This post details the reasoning behind this change and explains why this...
0
58
0
One of my teams at Google, ππ ππ΄π²π»π π¦π²π°ππΏπΆππ, is expanding in πππΏπΆπ°π΅ π¨πand π‘π²π π¬πΌπΏπΈ πΊπΈ. We're looking for π¦π²π°ππΏπΆππ ππ»π΄πΆπ»π²π²πΏπ with experience in attacking and securing AI/ML systems. DMs open.
0
0
5
Safari Tech Preview 215: Added support for Trusted Types π.
webkit.org
Safari Technology Preview Release 215 is now available for download for macOS Sequoia and macOS Sonoma.
0
2
17
RT @0xAsm0d3us: @ryancbarnett @akamai_research This reminds me of this cool paper from Google I read years back. The best possible resourceβ¦.
0
3
0
RT @GoogleVRP: Developers, tired of DOM XSS in your web applications? π© We were too. See how we refactored our code to solve Trusted Typesβ¦.
bughunters.google.com
Join us as we take a closer look at the technical details of how we identified the root causes for TT violations in two flagship rollouts: Gmail and AppSheet.
0
24
0
RT @dinodaizovi: This is a great example of secure by design through a framework-centric approach to security. The key idea is to build higβ¦.
0
2
0
RT @royalhansen: "This blog post aims to provide a detailed blueprint for how Google has created and deployed a high-assurance web frameworβ¦.
bughunters.google.com
Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.
0
16
0
Web security starter pack is in good shape now and includes many amazing folks passionate about web security like @terjanq or @shehackspurple:. Please share and recommend folks passionate about web security so we can get this community started there π
2
1
6
I put together a list of folks passionate about web security and related topics I follow on bluesky to stay on top of cool web bugs, web platform security features and fixes Please share, join us there or comment if know someone who should be on that list.
0
4
19
Hey @clintgibler we're missing you and your awesome newsletter on bluesky!.I put together a starter pack for web security to make bootstrapping easier:
0
0
2
B l u e s k y is π₯ got 80 followers overnight! So many infosec folks over there.
Bootstrap your #infosec network on bluesky with @j_opdenakker's starter pack: Please comment below if you can recommend other starter packs for infosec or other topics π.
0
0
4
RT @ayper: Excited to share our latest post on memory safety! We're tackling spatial safety in our massive C++ codebase by hardening libc+β¦.
security.googleblog.com
Posted by Alex Rebert and Max Shavrick, Security Foundations, and Kinuko Yasuda, Core Developer Attackers regularly exploit spatial mem...
0
51
0
Bootstrap your #infosec network on bluesky with @j_opdenakker's starter pack: Please comment below if you can recommend other starter packs for infosec or other topics π.
0
5
8