@slekies

Automated Security Scanning & Vulnerability Management @Google

Zürich, Schweiz
Joined October 2011
Today, we announced the official release of OSV-SCALIBR, Google's software composition analysis library. If you are working in vuln management / security scanning, SCALIBR is for you! SCALIBR is powering most of Google's vuln scanning. Please RT security.googleblog.com/2025…
3
74
206
14,971
Sebastian Lekies retweeted
The vulnapocalypse is here, but Opus 4.7 still routinely confuses the direction of a wild memcpy. LLMs are super crazy powerful, and in many ways superhuman, but in some ways ... well, not quite there yet.
7
16
1
98
9,043
Got a knack for security? We've launched a rewards program for OSV-SCALIBR and want your help! Earn cash 💰 for creating new plugins that detect vulnerabilities, secrets, or extract software inventory. bughunters.google.com/blog/6…
1
16
67
6,114
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com/ 1/4
12
172
3
457
43,560
Sebastian Lekies retweeted
Protect your systems from leaked credentials! 🚨 We're excited to announce Veles, a new open-source secret and credential scanner from Google. Veles helps you find and fix sensitive data exposures in your source code and artifacts, with more features on the way! Learn how Veles is battle-tested at Google and how it can help secure your organization: goo.gle/veles-scanner #Veles #OpenSource #Security #Cybersecurity #SecretsScanning
20
2
34
3,246
Veles, Google's new open-source secret scanner, is now available. This tool, built into our SCALIBR scanner, identifies exposed credentials with an extensible architecture for new secret types. We'd love to hear your feedback and answer any questions. opensource.googleblog.com/20…
2
6
543
Sebastian Lekies retweeted
Today Google announced a new OSV-SCALIBR: A library for Software composition analysis. It allows to extract software dependencies, generate SBOM’s and scan them via osv.dev! More details in our blogpost: security.googleblog.com/2025…
4
7
726
Google has launched OSV-SCALIBR, an open-source library for software composition analysis! It identifies vulnerabilities and generates SBOMs, supporting various OS and languages. 🛡️🔍 #OpenSource #Google #SoftwareSecurity #CybersecurityNews link: ift.tt/qE5l48z
1
1
5
323
Sebastian Lekies retweeted
Google’s New OSV-SCALIBR: Your Software’s Superhero or Just Another Sidekick? Hot Take: Google's OSV-SCALIBR: Because keeping tabs on your software vulnerabilities should be as easy as keeping tabs on your ex's Instagram story. With this new tool, Google is basically saying, "Don't worry, we got your back (and your code's back)!" buff.ly/42jkbj7
1
1
210
SCALIBR is a library that allows you to enumerate all software installed in a given file system, such as containers, VMs, running machines, or code repositories. Additionally, it offers extensible vulnerability scanning capabilities. Reach out in case you have questions.
1
4
5
1,514
Sebastian Lekies retweeted
⚒️ SCALIBR (Software Composition Analysis Library) An extensible file system scanner used to extract software inventory data (e.g. installed language packages) and detect vulnerabilities By @Google github.com/google/osv-scalib…
10
31
2,762
OSV-SCALIBR: A library for Software Composition Analysis: ift.tt/XrvxnOD by Google Online Security Blog #infosec #cybersecurity #technology #news
1
1
204
Sebastian Lekies retweeted
"OSV-SCALIBR combines Google’s internal vulnerability management expertise into one scanning library with significant new capabilities ..." security.googleblog.com/2025… < it's open source, and you can use what Google uses for software composition analysis
5
8
754
Sebastian Lekies retweeted
I wish we could deprecate javascript: URIs which are one of the few remaining XSS vectors for modern SPAs. Until then we can use CSP to disable javascript: URIs. Here's a prototype for a refactoring free strict & hash-based CSP that does that: github.com/google/strict-csp…
You’re unable to view this Post because this account owner limits who can view their Posts. Learn more
2
4
16
1,786
Are you passionate about expanding the capabilities of the Tsunami network scanner, and would like to help keep AI infrastructure secure? See our blog post for details on getting involved and how your efforts will be rewarded 💸! bughunters.google.com/blog/5… bughunters.google.com/blog/5…
26
2
85
9,614
Sebastian Lekies retweeted
⚗️ localtoast Localtoast is a scanner for running security-related configuration checks such as CIS benchmarks in an easily configurable manner. github.com/google/localtoast
1
12
2
57
6,821