@slekiesi
iAccount based inCanada
About this account
- Account based in
- Canada
- Connected via
- Switzerland App Store
Account-level information from X, not a live location or the device used for a specific post.
Automated Security Scanning & Vulnerability Management @Google
Zürich, Schweiz
Joined October 2011
- Tweets1.5K
- Following422
- Followers3.3K
- Likes744
Pinned Tweet
Today, we announced the official release of OSV-SCALIBR, Google's software composition analysis library. If you are working in vuln management / security scanning, SCALIBR is for you! SCALIBR is powering most of Google's vuln scanning. Please RT
security.googleblog.com/2025…
Sebastian Lekies retweeted
The vulnapocalypse is here, but Opus 4.7 still routinely confuses the direction of a wild memcpy.
LLMs are super crazy powerful, and in many ways superhuman, but in some ways ... well, not quite there yet.
Sebastian Lekies retweeted
Got a knack for security? We've launched a rewards program for OSV-SCALIBR and want your help!
Earn cash 💰 for creating new plugins that detect vulnerabilities, secrets, or extract software inventory.
bughunters.google.com/blog/6…
Sebastian Lekies retweeted
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥
The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇
gmsgadget.com/
1/4
Sebastian Lekies retweeted
Protect your systems from leaked credentials! 🚨 We're excited to announce Veles, a new open-source secret and credential scanner from Google. Veles helps you find and fix sensitive data exposures in your source code and artifacts, with more features on the way!
Learn how Veles is battle-tested at Google and how it can help secure your organization: goo.gle/veles-scanner #Veles #OpenSource #Security #Cybersecurity #SecretsScanning
Veles, Google's new open-source secret scanner, is now available. This tool, built into our SCALIBR scanner, identifies exposed credentials with an extensible architecture for new secret types. We'd love to hear your feedback and answer any questions. opensource.googleblog.com/20…
Sebastian Lekies retweeted
Today Google announced a new OSV-SCALIBR: A library for Software composition analysis. It allows to extract software dependencies, generate SBOM’s and scan them via osv.dev!
More details in our blogpost: security.googleblog.com/2025…
Sebastian Lekies retweeted
Google has launched OSV-SCALIBR, an open-source library for software composition analysis! It identifies vulnerabilities and generates SBOMs, supporting various OS and languages. 🛡️🔍 #OpenSource #Google #SoftwareSecurity #CybersecurityNews
link: ift.tt/qE5l48z
Sebastian Lekies retweeted
Google releases OSV-SCALIBR, an open source library for software composition analysis and file system scanning. securityweek.com/google-rele…
Sebastian Lekies retweeted
Google’s New OSV-SCALIBR: Your Software’s Superhero or Just Another Sidekick?
Hot Take:
Google's OSV-SCALIBR: Because keeping tabs on your software vulnerabilities should be as easy as keeping tabs on your ex's Instagram story. With this new tool, Google is basically saying, "Don't worry, we got your back (and your code's back)!"
buff.ly/42jkbj7
Sebastian Lekies retweeted
OSV-SCALIBR: A library for Software Composition Analysis
security.googleblog.com/2025…
Sebastian Lekies retweeted
⚒️ SCALIBR (Software Composition Analysis Library)
An extensible file system scanner used to extract software inventory data (e.g. installed language packages) and detect vulnerabilities
By @Google
github.com/google/osv-scalib…
Sebastian Lekies retweeted
OSV-SCALIBR: A library for Software Composition Analysis: ift.tt/XrvxnOD by Google Online Security Blog #infosec #cybersecurity #technology #news
Sebastian Lekies retweeted
"OSV-SCALIBR combines Google’s internal vulnerability management expertise into one scanning library with significant new capabilities ..." security.googleblog.com/2025… < it's open source, and you can use what Google uses for software composition analysis
Sebastian Lekies retweeted
I wish we could deprecate javascript: URIs which are one of the few remaining XSS vectors for modern SPAs. Until then we can use CSP to disable javascript: URIs.
Here's a prototype for a refactoring free strict & hash-based CSP that does that: github.com/google/strict-csp…
You’re unable to view this Post because this account owner limits who can view their Posts. Learn more
Sebastian Lekies retweeted
Tsunami wants to be the best platform for scanning your AI infrastructure. Come join the party.
bughunters.google.com/blog/5…
Sebastian Lekies retweeted
Are you passionate about expanding the capabilities of the Tsunami network scanner, and would like to help keep AI infrastructure secure? See our blog post for details on getting involved and how your efforts will be rewarded 💸!
bughunters.google.com/blog/5… bughunters.google.com/blog/5…
Sebastian Lekies retweeted
⚗️ localtoast
Localtoast is a scanner for running security-related configuration checks such as CIS benchmarks in an easily configurable manner.
github.com/google/localtoast