syro @0xsyr0.bsky.social Cybersecurity Specialist. Offensive Operator. Adversary Hunter. Crafting creative solutions for not-yet-existing problems. Hobby flag collector.
Simon Bennetts @psiinon.bsky.social ZAP Project Lead
ZAP by Checkmarx @zaproxy.org The Worlds Most Popular Web App Scanner.
kingthorin_rm @kingthorin.bsky.social IT Sec guy, zaproxy co-lead, WSTG co-lead, VWAD co-lead, OWASP Ottawa volunteer, Hacโบ3r, supporter of oxford commas, #INTJ. (Opinions == mine) ๐
OWASPยฎ Foundation @owasp.org We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
OWASP Juice Shop @owasp-juice.shop Probably the most modern and sophisticated insecure web application. Only we offer a 100% @owasp.org Top Ten incompliance guarantee! Skeets by @bkimminich.bsky.social
OWASP London Chapter @owasplondon.bsky.social #OWASP London Chapter
Follow us on X/Facebook/Meetup/Eventbrite/LinkedIN/YouTube. Mastodon: https://infosec.exchange/@owasplondon
๐ Webpage: https://owasp.org/london
๐ Meetup: https://meetup.com/OWASP-London
๐บ YouTube: https://youtube.com/OWASPLondon
OWASP Ottawa @owaspottawa.bsky.social The OWASP Chapter for Canada's Capital region.
https://owasp.org/ottawa/
Join us for monthly meetups discussing a variety of security topics.
Robin @digi.ninja Hacker, coder, climber, runner, triathlete.
Always learning.
Co-flounder of SteelCon
PortSwigger Research @portswiggerres.bsky.social Web security research from the team at PortSwigger.
PortSwigger @portswigger.net We are a leading provider of software and learning on web security. We make Burp Suite and the Web Security Academy.
James Kettle @jameskettle.com Director of Research at @portswigger.net
Also known as albinowax
Portfolio: https://jameskettle.com/
Dafydd Stuttard @dafyddstuttard.bsky.social Founder and Chief Swig at PortSwigger. Creator of Burp Suite and the Web Security Academy. Author of The Web Application Hacker's Handbook.
David Paterson @djpaterson.dev Software Engineer at PortSwigger and Man City season ticket holder
Sam Stepanyan @securestep9.bsky.social OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon https://twitter.com/securestep9 https://infosec.exchange/@securestep9
Tib3rius @tib3rius.bsky.social Web App (mostly) Hacker | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) ๐บ๐ธ A mostly unserious person. @therealc3rul34n.bsky.social is bae ๐ฅฐ
Josh Grossman (tghosth ๐ป) @joshcgrossman.com Friendly AppSec Ghost ๐ป
https://appsecg.host
Dominique Righetto @righettod.eu ๐จโ๐ป AppSec enthusiast | ๐ถ Addicted to Shetland Sheepdogs | ๐ Open Source/AppSec/OWASP junkie | ๐ OWASP Secure Headers Project Leader.
๐ฉ Opinions mentioned are mine.
garthoid @garthoid.bsky.social Father,Husband,Software Security Architect, Ethical Hacker,Musician,& Karate Geek.OWASP Ottawa Chapter Leader. Trying to learn Kendo. Devious-Plan.com founder. He/Him
Mastodon is better @garthoid@infosec.exchange
๐๐จ๐ฆ
Gareth Heyes @garethheyes.co.uk Web security researcher at PortSwigger. Author of JavaScript for Hackers, Shazzer and Hackvertor.
https://garethheyes.co.uk/#latestBook
garethr @garethr.bsky.social VP Product @snyksec. @openpolicyagent Conftest maintainer. Developer, designer, product. Open source geek. Devops Weekly. @gdsteam alum. he/him.
Daniel Cuthbert @dcuthbert.bsky.social Ageing hacker, long time documentary photographer. Black Hat Review board. Now sitting on numerous government cyber security boards so I guess that means Iโve grown up right?
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her
https://shehackspurple.ca ๐ป
Mastering Burp Suite @mastering-burp.agarri.fr Tips and tricks for Burp Suite Pro ๐ ๏ธ
Not affiliated with @portswigger.net ยฉ๏ธ
Managed by @agarri.fr ๐ซ๐ท
Additional free resources ๐
http://hackademy.agarri.fr/freebies
Bjรถrn Kimminich @bkimminich.bsky.social IT Product Group Lead at Kuehne+Nagel; @owasp-juice.shop Project Leader; @owasp-de.bsky.social Chapter Co-Leader; @owasp.org Project Committee Chair; @magic.wizards.com Amateur Player @mull2five.bsky.social
Liran Tal @lirantal.com ๐ฆ Node.js Secure Coding: http://nodejs-security.com
๐ @GitHub Star
๐
@OpenJS Pathfinder award for Security
๐ฅ DevRel at @snyksec
Erlend Oftedal @webtonull.bsky.social Security researcher at Crosspoint Labs. AppSec. Tweets are my own and do not express the opinion of my employer. OWASP. retire.js
Jeremy Long @ctxt.bsky.social Builder, infosec, SCA and SAST enthusiast, blue team.
Founder of OWASP dependency-check.
https://github.com/sponsors/jeremylong
Dan @basic-123.bsky.social
SeanWrightSec @seanwrightsec.com Principal Application Security Engineer focused on all things #AppSec. Occasionally dabble in my own research. Also keen gamer and aspiring photographer.
Soroush Dalili ๐๐ @irsdl.bsky.social Hacker (ethical), web appsec specialist, trainer, tools builder & apps breaker, X: @irsdl
https://secproject.com/
https://soroush.me/
https://burpsuite.ninja/
Lukas Weichselbaum @webappsec.dev Leading Google's web security team.
Passionate about web security and making secure-by-default web development the norm. Contributed to web platfom security features like CSP, Fetch Metadata, COOP and Trusted Types.
Adriana Porter Felt @apf.bsky.social I like writing silly skeets, but that doesn't pay so I also make Google Chrome. mamรก, Eng Director, volunteer at Second Harvest. ๐บ๐ฒ๐จ๐ท
Twitter: @__apf__
Emily Stark @estark.bsky.social Encryption, HTTPS, certificates, web security, security UX, software engineering and management, TMI about parenting. Opinions are my own.
Eiji Kitamura / ใใผใ @agektmr.com Google Chrome DevRel Identity Tech Lead - Anything about browser identity features: passwords, OTPs, passkeys, identity federation, digital credentials, etc
terjanq @terjanq.me security enthusiast that loves hunting for bugs in the wild. co-founder and player of @justCatTheFish.
infosec at @google. opinions are mine.
From: https://twitter.com/terjanq
Philippe De Ryck @philippederyck.bsky.social I help developers protect companies through better web security
Web Security Academy @websecacademy.bsky.social Free web security training from PortSwigger.
Koto @kkotowicz.bsky.social Security ninja wannabe / board game geek / photon catcher
Michal ล paฤek @spazef0rze.bsky.social In your web, securing your app. Hacker, webdev, speaker, engineer. Security shoptet.cz, ex-report-uri.com, ex-teenager. HTTPS = How To Transfer Private Sh๐ฉ. Also https://infosec.exchange/@spazef0rze
harisec @harisec.bsky.social Interested in web security, bug bounties, machine learning and investing. SolidGoldMagikarp
Marco Squarcina @minimalblue.bsky.social Senior Scientist @TU Wien / Web & Mobile Security / #drumandbass DJ
๐ฉ with @mhackeroni.bsky.social We_0wn_Y0u kukhofhackerei Team Austria
๐ https://minimalblue.com/
Michele Spagnuolo @miki.it ๐ผ: Staff Information Security Engineer at Google. ๐ ๏ธ: Rosetta Flash, BitIodine. ๐: web security, โ , โฟ, finance. Data is the most dangerous form of opinion.
Ben Stock @benstock.bsky.social Tenured Faculty @c-i-s-p-a.bsky.social Helmholtz Center for Information Security
Dag Flachet @dagflachet.bsky.social Co-founder of Codific. Professor and board member of the Geneva Business School. Doctorate in behavioral psychology. Entrepreneur and Appsec champion.
Louis Columbus @louiscolumbus.bsky.social VentureBeat contributor on cybersecurity; husband & dad; writer and speaker on AI, cybersecurity, ERP, and zero trust.
LinkedIn: https://www.linkedin.com/in/louiscolumbus/
VentureBeat: https://venturebeat.com/author/louis-columbus/
Sandy Carielli @sandycarielli.bsky.social VP & Principal Analyst at Forrester, covering #appsec. Post about security, the Muppets, #NHLBruins, my beagle. All opinions are my own. she/her
Grant Ongers @rewtd.bsky.social AppSec guy, OWASP member for life and general beardness.
Brixes @brixes.bsky.social Co-founder at a data company.
d4d @zakfedotkin.bsky.social Zak Fedotkin
All thought are mine and mine alone
Orange Tsai @orange.tw This is ๐
Datadog Security Labs @securitylabs.datadoghq.com Read our Security Labs blog: https://securitylabs.datadoghq.com
Subscribe to our monthly newsletter: https://securitylabs.datadoghq.com/newsletters/
Eslam Salem @netcodex.bsky.social Manager, security research @ Datadog | he/him | Chess lover | Blackhat speaker |
ex Sqreen.io, Shieldfy.io | my website: https://eslam.io
Kennedy Toomey @kennedytoomey.bsky.social Application Security | Security Research and Advocacy @ Datadog
Lisa Forte @lisaforte.bsky.social Cyber security, climbing, caving and diving! ๐
UK_Daniel_Card @mrr3b00t.bsky.social
Patrick Howell OโNeill @patrickhowelloneill.com Journalist at Bloomberg News in DC. Signal: @howelloneill.01, email: patoneill1@bloomberg.net https://www.bloomberg.com/authors/AXb8dLPHBFc/patrick-howell-oneill
Pwnallthethings @pwnallthethings.bsky.social Just thinking out loud.
SwiftOnSecurity @swiftonsecurity.com computer security person. former helpdesk
Meredith Whittaker @meredithmeredith.bsky.social President of Signal, Chief Advisor to AI Now Institute
David Buchanan @retr0.id reverse engineering, cryptography, exploits, hardware, file formats, and generally giving computers a hard time
Fedi: @retr0id@retr0.id
Macroblog: https://www.da.vidbuchanan.co.uk/blog/
Katie Moussouris (she/her/she-hulk/she-ra)๐ป @k8em0.bsky.social Founder & CEO LutaSecurity @payequitynow MIT&Harvard visiting scholar, @MasonNatSec fellow, 1/2 Chamoru, 1/2 Greek all-American hacker
Andy Greenberg @agreenberg.bsky.social Writer for WIRED. Author of SANDWORM. Latest book, TRACERS IN THE DARK: The Global Hunt for the Crime Lords of Cryptocurrency, out now. agreenberg@wired.com. Andy.01 on Signal.
Joseph Menn @joemenn.bsky.social Washington Post alum covering hacking, disinformation and whatโs left of privacy. Author of books on the Cult of the Dead Cow, organized criminal hacking, and Napster. Pulitzer co-finalist 2024. Signal joemenn.01
Dmitri Alperovitch @dmitri.silverado.org Geopolitics, Russia, China, Cyber
Chairman @silverado.org
Author of WorldOnTheBrink.com
Host GeopoliticsDecanted.com podcast
Founder Alperovitch Institute for Cybersecurity Studies at Johns Hopkins SAIS
Co-Founder CrowdStrike
@DAlperovitch elsewhere
Marcus Hutchins @malwaretech.com threads.com/@malwaretech
https://linkedin.com/in/malwaretech
https://marcushutchins.com
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social Real-time historian of the late cyber capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies.
Also writing a book about Hacking Team and the history of government spyware.
โ๏ธ Signal: +1 917 257 1382
Kevin Beaumont @doublepulsar.com cybersecurity weather man. scanning the horizons for cloudy cyber. Expert at nothing except computer rubbish. Anti-ransomware since 2015.
Runa Sandvik @runasand.bsky.social Founder of Granitt, securing journalists and at-risk people around the world.
Kim Zetter @kimzetter.bsky.social Journalist - cyber/natn'l security. Speaker. Georgetown adjunct prof. Author - COUNTDOWN TO ZERO DAY: Stuxnet and the Launch of the World's First Digital Weapon
Signal: KimZ.42
https://www.zetter-zeroday.com
Alex Stamos @stamos.org CPO/CSO of Corridor.dev, teaching at Stanford.
Matthew Green @matthewdgreen.bsky.social I teach cryptography at Johns Hopkins. https://blog.cryptographyengineering.com
Lesley Carhart @hacks4pancakes.com I am eminently qualified to speak from experience about a variety of dumpster fires.
ICS DFIR at Dragos, martial artist, marksman, humanist, level 14 Neutral Good rogue, USAF retired. I post *very serious* things about infosec. Thoughts my own. Enby. ๐ณ๏ธโ๐
Dustin Volz @dustinvolz.bsky.social Washington correspondent for The New York Times focused on cyber conflict, digital espionage and intelligence. Prior stops at WSJ, Reuters, National Journal. https://www.nytimes.com/by/dustin-volz
Azeria @azeria-labs.com Founder of Azeria Labs, Trainer, Author of Blue Fox: Arm Assembly Internals & Reverse Engineering
John Hultquist @hultquist.bsky.social Mandiant Intelligence at Google. CYBERWARCON and SLEUTHCON founder. Johns Hopkins professor. Army vet.
Rob Joyce @rgblights.bsky.social Cyber guy. Former NSA cybersecurity director and chief of TAO. Lover of memes. Warning - occasional outrageous Christmas light content.
Zack Whittaker @zackwhittaker.com Security editor, TechCrunch
Signal: zackwhittaker.1337
My stories: techcrunch.com/author/zack-whittaker
My newsletter/blog: this.weekinsecurity.com
Eric Geller @ericjgeller.com Senior reporter at @CybersecurityDive.bsky.social covering all things digital security. I also co-host @hothtakes.bsky.social. | Send me tips: https://ericjgeller.com/contact.html
Ellen Nakashima @ellenwapo.bsky.social Intelligence and national security reporter at The Washington Post. Reach me securely on Signal at Ellen.626.
Patrick Gray @patrick.risky.biz https://risky.biz/
J. A. Guerrero-Saade (JAGS) @jags.bsky.social VP of Intelligence and Security Research, Senior Technical Fellow (AI) @ SentinelOne.
Distinguished Fellow and Adj Professor @ Hopkins SAIS Alperovitch Institute. Three Buddy Problem Co-Host. LABScon Founder, Cyber Paleontologist, Fourth-Party Collector.
Chris Bing @chrisbing.bsky.social Cyber, natsec and foreign affairs. Formers with ProPublica, Reuters and CyberScoop
https://bing-chris.medium.com/how-to-contact-me-d2fd4bd3ed7b
Jason Kikta @kikta.net // Making it up as I go
// JHU SAIS @alperovitch.institute adjunct
// @istorg.bsky.social adjunct sr tech advisor
// Former USCYBERCOM/CNMF
// Retired US Marine Corps
// Personal views and invective
Bill Marczak @billmarczak.org senior researcher at @citizenlab.ca
chompie @chompie.rip hacker, poster, weird machine mechanic
https://chompie.rip
Catalin Cimpanu @campuscodi.risky.biz โ Cybersecurity reporter
โ
Newsletters at Risky Business
#infosec #cybersecurity
https://risky.biz
Joe Slowik @pylos.co Threat Intel / CTI / OT / ICS / Critical Infra stuff along with other things. I genuinely care, and wish others did too.
Website: pylos.co
Training/Consulting: paralus.co
Horkos @wylienewmark.bsky.social waking up everyday in a full sprint. cyber(punk) & counterintelligence. bloody inertia interspersed with bouts of bloody frenzy. i see kanly today in everything.
#FUZZYSNUGGLYDUCK
opinions are my own.
ลukasz @maldr0id.bsky.social Military-grade reverse engineer @ Google, working on Android malware
Got mistaken for a member of Project Zero once.
Everything here is my own opinion
he/him โจ๐๐ฆ
gab ๐บ๐ฆ๐ต๐ธ @gabagool.ing fka @gabbyroncone on twitter. mission tech lead for RU & Eastern European APT ops @Google. views expressed here are mine, not my employerโs. she/her.
Tom Uren @tom.risky.biz Author of the Seriously Risky Business cyber security newsletter
Greg Otto @gregotto.bsky.social @gregotto from twitter, now on bluesky. Editor-in-Chief at CyberScoop. Host of Safe Mode. Better with words than I am with code.
MITRE ATT&CK @attack.mitre.org MITRE ATT&CKยฎ - A knowledge base for describing the behavior of adversaries. Replying/Following/Reposting โ endorsement.
Selena Larson @selenalarson.bsky.social loves dogs, sports, memes. she/her. podcaster. "bluesky's humblest resident nailfluencer ๐
" - Jerry
my heart is in the west ๐ต๐ views mine.
evacide @evacide.bsky.social Director of Cybersecurity @eff.org
Co-founder of @stopstalkerware.bsky.social
These opinions are my own, not my employer's
I did a TED talk once
Max Smeets @maxwsmeets.bsky.social Author of No Shortcuts & Ransom War
Co-director Virtual Routes (https://virtual-routes.org/), previously ECCRI
Managing Editor Binding Hook (https://bindinghook.com)
Senior Researcher, ETH Zurich
Allan โRansomware Sommelierโ Liska @ransomwaresommelier.com Recorded Future - Ransomware Researcher
Owner @greenarcher.io - Yours Truly, Johnny Dollar | The Press Guardian | The Clock | The Green Archer
Weird mix of security, comics, photography and wine!
www.greenarcher.io
Lea Kissner @leak.bsky.social Security, privacy, respect. Was the Twitter CISO until it was terrible. Now LinkedIn CISO. they/them
Alex Ionescu @ionescu.bsky.social Windows Internals Author, Developer, Reverse Engineer, Security Researcher, Speaker, Trainer, and most recently Nation State Hacker.
Core OS Platform Developer at Apple, Hyper-V Vendor at Microsoft, Chief Architect at CrowdStrike and now Director at CSE.