Doyensec @doyensec.bsky.social Doyensec works at the intersection of software development and offensive engineering. We discover vulnerabilities others cannot, and help mitigate the risk.
Javan Rasokat @javanrasokat.bsky.social Product Security @ Sage, Security Research & Speaker, OWASP Contributor, Hacker & Creator.
Personal blog: https://about.javan.de
Kevin Johnson @secureideas.bsky.social I am a nerd that started a company almost 15 years ago. Secure Ideas is a security consulting firm focused on helping clients have the best penetration testing experience. I am also an IANS faculty member and currently an OWASP global board member.
Spyros @spyrosec.bsky.social open source | security | automation | founder smithy.security | maintainer opencre.org
OWASP Dependency-Track @dependencytrack.bsky.social Open Source SBOM Analysis Platform. Reduce Supply Chain Risk. #OWASP #SBOM #SaaSBOM #HBOM #VEX #SoftwareSupplyChain
https://dependencytrack.org/
Datadog Security Labs @securitylabs.datadoghq.com Read our Security Labs blog: https://securitylabs.datadoghq.com
Subscribe to our monthly newsletter: https://securitylabs.datadoghq.com/newsletters/
Semgrep @semgrep.com Semgrep is a code scanning platform for finding first and third-party security vulnerabilities in your code base.
PortSwigger @portswigger.net We are a leading provider of software and learning on web security. We make Burp Suite and the Web Security Academy.
Ulises Gascón @ulisesgascon.com #OpenSource Maintainer (@nodejs.org, @expressjs.bsky.social, Lodash, Yeoman...), #TC39 Delegate and #Maker | He/Him
Rafael Gonzaga | Node.js @rafaelgss.dev Node.js Technical Steering Committee member
Socket @socket.dev Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS.
https://socket.dev
Mike Samuel 🟣 @mvsamuel.bsky.social Programming languages person focused on software systems problems.
Previously, first frontend engineer on Google Calendar, and was a security engineer who worked on the industrial-strength Mad Libs undergirding Gmail.
Pro-trans-rights is pro-family.
naugtur @naugtur.pl Working on supply chain security for JS. LavaMoat and Endo contributor. meet.js Poland organizer. Node.js user since v0.8.
TC39 noobie.
Addicted to teaching.
https://naugtur.pl
Matt Travi @matt.travi.org DivOps Engineer. OSS Maintainer: semantic-release, repository-settings, form8ion
bryan english @bengl.dev 🇨🇦
Staff Software Engineer - Datadog APM
(he/him/his)
Dad
Royal Oak, MI, USA
https://bryanenglish.com
Eslam Salem @netcodex.bsky.social Manager, security research @ Datadog | he/him | Chess lover | Blackhat speaker |
ex Sqreen.io, Shieldfy.io | my website: https://eslam.io
Jakub Andrzejewski @jacobandrewsky.bsky.social 💻 Fullstack Developer
🏎️ @GoogleDevExpert in Web Perf
💚 @nuxt.com EcosystemTeam
👥 Ambassador @Storyblok, @algolia, @cloudinary, @supabase
Adam Baldwin @evilpacket.net Hacker / Farmer / Builder / Breaker
clickity, hackity, pwned.™
More info: https://evilpacket.net
Guy Podjarny @guypo.com Founder of Tessl (and Snyk), reimagining software development for the AI era. Also a co-host of The AI Native Dev podcast, an angel investor, and an occasional speaker & writer.
Nicholas C. Zakas @humanwhocodes.com Creator of @eslint.org and @bredbox.app. Author. Speaker. Advisor. Coach. GitHub Star.
Mastodon: https://fosstodon.org/@nzakas
Blog: https://humanwhocodes.com
Coaching: https://humanwhocodes.com/coaching
Michaël De Boey @michaeldeboey.be 👨💻 Freelance full stack #JavaScript / @TypeScriptlang.org & @React.dev engineer 🤓
📈 Index fund investor #FIRE 🌱🔥
🎧 Drum&Bass DJ 🎛️
😻 catlover 😻
Michael Dowling @mtdowling.bsky.social Principal engineer at AWS where I work on Smithy
Michael Zasso @targos.dev
Marcin Hoppe @marcinhoppe.bsky.social I am a computer programmer. I enjoy maintaining software, fixing bugs and debugging. I also know a few things about information security.
Outside of work I am a family guy. I like good coffee. I play tennis.
Vladimir de Turckheim @v2t.dev Web, AI Agents and LLM - often Node.js diagnostics
Ghulam Mohiuddin Malik @ishowcybersecurity.com Cybersecurity Educator | Ethical Hacker
AI • Cloud • Network Security
Bug Bounty & Real-World Attacks
Helping people stay safe online
Kennedy Toomey @kennedytoomey.bsky.social Application Security | Security Research and Advocacy @ Datadog
Dominic White @singe.bsky.social Hacker at Orange Cyberdefense's SensePost Team
https://hello.singe.za.net/
Jeroen @commjoenie.bsky.social Project leader #OWASP #WrongSecrets, dad, PSA
Dennis Irsigler @irsigler.dev Cloud Security Engineer | Protecting Cloud and Shitposting as a Service
Kelsey Hightower @kelseyhightower.com Minimalist
Mrs. Y @mrsyiswhy.bsky.social Security Bene Gesserit and professional nerd stalker. Likes long walks in hubsites and searching for spice. Views: definitely those of my puppet overlords. Location: kernel space https://linktr.ee/chubirka
dmnk @dmnk.bsky.social 【DΞCOMPILΞ NΣVΞR】
Android Red Team @google
Fuzzing @aflplusplus.bsky.social
CTF @enoflag
(opinions my own)
Felix Garriau @felixgarriau.bsky.social Cofounder aikido.dev a no-nonsense security platform /📍Antwerp based 🇧🇪
seven @sevensec.bsky.social unsecurity engineer
exploiting, reversing, gaming, coffee
Troy @troymarshall.bsky.social Product Security | Privacy | AI Safety | Digital Trust
Phill @psavage.net Building Corporate Retreats for remotely distributed tech teams, based in Thailand. Runner.
ejcx @ejcx.bsky.social Co-founder of Runreveal.com. The simple security data platform.
Burp Suite @burpsuite.bsky.social Burp Suite is the leading software for web security testing.
cailin @feralcybersec.com
SSW @anocendi.xyz AIML Cloud Security Professional
Also find me @anocendi@infosec.exchange
Phyu @phyushin.bsky.social
SirAppSec @sirappsec.bsky.social PayPal API Security Engineer
@SirAppSec
github.com/sirappsec
sulliwan @sulliwan.bsky.social Screaming into the void. Opinions dictated by a cosmic roulette wheel.
shellsharks @shellsharks.com Infosec researcher | more about me @ https://shellsharks.com
@shellsharks@shellsharks.social on Mastodon
Anant Shrivastava @anantshri.info Researcher | Trainer | Security Professional | Developer | Admin
ike @ike.io I identify as curious. Obsessed with poetry, irises, boats. Dad, coder, ᏥᏣᎳᎩ.
Most of my posts are #POSSE from my #indieweb site: https://ike.io
Giuseppe Maddiona @gppmad.bsky.social Developer. Passionate about applied cryptography.
Tib3rius @tib3rius.bsky.social Web App (mostly) Hacker | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) 🇺🇸 A mostly unserious person. @therealc3rul34n.bsky.social is bae 🥰
Nick Frichette @frichetten.com Staff Security Researcher @datadoghq | DEF CON/Black Hat USA main stage speaker | he/him | OSCP OSWE | I turned hacking AWS into a career | Tweets are my own | Created https://hackingthe.cloud
Matt Johansen @mattjay.com Friendly neighborhood cybersecurity guy | expect infosec news, appsec, cloud, dfir. | Long Island elder emo in ATX.
vulnu.com <- sign up for my weekly cybersecurity newsletter
ChiefGyk3D @chiefgyk3d.com #Cybersecurity and #InfoSec by Trade and content creator by night for #Tech, Cybersecurity, #IT, #Linux, #AmateurRadio, and #GamingonLinux
Twitch | YouTube | TikTok | Mastodon
CISSP
Socials and Tipping: https://links.chiefgyk3d.com/socials
#OpenSource
Tal Skverer @taltechtreks.com Security Researcher | Blog writer | Hacker | DEFCON speaker | Gamer | Silly stuff lover.
https://taltechtreks.com/
Sam Stepanyan @securestep9.bsky.social OWASP London Chapter Leader. #OWASP Global Board Member. OWASP #Nettacker Project Leader. #AppSec Consultant, #CISSP. Follow me on Twitter/X and Mastodon https://twitter.com/securestep9 https://infosec.exchange/@securestep9
Bar Hofesh @bararchy.bsky.social A father, CTO & Co-Founder at BrightSec.
Security researcher and lover of technology .
he/him. 🏳️🌈 safe space
#ADHD, 🇮🇱
Sands Discord: https://discord.gg/XVW66nW2bN
Dirk Lemstra 🧙♂️ @dirk.lemstra.org Open source maintainer of @imagemagick.org and its .NET Standard/Framework library called Magick․NET.
Microsoft #MVP | GitHub ⭐
🇳🇱 https://github.com/dlemstra 💖🇹🇼
David S Morse @dsmorse.bsky.social Silicon Valley born geek, Docker community leader for COS, @devOpsDaysRox Organizer, Director of Cloud and Platform Engineering for for Parry Labs
ramkumar @handle.invalid Security Software Engineer. Forever toggling between being a jack of all trades and a master of one.
Blog: https://ramenhost.dev
dragosr @dragostech.bsky.social Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense.
Host of CanSecWest, and PacSec.
Security audits, code, IR, LLM, red team consulting.
Specialize in Firmware, and RF.
VA7MOV
Graylog @graylog.bsky.social 🌍 Trusted Threat Detection & Incident Response solutions. Experience the difference with our unmatched capabilities. #SIEM #APISecurity #LogManagement #InfoSec
Anton Sankov @asankov.dev Senior Software Engineer at Cast AI. Working on Containers and Kubernetes Security
José Carlos Chávez @jcchavezs.bsky.social Software Security Engineer @ Okta
Loving father / Peruvian / Security Software Engineer @okta. Llamas, @OWASP @corazaio co-leader and #WASM enthusiast.
OWASP Threat Dragon @threatdragon.bsky.social Threat Dragon threat modeling tool from OWASP
owasp.org/www-project-threat-dragon/
ZAP by Checkmarx @zaproxy.org The Worlds Most Popular Web App Scanner.
Simon Bennetts @psiinon.bsky.social ZAP Project Lead
Liran Tal @lirantal.com 🦄 Node.js Secure Coding: http://nodejs-security.com
🌟 @GitHub Star
🏅 @OpenJS Pathfinder award for Security
🥑 DevRel at @snyksec
mbg @mbrg0.bsky.social Breaking AI. Building @zenitysec, lead @owaspnocode, columnist @DarkReading
PentesterLab @pentesterlab.com We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!
TomNomNom @tomnomnom.com Computer booper and food enthusiast. He/him.
Izar Tarandach @threatmodeling.dev Threat model and prosper! 🖖
OWASP pytm Leader | OWASP Events Committee Chair (2024)- E Matthew Coles @eternewbie.bsky.social Security professional. Author. Speaker. Mentor.
Always a newbie, continual learner. Avid gamer.
#threatmodeling | OWASP pytm | The Security Table podcast
Uncle Joe @sydseter.com Co-leader OWASP Cornucopia. If you like what we do for open source, visit our code repository https://github.com/OWASP/cornucopia and give us a star ⭐
🌈 «Difference is of the essence of humanity» 🦄 – John Hume
#appsec #owasp #cornucopia #threatmodeling
garthoid @garthoid.bsky.social Father,Husband,Software Security Architect, Ethical Hacker,Musician,& Karate Geek.OWASP Ottawa Chapter Leader. Trying to learn Kendo. Devious-Plan.com founder. He/Him
Mastodon is better @garthoid@infosec.exchange
📍🇨🇦
@vanderaj.bsky.social @vanderaj.bsky.social
Josh Grossman (tghosth 👻) @joshcgrossman.com Friendly AppSec Ghost 👻
https://appsecg.host
OWASP ASVS @asvs.owasp.org
Adam Shostack @adamshostack.bsky.social Threat modeling. BH Review Board. Affiliate Professor, UW. Fixed autorun. Helped create CVE.
Not sure why we're building graphs on yet another (effectively) centralized system. https://infosec.exchange/@adamshostack
Chris @brompwnie.bsky.social Likes to hack things.
GitHub.com/brompwnie
Christophe Tafani-Dereeper @christophetd.fr Cloud and container security • Security research and open source at Datadog
🇨🇭🇫🇷
https://christophetd.fr
aikido | no bullsh*t security for devs @aikidosecurity.bsky.social No bullsh*t security for devs.
Secure code, cloud, and runtime in one central system. fix issues automatically.
Get back to building. 🔗 aikido.dev
Dan Goodin @dangoodin.bsky.social Cybersecurity Reporter, Ars Technica: https://arstechnica.com/author/dan-goodin/ Hungry for tips. Text me on Signal: DanArs.82. "The world isn’t run by weapons anymore, or energy, or money. It’s run by little 1s and 0s, little bits of data."
SwiftOnSecurity @swiftonsecurity.com computer security person. former helpdesk
Christian Folini @christian-folini.ch Web application security guy with a passion for OWASP's open source WAF projects and National Cyber Strategy.
Maintains "Swiss Cyber Security" starter pack and cherishes his small collection of medieval helmets.
Dag Flachet @dagflachet.bsky.social Co-founder of Codific. Professor and board member of the Geneva Business School. Doctorate in behavioral psychology. Entrepreneur and Appsec champion.
Jeremy Long @ctxt.bsky.social Builder, infosec, SCA and SAST enthusiast, blue team.
Founder of OWASP dependency-check.
https://github.com/sponsors/jeremylong
Björn Kimminich @bkimminich.bsky.social IT Product Group Lead at Kuehne+Nagel; @owasp-juice.shop Project Leader; @owasp-de.bsky.social Chapter Co-Leader; @owasp.org Project Committee Chair; @magic.wizards.com Amateur Player @mull2five.bsky.social
kingthorin_rm @kingthorin.bsky.social IT Sec guy, zaproxy co-lead, WSTG co-lead, VWAD co-lead, OWASP Ottawa volunteer, Hac≺3r, supporter of oxford commas, #INTJ. (Opinions == mine) 🍁
Black Hills Information Security @bhinfosecurity.bsky.social Specializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
blackhillsinfosec.com & poweredbybhis.com
Dafydd Stuttard @dafyddstuttard.bsky.social Founder and Chief Swig at PortSwigger. Creator of Burp Suite and the Web Security Academy. Author of The Web Application Hacker's Handbook.
Mike Thompson @appsecbloke.com Information security leader, vendor adversary, occasionally opinionated.
Shitposts, memes, music and thoughts on the state of the place.
linktr.ee/appsecbloke | https://soundcloud.com/michael-thompson-70891340
Laura Bell Main @ladynerd.bsky.social CEO at SafeStack | coauthor of Agile Application Security and Security for Everyone | Host of Build Amazing Things (securely) | #appsec nerd | mom
OWASP Juice Shop @owasp-juice.shop Probably the most modern and sophisticated insecure web application. Only we offer a 100% @owasp.org Top Ten incompliance guarantee! Skeets by @bkimminich.bsky.social
OWASP® Foundation @owasp.org We improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
Lukas Weichselbaum @webappsec.dev Leading Google's web security team.
Passionate about web security and making secure-by-default web development the norm. Contributed to web platfom security features like CSP, Fetch Metadata, COOP and Trusted Types.
Adriana Porter Felt @apf.bsky.social I like writing silly skeets, but that doesn't pay so I also make Google Chrome. mamá, Eng Director, volunteer at Second Harvest. 🇺🇲🇨🇷
Twitter: @__apf__
Emily Stark @estark.bsky.social Encryption, HTTPS, certificates, web security, security UX, software engineering and management, TMI about parenting. Opinions are my own.
Eiji Kitamura / えーじ @agektmr.com Google Chrome DevRel Identity Tech Lead - Anything about browser identity features: passwords, OTPs, passkeys, identity federation, digital credentials, etc