Snyk Learn @Snyksec 🎉 Previously Cloud Foundry Tanzu @Pivotal @VMwareTanzu 🙏

Joined July 2008
456 Photos and videos
Alex retweeted
Calling all Miami bound hackers and AI builders 🌴🇺🇸 All about ToxicSkills, hacking MCP servers and more in this AISecEng Miami chapter meetup 👇
Today is the day! If you're in the Miami area, join us for an AI Security Meetup. There's still time to secure a spot for free and learn about Rules, Skills, Hooks & MCP—and how to use them safely with @_clarkio from @snyksec and @rodsoto meetup.com/ai-security-engin…
2
2
560
Alex retweeted
Jun 8
Snyk is heading to the Silicon Valley Cybersecurity Conference! Join us June 11th at San José State University to learn more about our Snyk Learn and University Partnerships Program. Learn more here: svcc-svcsi.org/
1
302
Alex retweeted
Jun 3
For the first time the AI Engineer World's Fair has a dedicated AI Security track and Snyk is proud to be the presenting partner. Join us in San Francisco, Jun 29 – July 2 for sessions built around the belief that security starts at inception. More here: snyk.io/events/ai-engineer-w…
1
287
Alex retweeted
May 26
See you in the Fan Zone ⚽️ 🏆 We're bringing the Snyk Connect community together. Part tournament, part tailgate, all defense. Live hacking and head-to-head AISec challenges, stadium-style eats, and giveaways worthy of a champion. Grab your spot here: wc.snyk.io/
1
3
454
Lots of supply chain attacks right now. If you use pnpm v11 it will stop updates to packages that were published less than 24 hours ago. This protects you because most supply chain attacks are fixed within a few hours (at least for major packages). Couple this with Snyk and Socket for extra protection.
3
4
27
2,062
Alex retweeted
May 7
you ready for @AISecSummit in London next Thursday? 🤩 Join us to learn how agentic security looks like from the eyes of CISOs, AppSec and builders of next-gen security tools Grab your ticket here: aisecuritysummit.com/events/…
1
1
317
PLG people start taking notes 📝 Snyk followed the same pattern in the early days with the “don’t break the build” approach with test limits.
Apr 29
Replying to @Mugilan_SS @OpenAI
It’s the small things. When we designed this the tradeoff was between a good experience or optimize for margin and not allow to draw more usage than you technically have. We chose to optimize for the experience as it’s really annoying to have your agent interrupted midway.
45
Alex retweeted
The Vercel security breach is a reminder that each and every SaaS tool your team uses IS a security risk of its own - especially if they need broad data access to eg email, internet docs etc (many AI tools do just this) Security teams onboarding new vendors happens for a reason.
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/verce…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
45
81
973
166,293
Alex retweeted
Apr 14
Are you an open source maintainer? 👋💜 If so, we’d love to support your project by providing you with complimentary access to our industry-leading developer security tooling and infrastructure! snyk.io/open-source/ Check out Snyk's Free Security for Open Source program
3
9
1,670
There will be many opportunities to gain the AI Security Engineer Foundations credential at Snyk events and global conferences🎓💻🤖
Apr 9
Congratulations on being one of the first people in the world to gain this credential for AI Security Engineer Pratul K. Keep learning about AI on Snyk Learn learn.snyk.io/catalog/?type=…
1
1
1,053
Alex retweeted
Mar 31
🚨 ACTIVE SUPPLY CHAIN ATTACK Two malicious versions of `axios`, the npm package with 300M weekly downloads, were just published via a hijacked maintainer account and have deployed a cross-platform RAT to affected machines. Affected: `axios@1.14.1` and `axios@0.30.4` 👇🧵
3
29
130
20,202
Alex retweeted
Mar 24
Replying to @karpathy
The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: snyk.io/articles/poisoned-se…
16
151
1,054
323,796
Alex retweeted
Mar 23
Today, we’re excited to announce Snyk Agent Security and the general availability of Snyk Evo AI-SPM. 🚀 You cannot slow down AI coding agents, but you cannot let them bypass your security stack either. It’s a shadow AI crisis. 👾 See the fix here : evo.ai.snyk.io/
1
3
4
729
Alex retweeted
if you're building CLI apps in Node.js then you probably want to install my Node.js command line apps best practices Use Tessl skills manager: $ npx tessl i lirantal/nodejs-cli-best-practices
2
2
7
722
Alex retweeted
Ready to share your AI Security expertise? We’re inviting speakers for upcoming meetups worldwide. Apply now 👉 form.typeform.com/to/LSyhDf1…
1
156
Alex retweeted
Feb 25
Are you attending RSA? Good news: we've got your itinerary sorted ✅ From rooftop cocktails to chats with Team USA soccer legends, we’ve built a roster of can’t-miss events, hands-on trainings, and VIP experiences ⚽️ Stay tuned for more details to come!
1
1
197
“The best security uses both AI and deterministic analysis” << this is the key takeaway. Security has always been about layering 🔒 AI can add security (and insecurity!) layers throughout the SDLC.
Feb 23
The market says Anthropic just ate the security industry’s lunch 🫠 The reality? Finding bugs is the easy part. Fixing them at scale without breaking your entire stack is the real challenge. Here’s what Claude Code Security actually means for AppSec: snyk.io/articles/anthropic-l…
81
Alex retweeted
Agents introduced a new supply chain: skills with privileges. @snyksec research: ~4k public skills, over a third had security issues Blog research: labs.snyk.io/resources/agent… Curious — are teams allowing skills or blocking them?
2
3
454
Alex retweeted
Feb 18
We’re thrilled to announce our partnership with Cline, bridging the gap between autonomous speed and security. You can now maximize the efficiency gains of AI coding without compromising trust 💥
1
1
5
519