Hey @leak.bsky.social, I've tried to reach you via mail, lately also connecting to your LinkedIn profile. Could you get back to me?
Christian Folini
@christian-folini.ch
Web application security guy with a passion for OWASP's open source WAF projects and National Cyber Strategy. Maintains "Swiss Cyber Security" starter pack and cherishes his small collection of medieval helmets.
Florian Schuetz from Swiss NCSC opening the @1ns0mn1h4ck.bsky.social conference: "Sovereignty is not autarky, sovereignty is freedom to choose." If you're around at the conference, come and say hello. Happy to talk.
I'm very lucky that @minimus.io considers the work I do for Kubernetes to be part of my job. That isn't true for most maintainers. Projects are failing or suffering attacks because of a lack of contributors from companies built on top of them, and that's *everyone's* problem. dev.to/katcosgrove/...
When Projects Fail: Why Companies Should Treat Open Source as Infrastructure
Maintaining an open source project is hard. It requires managing a group of people who are largely...
dev.to
Switzerland built a secure alternative to BGP. The rest of the world hasn't noticed yet www.theregister.com/2026/03/17/s...
Switzerland built an alternative to BGP. Nobody noticed
Feature: SCION: Proven in banking and healthcare, slow to spread everywhere else
theregister.com
Ein halbes Jahr ist seit dem Launch von #Apertus verstrichen. Für die @nzz.ch am Sonntag habe ich untersucht, was daraus geworden ist. Das Fazit ist ernüchternd: Kaum jemand nutzt es. Und ausgerechnet der wichtigste Partner setzt auf Anthropic und OpenAI. www.nzz.ch/wirtschaft/n... (Geschenk-Link)
Schweizer KI Apertus: ETH-Projekt wird kaum produktiv genutzt
Ein halbes Jahr nach dem Launch nutzt noch kaum jemand das Schweizer KI-Modell Apertus. Es liegt nicht nur am fehlenden Geld.
nzz.ch
Welcome Anastasija Collen as our keynote speaker at #INSO26! She reveals how security debt is driven more by environment and behavior than by tools. Last tickets available: https://ow.ly/Y94V50YsPlu #Infosec #CyberConference
Is the bombing of the elementary school in Iran a case study in how AI-assisted warfare outpaces the safeguards international humanitarian law (IHL) demands during armed conflict?
Thought I'd sahre the Swiss Cyber Security starter pack again. Am I missing somebody? go.bsky.app/4xD359p
A VC and some big-name programmers are trying to solve open source's funding problem, permanently | TechCrunch techcrunch.com/2026/02/26/a...
A VC and some big-name programmers are trying to solve open source's funding problem, permanently | TechCrunch
A group of well-known open source programmers and a VC have launched the Open Source Endowment. They hope this new method will provide funding for good.
techcrunch.com
PSYOP 2026: no need to drop leaflets when you can hijack push notifications. Israel hacked BadeSaba, one of Iran's most popular apps, with 37 million installs, used to track daily prayer times.
„Palantir has already lost the only contest that matters: the one for public perception. […] they apparently never thought to search “The Streisand Effect.”“ Palantir Sues Swiss Magazine For Accurately Reporting That The Swiss Government Didn’t Want Palantir www.techdirt.com/2026/02/27/pal…
Feeling the burn: When open source developers decide to take a break
Feeling the burn: When open source developers decide to take a break
A week off for vacation? The nerve of some people Opinion If you want to see the definition of "workaholic," you can't do better than to look at your typical senior open source developer or maintainer. I should know, I'm a workaholic too. I know my kind.…
dlvr.it
Switzerland’s NCSC boosts operational capabilities, mandates cyberattack reporting on critical infrastructure industrialcyber.co/reports/swit...
Switzerland’s NCSC boosts operational capabilities, mandates cyberattack reporting on critical infrastructure - Industrial Cyber
Switzerland’s NCSC boosts operational capabilities, implements mandatory reporting of cyberattacks on critical infrastructure in 2025.
industrialcyber.co
🔥 OWASP CRS is evolving! Introducing #CRSLang — a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors. Check it out 👉 coreruleset.org/2026... #WAF #AppSec #OWASP #ModSecurity
This is huge!! #WAF #DevSecOps
🔥 OWASP CRS is evolving! Introducing #CRSLang — a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors. Check it out 👉 coreruleset.org/2026... #WAF #AppSec #OWASP #ModSecurity
“We should be questioning how power formed in a way that enabled a handful of people—in service of their quarterly returns—to make socially significant decisions on behalf of everyone else, without scrutability, without clarity, and without democratic oversight.” - @meredithmeredith.bsky.social
I dreaded this moment a lot: Moving to a new phone. But as much as I loved my DOOGEE phone, the security update policy is not sustainable / not existing so I moved to a Fairphone yesterday. Long 🧵
I show how malicious Claude Code skills can spread across infrastructure. Approve one skill → it gets shell access → copies itself to every host in your SSH config. Skills are code. Treat them that way. blog.lukaszolejnik.com techletters.substack.com/p/techletter...
Security, Privacy & Tech Inquiries
Lukasz Olejnik on security, privacy, Web, technology and technology policy matters.
blog.lukaszolejnik.com
My comments in @WIRED about AI-powered information operation systems. The threat aren't bots posting fakes but coordinated, persistent, human-like agent networks that manufacture the appearance of debate, consensus, disagreement. Eloquent, adaptable, detail-heavy, threads.
Dream of speaking at OWASP? Join our FREE session, “So You Want to Be an OWASP Speaker!” Learn to nail your CfPs, deliver epic talks, and own the stage. Curiosity required, lifelines optional! owasp.glueup.com/eve... #OWASP #AppSec #upskill #publicspeaking #cybersecurity
The recording of the 2nd online event on #ECollecting has been published. We've also launched a dialogue platform and initiated two discussions. github.com/swiss/e-coll... Discussion 1: Political Balance (of E-Collecting) Discussion 2: Can an opt-out for the paper process really be avoided?
This link will take you to a page that’s not on LinkedIn
lnkd.in
With the rate @cloudflare.social goes down these days, they should totally invest in revamping their error page.
#react2shell (CVE-2025-55182) is detected by default by OWASP CRS 3 and CRS 4 alike. Rules in question are * 934100 #CRS3 and #CRS4 * 934130 CRS4 * 942550 CRS4 Test payload in graphic below. Other payloads can be tested via the public CRS sandbox. Kudos to Vincent-TW for the groundwork.
#ModSecurity / @owasp.org CRS engine puzzle! A solution has the potential to improve the performance across millions of servers.
Performing a major upgrade of your OWASP CRS #WAF rules usually means you need to lower your defenses. The new "netnea-crs-upgrading-plugin" that allows you to perform this transition in a smooth and calculated way without the need to raise your anomaly threshold. www.netnea.com/cms/2025/11/...
The new netnea-CRS-Upgrading-Plugin: Simplifying the Migration from CRS v3 to v4 – Welcome to netnea
netnea.com
Whenever a big cloud service goes down I think of the Swiss gov exec who ridiculed me on a panel when I claimed it's a little known secret, but it's actually possible to run your own servers without any dependency to somebody else's computer.
For a couple of days I see a new wave of attacks hitting our WP installation. Hundreds of IPs hitting /wp-login.php. Like 10 times the normal amount of requests despite fail2ban blocking them really fast. The best defense (and there are many layers of defense) has been installing WP in a subfolder.