One week to go. ⏳ AI helps us build faster — but it can also help attackers find vulnerabilities faster. Join @niels.fennec.dev for practical .NET AppSec demos, AI-assisted security testing, and live Q&A. Sep 24, 1 PM CEST: www.hypeless-ai.net #HypelessAI
Niels Tanis
@niels.fennec.dev
Software Security Researcher & Engineer @ Tidalis Former @ Veracode Microsoft MVP Familyman & Renovator @ N28
Security is built or broken with every development decision. Meet the #UCP26 experts bringing practical insights into software security: 👉 @programmeral.com, Sander Molenkamp, Christian Schabetsberger and @niels.fennec.dev Explore their sessions: prague.updateconference.net/en/2026/sche...
Want to know what’s coming in the next #HypelessAI episode? Hear it directly from @niels.fennec.dev. 👇 Join us live on September 24 and learn how #AI can help you uncover and fix vulnerabilities in your .NET applications before attackers do. Get your spot 👉 www.hypeless-ai.net #AppSec #Dotnet
What happens when #AI makes your code faster, but your #security risks grow faster too? Find out in the next #HypelessAI livestream, featuring 🎙️ @niels.fennec.dev, Microsoft MVP and software security expert. 📅 Thursday, Sep 24 👉 Save the date and register here: hypeless-ai.updateconf.net
Trusted publishing is the way to go if you can
Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime - .NET Blog
NuGet API key durations will be reduced to 30 days starting August 17th. This change will significantly strengthen the integrity of the NuGet supply chain.
devblogs.microsoft.com
It definitely was a year of change and that makes me really happy to see that I got renewed as MVP! Community and public speaking is the thing I still enjoy a lot and will continue on doing! Congratulations to all other MVP's that got renewed as well! #mvpbuzz
In amongst today's big chungus of a patch Tuesday there are some .NET updates, so let's begin #dotnet #aspnetcore #patchTuesday
If you're using MessagePack-CSharp directly you should update your dependency, as they've fixed 12 vulnerabilities today. github.com/MessagePack-...
shipped three new build warnings so your dotnet SDK can finally tell on itself. you're welcome jamiemagee.co.uk/blog/a-new-w...
A new way to catch a vulnerable .NET SDK
When NuGet finds a vulnerable package in your project, it tells you. NU1901 through NU1904 have warned about CVEs in your dependencies for a while now. The SDK that runs the build, though? That’s been...
jamiemagee.co.uk
🚀 NuGet Pruning is cleaner restores and fewer false positives. Better security signals. In .NET 10, NuGet package pruning removes platform-provided dependencies from your graph, so you only see what actually matters: actionable alerts. Learn more: devblogs.microsoft.com/dotnet/nuget...
NuGet Package Pruning: Cleaner Dependencies and Actionable Vulnerability Reports - .NET Blog
Package pruning in .NET 10 removes platform-provided packages from your dependency graph. With transitive auditing enabled by default, projects with these defaults have 70% fewer transitive vulnerabil...
devblogs.microsoft.com
NDC Copenhagen is only 3 weeks away! 4 days, 55 speakers, 65 sessions, 7 workshops. All happening 1-4 June at Øksnehallen in Copenhagen. Whether you're into AI, .NET, architecture, security, or modern software practices, there's a track for you there! Tickets 👉 ndccopenhagen.com
📣.NET 10.0.7 Out-of-Band Security Update - .NET Blog Microsoft released .NET 10.0.7 as an out-of-band security update to address CVE-2026-40372. hubs.li/Q04dbWjB0 #dotnet
.NET has an out of band update today to fix CVE-2026-40372, an Elevation of Privilege, which, in some cases, could allow an attacker to forge authentication tickets, or decode authentication tickets or other protected data. github.com/dotnet/annou...
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege · Issue #395 · dotnet/announcements
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege Executive Summary: A bug in Microsoft.AspNetCore.DataProtection 10.0.0-10.0.6 NuGet packages can give an attacker th...
github.com
Glasswing et al present a moral hazard to bug bounties. What I've seen recently is a significant increase in AI generated, or assisted vulnerability reports that are not vulnerabilities. (1/6)
I’m excited to let you know that the talks from [un]prompted—the AI Security Practitioner Conference—are now live on YouTube. No fluff, no hype—just real-world AI security from people actually doing the work. www.youtube.com/playlist?lis...
[un]prompted 2026 - YouTube
youtube.com
That is not what a 0-day is. It is a .NET CVE, it *does not* effect .NET Framework. 🙄
Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks
It's not that I mind AI written vulnerability reports for .NET, but there are a few problems we're seeing 1) Simply submitting the output from your favourite AI without testing the code it says demonstrates the vulnerability is bad. (1/4)
#BSidesLDN2025 videos are now live on our YouTube channel. Don’t forget to like and subscribe, we only publish once a year, your support makes a real difference! www.youtube.com/@Securitybsi... Huge thanks to @ministraitor.bsky.social & all our presenters for sharing their time and expertise!
𝐓𝐡𝐢𝐬 𝐭𝐢𝐦𝐞 𝐰𝐞’𝐫𝐞 𝐠𝐨𝐢𝐧𝐠 𝐞𝐯𝐞𝐧 𝐝𝐞𝐞𝐩𝐞𝐫! #UCK26 👉 krakow.updateconf.net #UpdateConference #Krakow @davidortinau.com & @konradkokosa.bsky.social & @codrina.bsky.social & @jfversluis.dev & @louella.dev & @niels.fennec.dev
Aspire beyond the basics. Aspire goes beyond its defaults once you understand the ideas underneath it. That foundation opens the door to extending Aspire in meaningful ways. Watch the full session from VSLive! Orlando youtu.be/rZQbhDfj7ek
The NDC Copenhagen Agenda is out 🇩🇰 See the full agenda and secure your Early Bird tickets before 27 Feb 👉 ndccopenhagen.com #ndccph
Like many services, as Signal grows, it becomes a more appealing place for scammers to try and cause harm. We've put together tips to help you protect yourself from phishing, scams, & impersonation attempts. Plus info about how Signal support communicates. support.signal.org/hc/en-us/art...
Staying Safe from Phishing, Scams, and Impersonation
We provide a privacy-first, end-to-end encrypted (E2EE) messaging and calling platform designed so only you and your intended recipients can communicate securely. Even with strong encryption, attac...
support.signal.org
📢 The NDC Copenhagen #CFP ends this Sunday, 1 February! We welcome all subjects relevant to software developers. If you have something to say, then speak up! 📅 Deadline: 1 February 👉 Submit: ndccopenhagen.com/call-for-pap... #ndccopenhagen
After a bit of trial and error, I finally made an agent that does exactly what I want. No hallucinations. Runs locally. And costs almost nothing. #! /bin/bash // Do exactly this one task and nothing else. // If it doesn't work, wait 30 seconds and try // again. If that fails, log a message. doTask
On 9 January 2026 mine and my family's lives changed forever. I tell the full story in this video: youtu.be/mNEPSWcOheY If you want to support my family as well as our local community, consider sharing this post, or donating here: www.gofundme.com/f/we-lost-al...
If 2025 was the year of vibe coding, 2026 will be the year of vibe maintenance and security.
It's that time of the season again, time for BsidesLondon! Let me know if you're around!
We’re headed to Toronto! 🇨🇦 We’re excited to partner up with @cppnorth.bsky.social for an incredible 4-day event you don’t want to miss. We’re currently booking speakers, and the CFP is open → ndctoronto.com
Generating SBOMs for .NET apps and NuGet packages with Microsoft.Sbom.Targets
Generating SBOMs for .NET apps and NuGet packages with Microsoft.Sbom.Targets
How to use the Microsoft.SBOM.Targets NuGet package to produce a Software Bill of Materials (SBOM) during your release builds.
idunno.org
I recently did a talk on internet safety for parents/guardians and it was well received by those in the room. Its honestly the toughest talk I have researched and given. It might help you if you have kids or you are the local tech support for people with small humans. www.youtube.com/watch?v=UgF5...
Won't somebody please think of the children!? – Niall Merrigan – HelloStavanger 2025
YouTube video by HelloStavanger
youtube.com