Niels Tanis

@niels.fennec.dev

Software Security Researcher & Engineer @ Tidalis Former @ Veracode Microsoft MVP Familyman & Renovator @ N28

It definitely was a year of change and that makes me really happy to see that I got renewed as MVP! Community and public speaking is the thing I still enjoy a lot and will continue on doing! Congratulations to all other MVP's that got renewed as well! #mvpbuzz

Bild

🚀 NuGet Pruning is cleaner restores and fewer false positives. Better security signals. In .NET 10, NuGet package pruning removes platform-provided dependencies from your graph, so you only see what actually matters: actionable alerts. Learn more: devblogs.microsoft.com/dotnet/nuget...

NuGet Package Pruning: Cleaner Dependencies and Actionable Vulnerability Reports - .NET Blog

Package pruning in .NET 10 removes platform-provided packages from your dependency graph. With transitive auditing enabled by default, projects with these defaults have 70% fewer transitive vulnerabil...

devblogs.microsoft.com

NDC Copenhagen is only 3 weeks away! 4 days, 55 speakers, 65 sessions, 7 workshops. All happening 1-4 June at Øksnehallen in Copenhagen. Whether you're into AI, .NET, architecture, security, or modern software practices, there's a track for you there! Tickets 👉 ndccopenhagen.com

NDC Copenhagen 2026 - ØksnehallenNDC Copenhagen 2026NDC Copenhagen 2026NDC Copenhagen 2026

Glasswing et al present a moral hazard to bug bounties. What I've seen recently is a significant increase in AI generated, or assisted vulnerability reports that are not vulnerabilities. (1/6)

It's not that I mind AI written vulnerability reports for .NET, but there are a few problems we're seeing 1) Simply submitting the output from your favourite AI without testing the code it says demonstrates the vulnerability is bad. (1/4)

Like many services, as Signal grows, it becomes a more appealing place for scammers to try and cause harm. We've put together tips to help you protect yourself from phishing, scams, & impersonation attempts. Plus info about how Signal support communicates. support.signal.org/hc/en-us/art...

Staying Safe from Phishing, Scams, and Impersonation

We provide a privacy-first, end-to-end encrypted (E2EE) messaging and calling platform designed so only you and your intended recipients can communicate securely. Even with strong encryption, attac...

support.signal.org

After a bit of trial and error, I finally made an agent that does exactly what I want. No hallucinations. Runs locally. And costs almost nothing. #! /bin/bash // Do exactly this one task and nothing else. // If it doesn't work, wait 30 seconds and try // again. If that fails, log a message. doTask