ActiveState @ActiveState
ActiveState enables DevOps, InfoSec, and Development teams to improve their security posture while simultaneously increasing productivity and innovation. activestate.com Vancouver, BC Joined November 2008-
Tweets15K
-
Followers4K
-
Following2K
-
Likes3K
Dependency cooldowns are table stakes now. Good. Adopt them. Also: patient attackers already know your window. And your AI coding agent's npm install mid-session bypasses your .npmrc config entirely. A time-based filter is not a software supply chain sourcing strategy. Provenance is. #SoftwareSupplyChain #OpenSourceSecurity #DevSecOps #SLSA Read more at buff.ly/kLYTGA0
Industry average MTTR for critical CVEs: above 50 days. ActiveState contractual SLA for critical CVEs: 5 business days. The 45 days in between are not a performance gap. For the security leader whose name is on the program, they are a documented liability window with a start date. Mitchell Hashimoto said it directly: someone has to charge for the relationship open source licenses won't provide. Read more at buff.ly/yKk2qmp #OpenSourceSecurity #CVE #SoftwareSupplyChain #CISO #AppSec
EU CRA Phase 1: September 2026. Mandatory 24-hour vulnerability reporting to ENISA. Applies to all products on market, including legacy. "We had a scanner" is not a sufficient legal defense. "Here is our provenance chain, our SBOM, and our contractual 5-day remediation SLA" is. The clock is running. Read more at buff.ly/yKk2qmp #EUCyberResilienceAct #OpenSourceSecurity #CISO #SoftwareSupplyChain #Compliance
Learn more and what this means for you in our article: buff.ly/fjJ6bGF
NIST can't enrich all CVEs anymore. Your scanner didn't tell you. It's still returning results as if nothing changed. The detection model that most open source software security programs are built around just became structurally incomplete, and the EU CRA enforcement date is September 11. The documentation regulators want cannot be assembled from scan exports. ActiveState joined the @linuxfoundation and @openssf this week because no single org secures the software supply chain alone. What 30 years of production-scale build infrastructure brings to that work is the point. Read more: buff.ly/whHtmla #SoftwareSupplyChain #OpenSourceSoftwareSecurity #OpenSSF #SLSA
Sonatype's 2025 Open Source Software Supply Chain Risk Report: 454,000+ new malicious open source packages in 2025. Cumulative total past 1.2 million. Your AI coding assistant is pulling from that ecosystem, one keystroke at a time, without checking maintainer status or vulnerability history. Scanning what entered your environment is a record of what you missed, not a prevention strategy. Read more at buff.ly/yKk2qmp #SoftwareSupplyChain #OpenSourceSecurity #AppSec #DevSecOps #AISecurity
The "as is" clause in open source licenses was never the problem. The problem was enterprise governance built on a warranty the license explicitly withheld. AI coding assistants just made that gap impossible to sustain. NIST says CVE submissions are up 263% and they can't keep up. Neither can your scanner. Read more at buff.ly/yKk2qmp #OpenSourceSecurity #SoftwareSupplyChain #CISO #AppSec #CyberResilience
Your AI coding tool will change. Your security layer shouldn't have to. The architecture argument nobody is making: govern the dependency, not the tool. Read More: buff.ly/jP77n9E #opensourcesecurity #softwaresupplychain #devsecops #CISO #AppSec
Malicious packages grew 156% YoY. Your AI coding assistant is pulling from those same registries right now. A plugin for your AI tool doesn't fix that. Governing what it resolves to does. Read more: buff.ly/jP77n9E #opensourcesecurity #softwaresupplychain #AIcode #CISO
AI-generated code doesn't just accelerate development. It accelerates the inherited trust problem. Every import statement an AI coding tool generates is a potential new open source dependency. At 500-1,000 developers, that intake rate isn't human-scale anymore. The governance model most teams are running was never built for this. The road ahead requires a different kind of decision. Read more at buff.ly/Cf6bswN #softwaresupplychain #opensourcesecurity #AppSec #AIcode #CISOnotes
'We were running a scanner' is not an audit trail for your OSS. SEC breach notification rules and the EU Cyber Resilience Act require documented, verifiable due diligence over your software supply chain. The question regulators will ask isn't whether you had tools. It's whether you made decisions. Most orgs cannot answer that question on demand today. Read more at buff.ly/Cf6bswN #CyberResilienceAct #softwaresupplychain #opensourcesoftwaresecurity #CISOnotes #compliance
The attack logic that TeamPCP used is still valid. Five package ecosystems. Transitive dependency layer. Inherited trust from upstream maintainers. No explicit governance decision about what open source software was safe to consume. That structure has not changed. The next attack will use the same entry points. Read more at buff.ly/Cf6bswN #opensourcesoftwaresecurity #softwaresupplychain #AppSec #CISOnotes #devsecops
TeamPCP was caught because a developer's laptop ran hot. The OSS governance gap it exposed is still open at most organizations. The scanner passed the binary through correctly. The failure was a decision about open source software provenance that was never made. Same structure. Same exposure. Still no decision. Read more at buff.ly/Cf6bswN #opensourcesecurity #softwaresupplychain #CISOnotes #AppSec #supplychainsecurity
Everyone is asking whether their AI agents will do the wrong thing. Nobody is asking what happens if they were built on the wrong thing. That's the conversation missing from every governance framework, every session agenda, every vendor pitch right now. Underneath every agent in your environment is a software stack. Inside that stack: open source dependencies pulled in by AI coding assistants, accepted in a single keystroke, with no provenance check, no manual review, no assigned owner. Behavioral trust is a real problem worth solving. Can the agent do what I asked? Yes. But that question rests on a foundation most organizations have never looked at. Security doesn't start with what your agent does. It starts with what it was built on. #CyberSecurity #AIAgents #SoftwareSupplyChain
CISOs: AI coding assistants don't just generate code. They generate open source risk. At machine speed. The fix can't be tethered to a single AI tool. It has to be at the dependency layer. That's exactly what the ActiveState Curated Catalog does. And today we expanded it to cover any AI coding environment. buff.ly/u1Sgjy0
ActiveState has sponsored the latest IDC Analyst Brief on open source software governance at scale. What the IDC Analyst Brief found: curated open source catalogs are the only governance model that intervenes at the point where the problem actually starts. Learn more here: buff.ly/MhIARTY
Outsourcing moves the work. It does not move the liability. When your open source dependencies ship through a vendor's pipeline, your compliance exposure travels with them, whether your security team can see it or not. The governance gap in IT outsourcing is a software supply chain problem. Read more at buff.ly/TIPio2j #OpenSourceSecurity #SoftwareSupplyChain #CISOInsights #ITOutsourcing
Two Apache ActiveMQ CVEs are now being chained for unauthenticated remote code execution. One is already in CISA KEV. ActiveState's Jonny Rivera on why this one stings: most organizations don't know they're running ActiveMQ at all. It's buried in transitive dependencies, untracked, and nowhere near the patch queue. You cannot patch what you cannot see. Patch target: 5.19.4 or 6.2.3. Read more at buff.ly/xEvq0hy #SoftwareSupplyChain #OpenSourceSecurity #CVE #DevSecOps
The most important number in your security program right now is not your CVE count. It is how long your remediation sequence takes from "critical CVE identified" to "clean deployment in production." Most teams do not know that number. Project Glasswing is going to surface it for them. Full read: buff.ly/EjYfOTB #OpenSourceSecurity #CyberSecurity #AppSec
The Perl Shop @ThePerlShop
940 Followers 1K Following Predictable On-demand Perl Consulting from an experienced team of 🐪 #Perl devs #Agile (We publish Perl community news, and occasionally tweet about us.)
Linux Magazine @linux_pro
80K Followers 2K Following Linux Magazine is your guide to the world of Linux and open source. @[email protected] Bluesky: https://t.co/pWCi1akeDK
socallinuxexpo @socallinuxexpo
4K Followers 2K Following A community run open source and free software event held annually in Southern California
Josh Long @starbuxman
85K Followers 4K Following Spring Developer Advocate (@Java_Champions & @Kotlin @GoogleDevExpert) @VMwareTanzu 🍃🐲 📽️ https://t.co/A2wBUe0b0A
Mark Gardner @markjgardner
886 Followers 3K Following I help #Perl #developers build modern, disciplined applications by writing easy-to-maintain code with confidence. https://t.co/dyeoDI21EP
Abukar Sh Ahmed Mursa... @mursal_abukar
348 Followers 3K Following Ph.D. In Eco. Candidate , Anti-Corruption Diploma, Expert Regional Integration (Customs&Trade) Former Somali Customs Dir, Director NAD & Manager Customs AAIA
PARDHIV REDDY @pardhivreddy
30 Followers 235 Following
Tracebit @tracebit_com
306 Followers 3K Following The Assume Breach platform that detects intrusions in seconds. Also on https://t.co/T4VNPGjS2O
IT GRC Forum @ITGRC
24K Followers 22K Following Educational Programs on IT, Governance, Risk Management, & Compliance (GRC)
Youcef Lakehal @Lamboo3131
20 Followers 226 Following
Oscar Henry Collins @oscarhenryclns
2 Followers 10 Following
Woody @renosharky
20 Followers 78 Following
يزن @yzn89994884
3 Followers 265 Following
Pepe Lopez @PepeZye
11 Followers 967 Following
CD @dhivus
134 Followers 281 Following She/her, Application Security enthusiast #aws #security Tweets/views are my own.
Ultraman Sam @SamUltraman0617
1 Followers 29 Following
pkt @piyushjnv
232 Followers 6K Following @IIT Delhi | @IIEST Shibpur | @JNV Muzaffarpur | @L&T Defence and Smart Technologies | Nature explorer | Passionate Cook.
Sunnysaxon @johnsunday7001
905 Followers 2K Following GOD DID🙏🙏 THE HAND OF GOD ❤❤ SELF CONFIDENT, SELF RELIANT. 100💯GOD
Sue Leclaire @LeclaireSu49112
0 Followers 2 Following
Apollo @Apollo87z
78 Followers 285 Following Backend security engineer 💻 | ML × Pentesting × Cloud automation 🤖⚡ | Python • Node • Docker • APIs | Breaking systems, building tools, sharing chaos 🔥
Ryan Nolte @rtnolte
1 Followers 85 Following
Mohamed Ehab @mohamedehab4020
1 Followers 123 Following
Kale Bauch @BauchKale16909
144 Followers 5K Following
Lucas von Hartmann @ichbinlucasv
793 Followers 5K Following •Cyber Security Specialist / Ethical Hacker •Science •Tech •✝️ •Libertarian 🟡⚫️
Brandon Henley @hackawaybh
131 Followers 2K Following Working on a novel, hoping it's very funny. 🎸🎸🎸🎸💀🎾🎾🎾💻🖱🎃🏀🏐🎁👄👄👄🫦🫦😍😍🍻🏆🍷🍷🍺🍺🥁💾😄😄😬😁🎸🎁🎁🏉😀🚰🚰🍷🍺🥗
Cyber Eagle @cyb3rw01f_
11 Followers 687 Following
Xevo @xev
18 Followers 116 Following
ลําใย พ�... @PhrmYi
50 Followers 336 Following
BluSapphire - NextGen... @BluSapphire_AI
135 Followers 252 Following The vendor-neutral AI-SOC for enterprises. Autonomous detection, investigation & response. Trusted by BSE. Built for scale. #CyberSecurity #SIEMlessSIEM #AISOC
Sarah Montoya @MontoyaOnAir
572 Followers 7K Following Aerial photographer full time. Part 107 Drone Pilot part time. Stand up Comedian just for fun. Almost out of 40,000 of debt. 2019-2023: ask me about it.
Hafssa SALAHI @Salahihafssa
1 Followers 47 Following
The Filipino Operator @amplitrace
1K Followers 5K Following building @gib_work | https://t.co/h2fml5po4U
Militaryfans @Military8929
0 Followers 18 Following
hahowe @hahowe_0
14 Followers 375 Following
ReversingLabs @ReversingLabs
7K Followers 864 Following ReversingLabs is the trusted name in file and software security. RL — Trust Delivered.
lord20 @lord00_00
1 Followers 178 Following
Adweoqa @adweoqa49123
10 Followers 148 Following
MyraLawson @2wc72B0J1bIS0
48 Followers 2K Following
_Rebel_boy_Adi @AsAditya17
74 Followers 315 Following I am die hard 💔 fan Rebel star ♥️ prabhas...Stars Stars Stars I Don't like star But Stars Like darling Prabahs I am Not aboved it So I like it & #Prabhas🤴
Stephanie Roberts @StephanieRVOhms
1 Followers 124 Following
Najup Imger @ImgerNajup
1 Followers 12 Following
Bilgin Ibryam @bibryam
83K Followers 876 Following PM at Diagrid | Ex-Red Hat Architect | Author Kubernetes Patterns → All in distributed systems; agentic apps; AI-assisted coding;
Mitchell Hashimoto @mitchellh
202K Followers 146 Following Creator of Ghostty. 👻 Prev founded @HashiCorp, created Vagrant, Terraform, Vault, and others.
The Linux Foundation @linuxfoundation
587K Followers 9K Following A nonprofit organization enabling mass innovation through open source. #linux #kubernetes #riscv #hyperledger #anuket #openssf #openjs #o3de and more!
Command Line Magic @climagic
187K Followers 10K Following Cool Unix/Linux Command Line tricks you can use in $TWITTER_CHAR_LIMIT characters or less. Here mostly to inspire. Also on https://t.co/YYJE9JpVnF
Linux Magazine @linux_pro
80K Followers 2K Following Linux Magazine is your guide to the world of Linux and open source. @[email protected] Bluesky: https://t.co/pWCi1akeDK
socallinuxexpo @socallinuxexpo
4K Followers 2K Following A community run open source and free software event held annually in Southern California
Mohammad Sajid Anwar @cpan_author
642 Followers 115 Following Author. Editor. Founder. Speaker. White Camel Awardee. Indian by birth, British by choice.
Rick Turoczy @turoczy
18K Followers 9K Following
John Lindquist @johnlindquist
29K Followers 2K Following Codex Power User Workshops - https://t.co/xPtDG0Inyh Previously @vercel AI DX The OG egghead - https://t.co/rxAeU2DHfm
Python Software Found... @ThePSF
692K Followers 126 Following The nonprofit organization behind the Python programming language. For help with Python code: https://t.co/XDHPttz2Xv On Mastodon: @[email protected]
Mark Gardner @markjgardner
886 Followers 3K Following I help #Perl #developers build modern, disciplined applications by writing easy-to-maintain code with confidence. https://t.co/dyeoDI21EP
ReversingLabs @ReversingLabs
7K Followers 864 Following ReversingLabs is the trusted name in file and software security. RL — Trust Delivered.
Techstrong.ai @Techstrongai
360 Followers 186 Following The future of artificial intelligence powered by @TechstrongGroup
Frederic Lardinois @fredericl
25K Followers 4K Following I write about tech. Sr. Editor, AI at The New Stack. Signal 860-208-3416 [email protected]
Loreli Cadapan @LoreliCadapan
136 Followers 237 Following
Python Package Index @pypi
23K Followers 11 Following The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced 🥧 🫛 👁️
Kayla Cinnamon ☕ @ ... @cinnamon_msft
22K Followers 310 Following Senior Developer Advocate at @Microsoft & @GitHub, former PM for Windows Terminal, Microsoft PowerToys, Cascadia Code, and @Windows developer experiences 👩💻✨
Techstrong Group @TechstrongGroup
876 Followers 128 Following The power source for people & tech @DevOpsdotcom @securityblvd @ContainerJrnl @DigCxO @Techstrongai @TechstrongTV @PlatformEng_ @TechstrongIT
CircuitSwan @CircuitSwan
6K Followers 1K Following Brains are inversely proportionate to common sense - me, Nicole Schwartz. My tweets are my own. Formerly known as AmazonV. she/her @DianaInitiative @dcskytalks
Dana Crane @GPT3me
12 Followers 11 Following GPT3 uses an ML/AI service to generate text & pics based on hashtag keywords. Warning: signal to noise ratio may be better than the rest of the twittersphere.
Abhishek Arya @infernosec
5K Followers 185 Following Principal Engineer, AI Security at Google. Opinions are my own.
JBaruch 🎩 @jbaruch
14K Followers 1K Following DevRel Team and context engineering management at @tessl_io Co-author of #LiquidSoftware and #DevOps Tools for #Java Developers. Java Champion. Legacy verified.
Google Cloud @googlecloud
566K Followers 746 Following Welcome to the new way to cloud. Questions? ➡️ https://t.co/BFKBu3tEmS For do-ers & makers ➡️ @GoogleCloudTech Watch #GoogleCloudNext on demand ⬇️
Amazon Web Services @AWS
19K Followers 1 Following For all the latest news and information about AWS head to @AWSCloud. For support, go to @AWSSupport
JFrog @jfrog
23K Followers 2K Following Driven by a “Liquid Software” vision, the JFrog Software Supply Chain Platform powers organizations to build, manage, and distribute software quickly & securely
Blue Team Con @BlueTeamCon
11K Followers 6 Following Blue Team Con is an annual cybersecurity conference built for defenders, inclusive of anyone interested in safeguarding organizations. | 10-13 September 2026
Shopify Engineering @ShopifyEng
58K Followers 709 Following Making commerce better for everyone. Follow us for technical discussions and updates on how engineers build @Shopify. Explore open roles: https://t.co/NFSvvCJBXt
EveryoneSocial @EveryoneSocial
3K Followers 2K Following Accelerate growth across your entire company by enabling employees to share and create content on social media.
Janna Bastow simplyba... @simplybastow
30K Followers 1K Following Product 🤓 Invented Now-Next-Later roadmap Founder @ProdPad & @MindTheProduct writer speaker artist ADHD 🇨🇦/🇬🇧/🏳️🌈/she/they
BluSapphire - NextGen... @BluSapphire_AI
135 Followers 252 Following The vendor-neutral AI-SOC for enterprises. Autonomous detection, investigation & response. Trusted by BSE. Built for scale. #CyberSecurity #SIEMlessSIEM #AISOC
Andrew Ng @AndrewYNg
1.6M Followers 1K Following Co-Founder of Coursera; Stanford CS adjunct faculty. Former head of Baidu AI Group/Google Brain. #ai #machinelearning, #deeplearning #MOOCs
Christina Warren @film_girl
98K Followers 14K Following DevRel @GitHub Past: @GoogleDeepMind, hosts: @ovrtrd Journalist turned developer. @[email protected]. Loves media, tech and OSS. opinions = own
Security Compass @securitycompass
1K Followers 815 Following Security Compass, the Security by Design Company, is a leading provider of cybersecurity solutions.
Jacob Schreiber @jmschreiber91
5K Followers 1K Following Programmable Genomics Lab @UMassGCB, Technical Steering Committee @NumFOCUS. Prev @impvienna @StanfordMed. Studying genomics, ML, and fruit. Opinions my own.
Christopher Hart @_ChrisJHart
3K Followers 371 Following Software Consulting Engineering Technical Leader at Cisco. Systems & network administration, Python, Ansible, DevOps, CI/CD, and much more! Tweets are my own
Jesse Warden @jesterxl
4K Followers 530 Following Software, Powerlifter, Parkourist, Body Builder, Backpacker, married to @UXBrandy YouTube Channel https://t.co/xR82wzb6Ts
Jake Miller @theBumbleSec
2K Followers 382 Following Web Security Researcher | h2c smuggling, JSON Interop vulns, RMIScout, GadgetProbe, Server-side Spreadsheet Injection | AppSec @BrexHQ; formerly @BishopFox
Cole Kennedy @colek42c
546 Followers 459 Following Founder - TestifySec - Secure Systems from Source to Production
Luke Hinds @decodebytes
3K Followers 750 Following Creator of https://t.co/T8htHI7vHB , now building https://t.co/OBABqFvHE2 - the agent security platform.
Oliver Chang @halbecaf
2K Followers 147 Following https://t.co/bmyDmTlFKv Senior Staff Eng @ Google DeepMind. Former: founder of https://t.co/K575lba4tt, lead/co-founder for OSS-Fuzz.
Bob Callaway @rdcallaw
691 Followers 135 Following OSS Supply Chain Security @google. @projectsigstore @theopenssf Technical Advisory Council - Ex-Red Hat, NetApp, IBM. PhD ECE NCSU.
Christian Heimes @ChristianHeimes
4K Followers 649 Following (he/him) Python core developer, Python security team, @ThePSF fellow, speaker. Views are my own. @[email protected]
Emily Morehouse-Valca... @emilyemorehouse
4K Followers 466 Following 🦑 Co-founder, Dir of Engineering @Cuttlesoft 👩🏻💻 Python Core Dev, @ThePSF Fellow 🐍 @PyCon 202{0,1,2} chair 🖤 Lover of programming languages. (she/her)
Pablo Galindo Salgado @pyblogsal
13K Followers 344 Following Python Steering Council and core developer. Python 3.10/3.11 release manager. @ThePSF Fellow. Deals with black holes and parsers. Attracts linker problems.
freakyclown @_Freakyclown_
17K Followers 3K Following Co-Founder of @CygentaHQ former head of cyber research @Raytheon - Keynote Speaker, ethical hacker and physical security specialist. Author of How I Rob Banks.
O-Line Security @Olinesec
325 Followers 17 Following We create Security Professionals who apply best security practices that are tailored to organizational needs and demands.
T.O @cybershinobii
420 Followers 114 Following
AWS Architecture @AWSArchitecture
53K Followers 10 Following Cloud architecture guidance to build your best with #AWS
Daniel Micay @DanielMicay
12K Followers 349 Following Security researcher/engineer working on mobile privacy/security. Founder of @GrapheneOS.
Chris Wysopal @WeldPond
55K Followers 1K Following Hacker. Co-founder/CTO Veracode. Former L0pht security researcher. GenAI Auto-repair of vulns is the future @weld.bsky.social @[email protected]
TrendAI Zero Day Init... @thezdi
89K Followers 16 Following TrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
Chris Evans @scarybeasts
25K Followers 201 Following CISO and Chief Hacking Officer at HackerOne. Past: Founded {vsftpd, Chrome security, Google Project Zero}; Tesla; Dropbox. Hacker / Researcher. beebjit.
Trail of Bits @trailofbits
38K Followers 260 Following We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
Asra Ali @AsraEntr0py
508 Followers 254 Following math @mit | FHE compilers @google | pullup princess, sometimes i fight
















