Andrea Jemmett

Platform Security Engineer at kaiko.ai

#PhD candidate in #computersecurity at @vusec
#fuzzing #AI #ML #privacy #programminglanguages

Otherwise: inking in #splatoon, hoarding #virtualpets, training #pokemon, digievolving #digimon

Addicted to Whiskey: I serve a cat we call Whiskers. Heโ€™s not drinkable

Immigrant ๐Ÿ‡ฎ๐Ÿ‡น โ†’ ๐Ÿ‡ณ๐Ÿ‡ฑ - he/him

Andrea Jemmett boosted:
2025-01-15

I wonder if #fuzzing nowadays is used more for #pentesting (mostly black box) or defensive #testing (mostly gray or white box) ๐Ÿค”

Share for reach ๐Ÿ™
#cybersecurity #infosec

2025-01-12

These are really old features, which says a lot about how long Iโ€™ve been away from the web frontend ๐Ÿ˜…

2025-01-12

Moreover if you add a name attribute on the details elements with the same value, it behaves as an exclusive accordion

2025-01-12

#TIL about details / summary #html elements which allow to hide/show some content by clicking on the summary

Andrea Jemmett boosted:

This is how fuzzers work.

From Reddit.

#fuzzing #pentesting

Andrea Jemmett boosted:
Astra Kernel :verified:AstraKernel@infosec.exchange
2025-01-10

๐Ÿฆ€ One of the famous vulnerability scanner getting Rust rewrite

"The goal is to replace the current scanner stack (openvas-scanner, ospd-openvas, notus-scanner), including the Open Scanner Protocol (OSP)"

"It provides an interface to manage scans for vulnerability testing"

github.com/greenbone/openvas-s

#infosec

2025-01-10

The latest #HelixEditor release is packed with exciting new features! ๐Ÿš€ Quite eager to try the new pickers and inline diagnostics; files completion is a must. I haven't tried it in over a yearโ€”maybe it's time for a second round? ๐Ÿค”

๐Ÿ‘‰ helix-editor.com/news/release-

2025-01-10

@tuckerjj @caseyliss a couple of weeks ago I thought I was going crazy and that the chime was coming from some of the 10s of virtual pets I have laying around ๐Ÿ˜…

After realizing that the chime was coming from the AirPods, I couldnโ€™t find anything online. Thanks for solving the mystery!

Andrea Jemmett boosted:
lcamtuf :verified: :verified: :verified:lcamtuf@infosec.exchange
2025-01-10

- You have to understand that back in my day, it was possible to make a career out of sending a lot of AAAAAAs to computer programs

- Sure grandpa, let's get you to bed

Andrea Jemmett boosted:
2025-01-10

I am finally ready to release a decent version of Plainews - a distraction-free news readers for the terminal. It allows you to follow RSS feeds, read them without ads, summarise and translate articles.
nsobadzhiev.github.io/plainews

2025-01-09

I wonder if #fuzzing nowadays is used more for #pentesting (mostly black box) or defensive #testing (mostly gray or white box) ๐Ÿค”

Share for reach ๐Ÿ™
#cybersecurity #infosec

2025-01-09

It would also be nice to compare the runtime, since LLMs can be quite slow on commodity hardware

2025-01-09

Interesting use of #llm to enhance #fuzzing. I donโ€™t have much experience with web fuzzing, but I wonder how this compares with state of the art gray box techniques

invicti.com/blog/security-labs

#cybersecurity #pentesting

2025-01-05

@mboelen Thatโ€™s quite useful! I used some of your articles recently to optimize auditd rules, the Internet really seems bigger than it is ๐Ÿ˜

2025-01-05

๐Ÿค“ #TIL: You can use the lslogins command on #Linux to get info about user accounts. ๐Ÿ‘€ It's pretty useful if you need to manage accounts, monitoring, or doing access reviews

Andrea Jemmett boosted:
bert hubert ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆbert_hubert@fosstodon.org
2025-01-04

"If you're thinking without writing, you only think you're thinking" - Leslie Lamport. As a programmer, he'd know this personally, as many programming ideas work fine in your head. Until you try to type it in. en.wikipedia.org/wiki/Leslie_L

2025-01-04

Count Orlok in the new #Nosferatu movie looks like Jim Carreyโ€™s Dr. Robotnik.

Andrea Jemmett boosted:
2025-01-01

Now that 2025 is here, it's time to wind down the #osspodcast

It was a fun run, but it was time to be done.

I have a new project I'm calling "Open Source Security" (the domain is too good to not do something with it)

I want to chat with people securing the use and creating of open source. I explain a lot more in the blog post (which also has audio)

If you're one of these people, let me know! There are a lot of lessons for us all, and the people doing the best work aren't being listened to

opensourcesecurity.io/posts/20

Andrea Jemmett boosted:
2025-01-01

โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘ 0%

2024-12-31

Prediction for 2025: Zig language gets into mainstream, kickstarted by Ghostty exposure #PredictionFor2025 #ziglang #zig #ghostty

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst