Sign in

badrap.io

@badrap.io
48 followers 71 following 25 posts

Cyber security made easy • badrap.io

PostsRepliesMedia
badrap.io @badrap.io · 29/09/2026
Our #atproto based changelog has news of its own 🦋 You can now browse it without logging in at badrap.io/changelog. For logged-in users, a snazzy #new "What's new" ticker appears when there are fresh entries.
191
badrap.io @badrap.io · 25/09/2026
Throwback to the Cybersicherheitsgipfel event in Hessen: excellent German and international perspectives on cyber resilience! Our DACH presence continues next week at the Zurich AI Festival and at the ECSO CISO Meetup in Berlin, followed by the German-Finnish Businessforum in Munich. See you there!
Overview of the Cybersicherheitsgipfel Hessen event main stage area, with audience and exhibitor stands.Wall with graffiti next to a display showing the Cybersicherheitsgipfel Hessen event information.Heikki from Badrap along with other international panelists on the stage at the Cybersicherheitsgipfel Hessen event, with audience in the background.
000
badrap.io @badrap.io · 22/09/2026
A changelog you can reply to! 🦋 We built our new changelog on #atproto. Our Bluesky posts tagged #new, #feature or #release also appear as changelog entries inside badrap.io. Each entry links back to the original post.
2426
Reposted by badrap.io
Matteo Gabriele @matteogabriele.npmx.social · 30/08/2026
Inspired by @jviide.iki.fi post about GitHub name typosquatting, I made a prototype of a possible action we could use in our workflows 👀
2296
badrap.io @badrap.io · 01/09/2026
Turn everyday security work into visible compliance progress. Our Security Playbooks now show which compliance requirements each playbook supports, starting with ISO/IEC 27002 and NIS2. From "what should we do?" to "what does this cover?" in one place!
030
Reposted by badrap.io
jviide.iki.fi @jviide.iki.fi · 21/05/2026
Whee! Published @badrap/valita v0.5.2 using both trusted & staged publishing just now insert party emoji here
npmjs.com's Staged Packages tab, listing @badrap/valita v0.5.2 waiting for approval. The mouse cursor is hovering over the Approve button.
0242
badrap.io @badrap.io · 12/05/2026
Teams, teams for everyone! 🫶 Whether you're securing a home network with your family or testing the waters for a small organization, we've got you covered. Create your free Team Workspace and start protecting your assets together at badrap.io. 🇪🇺 Co-funded by the European Union
A screenshot of the badrap.io user interface highlighting a new team creation feature. On the left sidebar's workspace dropdown menu, a large pink arrow with the text "NEW!" points directly to an option that reads "+ Create a new team". The menu also displays existing options for a personal workspace and a "Friends & Family" team workspace.
030
Reposted by badrap.io
jviide.iki.fi @jviide.iki.fi · 11/05/2026
More companies, governmental organizations and community projects should adopt the security.txt convention/proposal: securitytxt.org Making security contact discovery as easy as possible is good for everyone. Yes, even within the context of the recent AI vulnerability report slopocalypse.
Google's security.txt:

Contact: https://g.co/vulnz
Contact: mailto:security@google.com
Encryption: https://services.google.com/corporate/publickey.txt
Acknowledgments: https://bughunters.google.com/
Policy: https://g.co/vrp
Hiring: https://g.co/SecurityPrivacyEngJobs
Expires: 2030-04-01T00:00:00z
0225
badrap.io @badrap.io · 08/05/2026
Phishing, invoice scams, CEO scams and ransomware all target people. Our Employee Cyber Hygiene playbook helps you start a practical and engaging course for selected employees, giving your workforce the awareness to become your strongest security asset 💪👁️👄👁️💪
Screenshot of an Employee Cyber Hygiene app page showing search and filter controls, an "Invite selected users" button for initiating the course for the selected employee, a language selector set to English, and a user list with one employee selected and another shown as having already completed the course.
030
badrap.io @badrap.io · 07/05/2026
Announcing: CE3 - Common Excuse & Evasion Enumeration 😁 A taxonomy of vendor dismissal patterns for legitimate vulnerability reports: github.com/badrap/ce3
CE3-002 | Region-Blocked-So-Safe

Asserting that geo/IP blocking removes risk, ignoring VPNs, proxies, and compromised in-region devices.

Pattern indicator: "We geofence to allowed countries; this isn't exploitable for our users."

The Australian Cyber Security Centre's "Geo-blocking in Context" warns this is bypassed routinely; DigiCert/Vercara documentation notes geo-blocking is "losing its edge."

Related: CE3-004 (Behind-the-VPN)
0102
Reposted by badrap.io
jviide.iki.fi @jviide.iki.fi · 06/05/2026
Switched @badrap/valita to ESM-only, pretty cool how @npmx.dev celebrates the package size reduction 🎉 npmx.dev/package/@bad...
A notice on the @badrap/valita v0.5.0 page on npmx.dev:

"Package size decreased sinve v0.4.6! 🎉

Install size reduced by 72% (369.4 kB smaller)"
0557
badrap.io @badrap.io · 07/04/2026
New in the SensorFu Honeytoken app: automatic IP allowlisting for AWS, Google Cloud, Azure, and other Microsoft services. 🌐 Honeytokens are fake secrets meant to attract hackers like bees to honey – basically digital tripwires to catch someone snooping around. Set up your own at badrap.io.
A screenshot of the SensorFu Honeytoken app settings page showing toggles for cloud provider alerts. AWS and GCP are enabled, while Microsoft Azure and Microsoft Services are muted.
020
badrap.io @badrap.io · 02/04/2026
Badrap is happy to support @npmx.dev in an advisory role. A better developer experience can be a boon to security. Easier access to trust signals and tips for avoiding unnecessary dependencies, among other things, help make stronger supply chain choices. Read their intro: npmx.dev/blog/alpha-r...
npmx.dev
Announcing npmx: a fast, modern browser for the npm registry
Today we're releasing the alpha of npmx.dev – a fast, modern browser for the npm registry, built in the open by a growing community.
10172
badrap.io @badrap.io · 30/03/2026
Pricing by "Contact Sales" is out. Public and transparent pricing is in. We just shipped a way for anyone to plan a cybersecurity roadmap based on their actual needs and budget. No guessing, no forced sales calls. Use the Add to Cart button on our Playbooks page to get started: badrap.io/playbooks
130
badrap.io @badrap.io · 24/03/2026
Our Heikki is at the wonderful #kyberlahti today - come and say hi if you're around!
Kyberlahti 2026 event overview, exhibition areaKyberlahti 2026 event overview, main stage
000
badrap.io @badrap.io · 27/11/2025
We're again at the wonderful Baden-Württemberg #CyberSicherheitsForum today with friends from NCSC-FI (@traficomfinland.bsky.social), SensorFu, Arctic Security (@arcticsecurity.bsky.social), SensorFleet and Semantti (@semantti.bsky.social). Come and say hi!
Our Finnish delegation hanging around a table.A CyberSicherheitsForum Baden-Württenberg wall.A table reserved for our Finnish delegation.A crowd of participants.
030
badrap.io @badrap.io · 21/10/2025
If you're at the GovWare 2025 expo in Singapore this week, drop by and meet us at booth D10! Our Jani will also be speaking on Tuesday 16:00 (Level 6, Room GW6) about lessons learned from doing supply chain cybersecurity checks for over 3000 companies at scale. Come and chat with him afterwards!
Jani Kenttälä of badrap.io
010
badrap.io @badrap.io · 17/10/2025
Your mandatory cyber routines are becoming even easier to automate and execute! We're: 🤗 improving your user experience 🧑‍🔧 by developing new self-service features ⛳️ to the badrap.io platform and playbooks The effort is co-funded by the European Union: badrap.io/eakr2025 #CyberSecurity #EUfunded
badrap.io
Cyber Security Made Easy
Badrap playbooks help you automate cyber security tasks with ease. Step-by-step best practices boost your online security and privacy.
030
badrap.io @badrap.io · 14/02/2025
Great to meet 150 customers and partners at @scanabc.com's #prevent25 today - thanks to everyone for coming! Now off to Disobey (@disobeyfi.bsky.social), catch us there.
A crowd of Prevent'25 participants watching the show.A dapper fellow wearing an eye-catching vest gesturing towards the camera.badrap.io's Jani Kenttälä preparing the Prevent'25 presentation.
031
badrap.io @badrap.io · 11/02/2025
Remod wrote (in Finnish) some nice things about partnering with Badrap at remod.fi/asiakastarin... ❤️ Together, we’re tackling email security with the "Spoofproof Your Emails" playbook, helping organizations block fraud and keep communications trusted. Check it out at badrap.io/playbooks/sp...!
remod.fi
Badrap ja Remod - Tiukkaa tietoturva-asiantuntemusta jalat maassa
Badrapin ja Remodin yhteistyöllä on pitkä historia ja juuret syvällä kotimaisessa kyberturvallisuusyhteisössä.
042
Reposted by badrap.io
jviide.iki.fi @jviide.iki.fi · 20/01/2025
Quite mind-boggling to learn that jviide.iki.fi/http-redirects was referenced in a proposal to amend the OWASP Application Security Verification Standard: github.com/OWASP/ASVS/i... Huge thanks to everyone involved! Heartening to see the measured debate and the well-worded end result.
github.com
Don't redirect to HTTPS for API · Issue #2416 · OWASP/ASVS
Your API Shouldn't Redirect HTTP to HTTPS The argument is that when a client uses 'http://api.example.org', it should fail instead of silently be insecure. I propose to add a requirement that speci...
0143
Reposted by badrap.io
Jani Kenttälä @janikenttala.bsky.social · 27/12/2024
Here is a nice list of personal cyber hygiene tasks to complete. 👍
041
badrap.io @badrap.io · 09/12/2024
Glad to hear that our little library has been useful 🎉 io-ts is also a great option, and has definitely influenced valita and many others.
020
badrap.io @badrap.io · 28/11/2024
Oh no, badrap.io has been busted for speeding! What a great idea from @strek.in 😀 Get a ticket issued for your website from speeding-ticket.vercel.app
Website performance metrics for badrap.io.
030
badrap.io @badrap.io · 18/11/2024
A quick reminder for all our friends creating new Bluesky accounts: Recycling is usually a good thing, but not for passwords. Use a unique password for each online service.
A crossed-over recycling symbol, accompanied by the text: "Passwords are non-recyclable material."
082
badrap.io @badrap.io · 03/09/2024
Let's not forget our Brazilian friends! Huge thanks to Bruno for translating this evergreen post: medium.com/badrapio/sof... #cybersecurity #infosec
medium.com
Sofri um vazamento de dados. Como devo proceder?
Se você recebeu um alerta de vazamento de dados de um serviço de monitoramento como Have I Been Pwned ou Badrap.io e está se perguntando…
000
badrap.io @badrap.io · 03/09/2024
Let's get this ball rolling with an oldie but goodie: medium.com/badrapio/i-g... #cybersecurity #infosec
medium.com
I got a data breach alert. What next?
You received a data breach alert from a monitoring service and are wondering what to do next? Look no further, let’s sort it out together!
001