Sign in

Christian Folini

@christian-folini.ch
3.4K followers 308 following 291 posts

Web application security guy with a passion for OWASP's open source WAF projects and National Cyber Strategy. Maintains "Swiss Cyber Security" starter pack and cherishes his small collection of medieval helmets.

PostsRepliesMedia
Christian Folini @christian-folini.ch · 23/03/2026
Hey @leak.bsky.social, I've tried to reach you via mail, lately also connecting to your LinkedIn profile. Could you get back to me?
001
Christian Folini @christian-folini.ch · 19/03/2026
Florian Schuetz from Swiss NCSC opening the @1ns0mn1h4ck.bsky.social conference: "Sovereignty is not autarky, sovereignty is freedom to choose." If you're around at the conference, come and say hello. Happy to talk.
031
Reposted by Christian Folini
kat cosgrove @kat.lol · 19/03/2026
I'm very lucky that @minimus.io considers the work I do for Kubernetes to be part of my job. That isn't true for most maintainers. Projects are failing or suffering attacks because of a lack of contributors from companies built on top of them, and that's *everyone's* problem. dev.to/katcosgrove/...
dev.to
When Projects Fail: Why Companies Should Treat Open Source as Infrastructure
Maintaining an open source project is hard. It requires managing a group of people who are largely...
610820
Reposted by Christian Folini
Patrick C Miller @patrickcmiller.bsky.social · 17/03/2026
Switzerland built a secure alternative to BGP. The rest of the world hasn't noticed yet www.theregister.com/2026/03/17/s...
theregister.com
Switzerland built an alternative to BGP. Nobody noticed
Feature: SCION: Proven in banking and healthcare, slow to spread everywhere else
133
Reposted by Christian Folini
Reto Vogt @rvgt.ch · 15/03/2026
Ein halbes Jahr ist seit dem Launch von #Apertus verstrichen. Für die @nzz.ch am Sonntag habe ich untersucht, was daraus geworden ist. Das Fazit ist ernüchternd: Kaum jemand nutzt es. Und ausgerechnet der wichtigste Partner setzt auf Anthropic und OpenAI. www.nzz.ch/wirtschaft/n... (Geschenk-Link)
nzz.ch
Schweizer KI Apertus: ETH-Projekt wird kaum produktiv genutzt
Ein halbes Jahr nach dem Launch nutzt noch kaum jemand das Schweizer KI-Modell Apertus. Es liegt nicht nur am fehlenden Geld.
0112
Reposted by Christian Folini
Insomni'hack @1ns0mn1h4ck.bsky.social · 13/03/2026
Welcome Anastasija Collen as our keynote speaker at #INSO26! She reveals how security debt is driven more by environment and behavior than by tools. Last tickets available: ow.ly/Y94V50YsPlu #Infosec #CyberConference
033
Reposted by Christian Folini
Lukasz Olejnik @lukaszolejnik.bsky.social · 12/03/2026
Is the bombing of the elementary school in Iran a case study in how AI-assisted warfare outpaces the safeguards international humanitarian law (IHL) demands during armed conflict?
183
Christian Folini @christian-folini.ch · 06/03/2026
Thought I'd sahre the Swiss Cyber Security starter pack again. Am I missing somebody? go.bsky.app/4xD359p
061
Reposted by Christian Folini
Patrick C Miller @patrickcmiller.bsky.social · 01/03/2026
A VC and some big-name programmers are trying to solve open source's funding problem, permanently | TechCrunch techcrunch.com/2026/02/26/a...
techcrunch.com
A VC and some big-name programmers are trying to solve open source's funding problem, permanently | TechCrunch
A group of well-known open source programmers and a VC have launched the Open Source Endowment. They hope this new method will provide funding for good.
022
Reposted by Christian Folini
Lukasz Olejnik @lukaszolejnik.bsky.social · 01/03/2026
PSYOP 2026: no need to drop leaflets when you can hijack push notifications. Israel hacked BadeSaba, one of Iran's most popular apps, with 37 million installs, used to track daily prayer times.
22718
Reposted by Christian Folini
Patrick Seemann @nohillside.ch · 27/02/2026
„Palantir has already lost the only contest that matters: the one for public perception. […] they apparently never thought to search “The Streisand Effect.”“ Palantir Sues Swiss Magazine For Accurately Reporting That The Swiss Government Didn’t Want Palantir www.techdirt.com/2026/02/27/pal…
0103
Reposted by Christian Folini
The Register @theregister.com · 23/02/2026
Feeling the burn: When open source developers decide to take a break
dlvr.it
Feeling the burn: When open source developers decide to take a break
A week off for vacation? The nerve of some people Opinion  If you want to see the definition of "workaholic," you can't do better than to look at your typical senior open source developer or maintainer. I should know, I'm a workaholic too. I know my kind.…
1232
Reposted by Christian Folini
Patrick C Miller @patrickcmiller.bsky.social · 23/02/2026
Switzerland’s NCSC boosts operational capabilities, mandates cyberattack reporting on critical infrastructure industrialcyber.co/reports/swit...
industrialcyber.co
Switzerland’s NCSC boosts operational capabilities, mandates cyberattack reporting on critical infrastructure - Industrial Cyber
Switzerland’s NCSC boosts operational capabilities, implements mandatory reporting of cyberattacks on critical infrastructure in 2025.
022
Reposted by Christian Folini
coreruleset.bsky.social @coreruleset.bsky.social · 18/02/2026
🔥 OWASP CRS is evolving! Introducing #CRSLang — a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors. Check it out 👉 coreruleset.org/2026... #WAF #AppSec #OWASP #ModSecurity
042
Reposted by Christian Folini
kingthorin_rm @kingthorin.bsky.social · 18/02/2026
This is huge!! #WAF #DevSecOps
022
Reposted by Christian Folini
The Maybe @themaybe.org · 18/02/2026
“We should be questioning how power formed in a way that enabled a handful of people—in service of their quarterly returns—to make socially significant decisions on behalf of everyone else, without scrutability, without clarity, and without democratic oversight.” - @meredithmeredith.bsky.social
415439
Christian Folini @christian-folini.ch · 09/02/2026
I dreaded this moment a lot: Moving to a new phone. But as much as I loved my DOOGEE phone, the security update policy is not sustainable / not existing so I moved to a Fairphone yesterday. Long 🧵
120
Reposted by Christian Folini
Lukasz Olejnik @lukaszolejnik.bsky.social · 22/01/2026
I show how malicious Claude Code skills can spread across infrastructure. Approve one skill → it gets shell access → copies itself to every host in your SSH config. Skills are code. Treat them that way. blog.lukaszolejnik.com techletters.substack.com/p/techletter...
blog.lukaszolejnik.com
Security, Privacy & Tech Inquiries
Lukasz Olejnik on security, privacy, Web, technology and technology policy matters.
14117
Reposted by Christian Folini
Lukasz Olejnik @lukaszolejnik.bsky.social · 22/01/2026
My comments in @WIRED about AI-powered information operation systems. The threat aren't bots posting fakes but coordinated, persistent, human-like agent networks that manufacture the appearance of debate, consensus, disagreement. Eloquent, adaptable, detail-heavy, threads.
22923
Reposted by Christian Folini
OWASP® Foundation @owasp.org · 29/12/2025
Dream of speaking at OWASP? Join our FREE session, “So You Want to Be an OWASP Speaker!” Learn to nail your CfPs, deliver epic talks, and own the stage. Curiosity required, lifelines optional! owasp.glueup.com/eve... #OWASP #AppSec #upskill #publicspeaking #cybersecurity
021
Christian Folini @christian-folini.ch · 12/12/2025
The recording of the 2nd online event on #ECollecting has been published. We've also launched a dialogue platform and initiated two discussions. github.com/swiss/e-coll... Discussion 1: Political Balance (of E-Collecting) Discussion 2: Can an opt-out for the paper process really be avoided?
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
010
Reposted by Christian Folini
ZAP by Checkmarx @zaproxy.org · 05/12/2025
New blog post: #React2Shell Detection with ZAP www.zaproxy.org/blog/2025-12... #zaproxy #appsec
zaproxy.org
React2Shell Detection with ZAP
React2Shell is the latest big “named” vulnerability - heres how you can detect it with ZAP.
084
Christian Folini @christian-folini.ch · 05/12/2025
With the rate @cloudflare.social goes down these days, they should totally invest in revamping their error page.
140
Christian Folini @christian-folini.ch · 05/12/2025
#react2shell (CVE-2025-55182) is detected by default by OWASP CRS 3 and CRS 4 alike. Rules in question are * 934100 #CRS3 and #CRS4 * 934130 CRS4 * 942550 CRS4 Test payload in graphic below. Other payloads can be tested via the public CRS sandbox. Kudos to Vincent-TW for the groundwork.
032
Christian Folini @christian-folini.ch · 25/11/2025
#ModSecurity / @owasp.org CRS engine puzzle! A solution has the potential to improve the performance across millions of servers.
010
Christian Folini @christian-folini.ch · 21/11/2025
Performing a major upgrade of your OWASP CRS #WAF rules usually means you need to lower your defenses. The new "netnea-crs-upgrading-plugin" that allows you to perform this transition in a smooth and calculated way without the need to raise your anomaly threshold. www.netnea.com/cms/2025/11/...
netnea.com
The new netnea-CRS-Upgrading-Plugin: Simplifying the Migration from CRS v3 to v4 – Welcome to netnea
053
Christian Folini @christian-folini.ch · 18/11/2025
Whenever a big cloud service goes down I think of the Swiss gov exec who ridiculed me on a panel when I claimed it's a little known secret, but it's actually possible to run your own servers without any dependency to somebody else's computer.
052
Christian Folini @christian-folini.ch · 10/11/2025
For a couple of days I see a new wave of attacks hitting our WP installation. Hundreds of IPs hitting /wp-login.php. Like 10 times the normal amount of requests despite fail2ban blocking them really fast. The best defense (and there are many layers of defense) has been installing WP in a subfolder.
110
Reposted by Christian Folini
Gabriel Geiger @gabrielgeiger.bsky.social · 14/10/2025
On a Saturday night I stumbled across something on the internet that made me feel like ****** my pants. A giant dataset of real surveillance operations targeting 1000s of people across nearly every country. Unraveling it and the mysterious company behind it has consumed 1.5 years of my life
726996
Christian Folini @christian-folini.ch · 22/09/2025
Later today, I'll be hosting a ModSecurity / CRS community call luma.com/8yc1p543 We'll be talking about success metrics, WAF testing and other integration questions.
luma.com
CRS Community Call · Luma
A video call where the CRS dev team gets to meet their community face-to-face. A place for information exchange and questions for both newbies and experienced…
074
Reposted by Christian Folini
Patrick Seemann @nohillside.ch · 27/08/2025
“E-ID explained, Teil 1: Wieso und wie? - #dnip” dnip.ch/2025/08/27/e-id-explained-t…
0116
Reposted by Christian Folini
Reto Vogt @rvgt.ch · 15/08/2025
In der heutigen Freitagskolumne für #dnip habe ich mich der #eID gewidmet. Dabei untersuchte ich die Argumente der Gegner:innen und unterzog sie einem Faktencheck. Die meisten davon ziehen nicht, weil sie die Vorlage gar nicht betreffen. Von mir gibt's ein "Ja" am 28.9. dnip.ch/2025/08/15/v...
dnip.ch
Vogt am Freitag: Gespenster - Das Netz ist politisch
Kommerzielle Auswertung, massenhafte Datenspeicherung, Überwachung durch Tech-Konzerne: Die Gegner der neuen E-ID malen ein düsteres Bild. Aber die meisten
82611
Reposted by Christian Folini
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 14/08/2025
An Open Source sustainability story in two slides. (for a coming talk of mine) Slide 1: car brands using #curl Slide 2: car brands sponsoring or paying for #curl support
38 known car brandsa blank slide
15223372
Christian Folini @christian-folini.ch · 03/08/2025
Guess who's going to the circus tonight.
030
Reposted by Christian Folini
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 31/07/2025
Do I know anyone near Bern Switzerland that I can meet up with in Vegas next week, to take a book to my friend? I mailed him one months ago and it never arrived. I don't want him to wait 3 more months. Let me know!
013
Reposted by Christian Folini
Adrienne Fichter @adfichter.eurosky.social · 27/07/2025
Die NZZ ist einer der grössten Datenhändlerinnen der Schweiz. Dark Patterns at its worst. Stell Regler auf off bei Standort-Weitergabe und IMMER NOCH sind gewisse Advertising Tech-Firmen auf ON eingestellt. Das sind alles übelste Datenschutzverstösse. Der EDÖB hat leider aufgegeben bei dem Thema.
76620
Christian Folini @christian-folini.ch · 26/07/2025
Switzerland is starting a project test #ECollecting / the electronic collection of signatures for referendums. The Federal Chancellery launched a public participation process and they recruited me to moderate this dialogue. www.news.admin.ch/de/newnsb/vy...
news.admin.ch
Die Webseite veröffentlicht alle Mitteilungen der Departemente und Ämter, sowie Daten der Medienkonferenzen des Bundesrates, der Bundesverwaltung, der Parteien usw.
051
Reposted by Christian Folini
Josh Grossman (tghosth 👻) @joshcgrossman.com · 17/07/2025
The final two parts of my blog series about delivering training at conferences have now been released! You can check them out on the @BounceSecurity website now!
121
Christian Folini @christian-folini.ch · 04/07/2025
#pastpuzzle 345 🟩🟩🟩🟩 (0) ▪️▪️▪️▪️ ▪️▪️▪️▪️ ▪️▪️▪️▪️ 1/4 🥇 www.pastpuzzle.de The question is always whether historians have advantages in trivia quizzes - like pastpuzzle. Today: yes
pastpuzzle.de
past puzzle
Errate mithilfe von 4 historischen Ereignissen das gesuchte Jahr. Ein von Wordle und Geschichten aus der Geschichte inspiriertes Spiel.
010
Christian Folini @christian-folini.ch · 29/06/2025
Another hour and we're ready. Deer shank on a spit.
030
Christian Folini @christian-folini.ch · 02/06/2025
OWASP awarded me with a distinguished lifetime member award last week. I am deeply thankful for this recognition and the support by the OWASP CRS team that made this possible.
050
Christian Folini @christian-folini.ch · 27/05/2025
On my way to the @owasp.org WAF day and the OWASP AppSec EU conference in Barçelona. If you're around, please come and say hello!
030
Reposted by Christian Folini
Troy Hunt @troyhunt.com · 27/05/2025
I'm coming to Switzerland! Join me at the Microsoft Azure Zürich User Group in only a few weeks from now: www.meetup.com/de-DE/micros...
meetup.com
[In Person] Troy Hunt Have I Been Pwned Alpine Grand Tour Zürich , Di., 17. Juni 2025, 18:00 | Meetup
**IN-PERSON** Troy Hunt meetup at **Kraftwerk in Zurich** This meetup is a collaboration between several Swiss User Groups: [Azure Zurich User Group ](https://www.azurezur
1178
Reposted by Christian Folini
emily s. @emily.news · 08/05/2025
Pope Francis wanted to ensure that a new pope yielded the same result. This means the papacy is idempontiff
725946
Reposted by Christian Folini
Ben Adida @benadida.com · 04/05/2025
I spend a chunk of my time explaining how open-source, when you do it on purpose and have a publicly available code repository, strongly disincentivizes you from taking these silly and dangerous shortcuts. We should not underestimate the power of shame and public oversight.
083
Christian Folini @christian-folini.ch · 04/05/2025
What I find intriguing about hiring disguised North Koreans is that they excel in their job since you hired an entire team.
061
Christian Folini @christian-folini.ch · 17/04/2025
Digital integrity mit der #digiges und Jörg Mäder im #lichtspiel in Bern.
000
Christian Folini @christian-folini.ch · 16/04/2025
Andrew Kochura shared a very simple WAF smoke test with 15 diverse payloads that can serve as a simple indicator of the baseline quality of a WAF. I like the simplicity of this. Furthermore, I like that CRS covers 90% of the payloads by default and 100% at PL2. gist.github.com/kochuraa/fb3...
gist.github.com
Lightweight Bash script to test basic WAF (Web Application Firewall) protections against common SQL injection and XSS payloads. Use this to quickly assess your web application’s surface against low-ha...
Lightweight Bash script to test basic WAF (Web Application Firewall) protections against common SQL injection and XSS payloads. Use this to quickly assess your web application’s surface against low...
010