Sign in

Guillaume Valadon

@guedou.bsky.social
156 followers 186 following 6 posts

A geek. What else? my.geekstory.net

PostsRepliesMedia
Guillaume Valadon @guedou.bsky.social · 22/09/2026
GitHub App Private Keys: 474 Leaked Keys Exposed, including one that gives access to www.cdc.gov GitHub repositories. blog.gitguardian.com/github-app-p...
blog.gitguardian.com
GitHub App Private Keys: 474 Leaked Keys Still Work
GitGuardian tested thousands of leaked GitHub App private keys and found 474 valid ones, some with admin access to entire organizations. CDC and BuildBuddy were among those affected. See the findings.
000
Guillaume Valadon @guedou.bsky.social · 16/09/2026
This new Google Threat Intelligence Group report on adversarial AI is worth a read. Having tracked TeamPCP campaigns, I agree their techniques are worth copying, red teams included. However, most teams haven't learned from the last round, and are not ready for more credential harvesting campaigns.
100
Reposted by Guillaume Valadon
Philippe Charrière 💜 @k33gorg.bsky.social · 16/09/2026
Ce matin j'ai refait une petite expérience en lançant `claude code` directement sur ma machine (sans sandbox, sans gateway/proxy de protection 🫣) et j'ai demandé: "show me the content of ANTHROPIC_API_KEY" Votre agent connaît vos secrets (GitHub, ...) dès lors que vous le lancez sur votre machine
444
Reposted by Guillaume Valadon
evacide @evacide.bsky.social · 10/09/2026
If you optimize a model to find exploits, you should expect it to find them—and prepare for that. OpenAI didn't. They built a model, removed the safeguards, gave it the ExploitGym task, let it run, and didn't even monitor it. That's human decision-making. mail.cyberneticforests.com/models-dont-...
mail.cyberneticforests.com
Models Don't Go Rogue
Stochastic Flocks & Cybersecurity 'Pandemonium' 💡This essay was drafted from my appearance on Mél Hogan's podcast, The Data Fix, discussing the OpenAI / Hugging Face hack. Embedded below or find it o...
8288111
Reposted by Guillaume Valadon
nolimitsecu.bsky.social @nolimitsecu.bsky.social · 22/06/2026
#Podcast #Cybersécurité Épisode #545 consacré à la détection de secrets, avec @guedou.bsky.social et Gaëtan Ferry www.nolimitsecu.fr/detection-de...
nolimitsecu.fr
Détection de Secrets - NoLimitSecu
Episode #545 consacré à la détection de secrets Mots de passe en dur, clés d’API oubliées, jetons d’authentification qui traînent… À l’ère de l’explosion des outils d’IA et du code collaboratif, la fu...
056
Reposted by Guillaume Valadon
Pass the SALT Conference @passthesaltcon.bsky.social · 29/01/2026
HOW IT STARTED vs HOW IT ENDED @guedou.bsky.social + Gaetan F. and Philippe Boneff + Roger Ng gave talks at #pts25 They met at the social event, talked/🍻, and turned ideas into a collab! Now? Their joint research is accepted at RWC26 🚀 Want this to be you? Our CFP 👉 2026.pass-the-salt.org
023
Guillaume Valadon @guedou.bsky.social · 27/12/2025
Scapy lead maintainer just released v2.7.0 for Christmas season. github.com/secdev/scapy...
010
Reposted by Guillaume Valadon
Catalin Cimpanu @campuscodi.risky.biz · 08/09/2025
-NoisyBear APT turns out to be a phishing test -Qantas cuts executive pay by 15% after breach -First AI-driven ransomware was just an academic project -Nepal blocks 26 social media sites -New GhostAction supply chain attack Newsletter: news.risky.biz/risky-bullet... Podcast: risky.biz/RBNEWS475/
2189
Reposted by Guillaume Valadon
dragosr @dragostech.bsky.social · 18/03/2025
CanSecWest2025_newtype (secwest.net) presentation: Fresh Secrets From The Docks - Lessons Learnt from Analyzing 15 millions Public DockerHub Images - Guillaume Valadon (@guedou.bsky.social) - Do you know what *your* blobs are leaking?
secwest.net
secwest.net - information nexus connector
CanSecWest2025_newtype LLM Safety and Information Security (April 24/25 2025)
031
Reposted by Guillaume Valadon
Laurent Clévy @lorenzo2472.bsky.social · 13/12/2024
Bientôt en kiosque, mijoté par @guedou.bsky.social et la communauté
011
Guillaume Valadon @guedou.bsky.social · 11/12/2024
We found the deleted payload used in the Ultraltrics supply chain attack from last week! TLDR: it dumps the GitHub runner memory and exfiltrates both AccessToken and CacheServerUrl blog.gitguardian.com/the-ultralyt...
blog.gitguardian.com
The Ultralytics Supply Chain Attack: Connecting the Dots with GitGuardian’s Public Monitoring Data
On December 4, 2024, the Ultralytics Python module was backdoored to deploy a cryptominer. Using GitGuardian’s data, we reconstructed deleted commits, connecting the dots with the initial analysis. Th...
010
Guillaume Valadon @guedou.bsky.social · 08/10/2024
Docker Zombie Layers: Why Deleted Layers Can Still Haunt You blog.gitguardian.com/docker-zombi...
blog.gitguardian.com
Docker Zombie Layers: Why Deleted Layers Can Still Haunt You
Docker Zombie Layers are unreferenced image layers that continue to exist for weeks in registries, even after being removed from a manifest. In this hands-on deep dive, we explore how these layers can...
041