Sign in

Niels Tanis

@niels.fennec.dev
309 followers 191 following 23 posts

Software Security Researcher & Engineer @ Tidalis Former @ Veracode Microsoft MVP Familyman & Renovator @ N28

PostsRepliesMedia
Reposted by Niels Tanis
Update Conference @updateconference.bsky.social · 24/09/2026
Going live soon with @niels.fennec.dev, hosted by Tomáš Herceg 🔴 Today on #HypelessAI: finding, testing, and fixing security flaws in .NET apps with AI. Starts at 13:00 CEST, with a live Q&A. Join us: www.hypeless-ai.net
021
Reposted by Niels Tanis
Update Conference @updateconference.bsky.social · 17/09/2026
One week to go. ⏳ AI helps us build faster — but it can also help attackers find vulnerabilities faster. Join @niels.fennec.dev for practical .NET AppSec demos, AI-assisted security testing, and live Q&A. Sep 24, 1 PM CEST: www.hypeless-ai.net #HypelessAI
011
Reposted by Niels Tanis
Update Conference @updateconference.bsky.social · 11/09/2026
Security is built or broken with every development decision. Meet the #UCP26 experts bringing practical insights into software security: 👉 @programmeral.com, Sander Molenkamp, Christian Schabetsberger and @niels.fennec.dev Explore their sessions: prague.updateconference.net/en/2026/sche...
031
Reposted by Niels Tanis
Update Conference @updateconference.bsky.social · 08/09/2026
Want to know what’s coming in the next #HypelessAI episode? Hear it directly from @niels.fennec.dev. 👇 Join us live on September 24 and learn how #AI can help you uncover and fix vulnerabilities in your .NET applications before attackers do. Get your spot 👉 www.hypeless-ai.net #AppSec #Dotnet
011
Reposted by Niels Tanis
Update Conference @updateconference.bsky.social · 20/08/2026
What happens when #AI makes your code faster, but your #security risks grow faster too? Find out in the next #HypelessAI livestream, featuring 🎙️ @niels.fennec.dev, Microsoft MVP and software security expert. 📅 Thursday, Sep 24 👉 Save the date and register here: hypeless-ai.updateconf.net
011
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 04/08/2026
Trusted publishing is the way to go if you can
devblogs.microsoft.com
Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime - .NET Blog
NuGet API key durations will be reduced to 30 days starting August 17th. This change will significantly strengthen the integrity of the NuGet supply chain.
293
Niels Tanis @niels.fennec.dev · 15/07/2026
It definitely was a year of change and that makes me really happy to see that I got renewed as MVP! Community and public speaking is the thing I still enjoy a lot and will continue on doing! Congratulations to all other MVP's that got renewed as well! #mvpbuzz
150
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 14/07/2026
In amongst today's big chungus of a patch Tuesday there are some .NET updates, so let's begin #dotnet #aspnetcore #patchTuesday
3107
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 09/06/2026
If you're using MessagePack-CSharp directly you should update your dependency, as they've fixed 12 vulnerabilities today. github.com/MessagePack-...
045
Reposted by Niels Tanis
Jamie Magee @jamiemagee.bsky.social · 23/05/2026
shipped three new build warnings so your dotnet SDK can finally tell on itself. you're welcome jamiemagee.co.uk/blog/a-new-w...
jamiemagee.co.uk
A new way to catch a vulnerable .NET SDK
When NuGet finds a vulnerable package in your project, it tells you. NU1901 through NU1904 have warned about CVEs in your dependencies for a while now. The SDK that runs the build, though? That’s been...
082
Reposted by Niels Tanis
NuGet @nuget.org · 19/05/2026
🚀 NuGet Pruning is cleaner restores and fewer false positives. Better security signals. In .NET 10, NuGet package pruning removes platform-provided dependencies from your graph, so you only see what actually matters: actionable alerts. Learn more: devblogs.microsoft.com/dotnet/nuget...
devblogs.microsoft.com
NuGet Package Pruning: Cleaner Dependencies and Actionable Vulnerability Reports - .NET Blog
Package pruning in .NET 10 removes platform-provided packages from your dependency graph. With transitive auditing enabled by default, projects with these defaults have 70% fewer transitive vulnerabil...
053
Reposted by Niels Tanis
NDC Conferences @ndcconferences.com · 12/05/2026
NDC Copenhagen is only 3 weeks away! 4 days, 55 speakers, 65 sessions, 7 workshops. All happening 1-4 June at Øksnehallen in Copenhagen. Whether you're into AI, .NET, architecture, security, or modern software practices, there's a track for you there! Tickets 👉 ndccopenhagen.com
NDC Copenhagen 2026 - ØksnehallenNDC Copenhagen 2026NDC Copenhagen 2026NDC Copenhagen 2026
041
Reposted by Niels Tanis
.NET Foundation @dotnetfoundation.org · 01/05/2026
📣.NET 10.0.7 Out-of-Band Security Update - .NET Blog Microsoft released .NET 10.0.7 as an out-of-band security update to address CVE-2026-40372. hubs.li/Q04dbWjB0 #dotnet
001
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 21/04/2026
.NET has an out of band update today to fix CVE-2026-40372, an Elevation of Privilege, which, in some cases, could allow an attacker to forge authentication tickets, or decode authentication tickets or other protected data. github.com/dotnet/annou...
github.com
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege · Issue #395 · dotnet/announcements
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege Executive Summary: A bug in Microsoft.AspNetCore.DataProtection 10.0.0-10.0.6 NuGet packages can give an attacker th...
22417
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 09/04/2026
Glasswing et al present a moral hazard to bug bounties. What I've seen recently is a significant increase in AI generated, or assisted vulnerability reports that are not vulnerabilities. (1/6)
3278
Reposted by Niels Tanis
Chris Wysopal @weld.bsky.social · 25/03/2026
I’m excited to let you know that the talks from [un]prompted—the AI Security Practitioner Conference—are now live on YouTube. No fluff, no hype—just real-world AI security from people actually doing the work. www.youtube.com/playlist?lis...
youtube.com
[un]prompted 2026 - YouTube
074
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 11/03/2026
That is not what a 0-day is. It is a .NET CVE, it *does not* effect .NET Framework. 🙄
5155
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 10/03/2026
It's not that I mind AI written vulnerability reports for .NET, but there are a few problems we're seeing 1) Simply submitting the output from your favourite AI without testing the code it says demonstrates the vulnerability is bad. (1/4)
173
Reposted by Niels Tanis
BSides London @bsideslondon.bsky.social · 01/03/2026
#BSidesLDN2025 videos are now live on our YouTube channel. Don’t forget to like and subscribe, we only publish once a year, your support makes a real difference! www.youtube.com/@Securitybsi... Huge thanks to @ministraitor.bsky.social & all our presenters for sharing their time and expertise!
0127
Reposted by Niels Tanis
Update Conference @updateconference.bsky.social · 24/02/2026
𝐓𝐡𝐢𝐬 𝐭𝐢𝐦𝐞 𝐰𝐞’𝐫𝐞 𝐠𝐨𝐢𝐧𝐠 𝐞𝐯𝐞𝐧 𝐝𝐞𝐞𝐩𝐞𝐫! #UCK26 👉 krakow.updateconf.net #UpdateConference #Krakow @davidortinau.com & @konradkokosa.bsky.social & @codrina.bsky.social & @jfversluis.dev & @louella.dev & @niels.fennec.dev
044
Reposted by Niels Tanis
Visual Studio @visualstudio.com · 14/02/2026
Aspire beyond the basics. Aspire goes beyond its defaults once you understand the ideas underneath it. That foundation opens the door to extending Aspire in meaningful ways. Watch the full session from VSLive! Orlando youtu.be/rZQbhDfj7ek
053
Reposted by Niels Tanis
NDC Conferences @ndcconferences.com · 09/02/2026
The NDC Copenhagen Agenda is out 🇩🇰 See the full agenda and secure your Early Bird tickets before 27 Feb 👉 ndccopenhagen.com #ndccph
NDC Copenhagen 2026 - 4-Day Event for Software Developers
032
Reposted by Niels Tanis
Signal @signal.org · 25/11/2025
Like many services, as Signal grows, it becomes a more appealing place for scammers to try and cause harm. We've put together tips to help you protect yourself from phishing, scams, & impersonation attempts. Plus info about how Signal support communicates. support.signal.org/hc/en-us/art...
support.signal.org
Staying Safe from Phishing, Scams, and Impersonation
We provide a privacy-first, end-to-end encrypted (E2EE) messaging and calling platform designed so only you and your intended recipients can communicate securely. Even with strong encryption, attac...
3414138
Reposted by Niels Tanis
NDC Conferences @ndcconferences.com · 27/01/2026
📢 The NDC Copenhagen #CFP ends this Sunday, 1 February! We welcome all subjects relevant to software developers. If you have something to say, then speak up! 📅 Deadline: 1 February 👉 Submit: ndccopenhagen.com/call-for-pap... #ndccopenhagen
Call for Papers ends 1 Feb
001
Reposted by Niels Tanis
Kelsey Hightower @kelseyhightower.com · 22/01/2026
After a bit of trial and error, I finally made an agent that does exactly what I want. No hallucinations. Runs locally. And costs almost nothing. #! /bin/bash // Do exactly this one task and nothing else. // If it doesn't work, wait 30 seconds and try // again. If that fails, log a message. doTask
3902
Reposted by Niels Tanis
Lars Klint @larsklint.bsky.social · 14/01/2026
On 9 January 2026 mine and my family's lives changed forever. I tell the full story in this video: youtu.be/mNEPSWcOheY If you want to support my family as well as our local community, consider sharing this post, or donating here: www.gofundme.com/f/we-lost-al...
71727
Reposted by Niels Tanis
Kelsey Hightower @kelseyhightower.com · 03/01/2026
If 2025 was the year of vibe coding, 2026 will be the year of vibe maintenance and security.
826426
Niels Tanis @niels.fennec.dev · 13/12/2025
It's that time of the season again, time for BsidesLondon! Let me know if you're around!
020
Reposted by Niels Tanis
NDC Conferences @ndcconferences.com · 10/12/2025
We’re headed to Toronto! 🇨🇦 We’re excited to partner up with @cppnorth.bsky.social for an incredible 4-day event you don’t want to miss. We’re currently booking speakers, and the CFP is open → ndctoronto.com
Introducing NDC Toronto, 5-8 May 2026
062
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 08/12/2025
Generating SBOMs for .NET apps and NuGet packages with Microsoft.Sbom.Targets
idunno.org
Generating SBOMs for .NET apps and NuGet packages with Microsoft.Sbom.Targets
How to use the Microsoft.SBOM.Targets NuGet package to produce a Software Bill of Materials (SBOM) during your release builds.
1268
Reposted by Niels Tanis
Niall Merrigan @nmerrigan.bsky.social · 09/12/2025
I recently did a talk on internet safety for parents/guardians and it was well received by those in the room. Its honestly the toughest talk I have researched and given. It might help you if you have kids or you are the local tech support for people with small humans. www.youtube.com/watch?v=UgF5...
youtube.com
Won't somebody please think of the children!? – Niall Merrigan – HelloStavanger 2025
YouTube video by HelloStavanger
0137
Reposted by Niels Tanis
Erlend Oftedal @webtonull.bsky.social · 06/12/2025
The call for papers for NDC Security ends tomorrow. Come do your talk in Oslo: ndcsecurity.com/call-for-pap...
035
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 22/11/2025
I think this is not the type of “tampering” Matt Blaze was concerned with
arstechnica.com
Oops. Cryptographers cancel election results after losing decryption key.
Voting system required three keys. One of them has been “irretrievably lost.”…
1111
Reposted by Niels Tanis
NDC Conferences @ndcconferences.com · 20/11/2025
If you missed Aleksander Stensby's 2-day workshop on MCP and RAG at NDC AI last week, don’t worry - you can still join the online workshop on 1–2 December! event.checkin.no/206017/ndc-o...
event.checkin.no
NDC ONLINE WORKSHOPS – 1. des. 2025 – NDC Conferences AS
011
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 18/11/2025
The details of .NET's PQ algorithms, and their APIs are available devblogs.microsoft.com/dotnet/post-...
devblogs.microsoft.com
Post-Quantum Cryptography in .NET - .NET Blog
What we've added for PQC, and how we got there.
1133
Reposted by Niels Tanis
Visual Studio User Group @visug.bsky.social · 07/11/2025
🎤 Meet one of our VISUG XL 2025 speakers: 𝐍𝐢𝐞𝐥𝐬 𝐓𝐚𝐧𝐢𝐬! We’re excited to welcome 𝐍𝐢𝐞𝐥𝐬 this year at Visug XL, our yearly, free, community-driven .NET conference. 📅 November 28, 2025 📍 UCLL Leuven 👉 More information and tickets: www.visug.be/Events/102 #VisugXL #DotNet #Community #Conference
021
Reposted by Niels Tanis
NDC Conferences @ndcconferences.com · 06/11/2025
With 80% of modern #apps built on third-party #code, supply chain #security has become critical. Don't miss @niels.fennec.dev "Beyond Trust: Building Community-Driven Security Analysis for Your .NET Software Supply Chain" at #NDCManchester! ndcmanchester.com/agenda/beyon...
ndcmanchester.com
Beyond Trust: Building Community-Driven Security Analysis for Your .NET Software Supply Chain | NDC Manchester 2025
With 80% of modern applications built on third-party code, supply chain security has become critical. Traditional security tools like OpenSSF Security Scorecard provide surface-level metrics, but fail...
042
Reposted by Niels Tanis
Katie Mack @astrokatie.com · 19/06/2025
Chatbots — LLMs — do not know facts and are not designed to be able to accurately answer factual questions. They are designed to find and mimic patterns of words, probabilistically. When they’re “right” it’s because correct things are often written down, so those patterns are frequent. That’s all.
6263661711258
Reposted by Niels Tanis
.NET @dot.net · 27/10/2025
We are increasing the length of support offered for .NET Standard Term Support (STS) releases from 18 months to 24 months. This change is effective starting with .NET 9 and there is no change for LTS releases. Get all the details you need: msft.it/63328t6MeM
Timeline of .NET Standard Term Support.
text reads:
.NET STS releases supported for 24 months
.NET 7
Nov 2022
.NET 8
Nov 2023
May 2024
.NET 9
Nov 2024
Latest release
.NET 10
Nov 2025
May 2026
.NET 11
Nov 2026
STANDARD TERM SUPPORT
Patches for 2 years
LONG TERM SUPPORT
Patches for 3 years
Get the details
The image also includes a timeline with colored bars:
Purple bar = Standard Term Support (STS) for 2 years.
Gray bar = Long Term Support (LTS) for 3 years.
.NET 9 is highlighted as the latest release.
12310
Reposted by Niels Tanis
Microsoft Security Response Center @msrc.microsoft.com · 23/10/2025
Microsoft is expanding transparency in vulnerability management. We are now publishing VEX (Vulnerability Exploitability eXchange) attestations for third-party CVEs associated with the Azure Linux Distribution (formerly CBL-Mariner). Learn why VEX matters in our blog post: msft.it/6014shEmn
022
Reposted by Niels Tanis
Dennis "D.C." Dietrich @dcdietrich.bsky.social · 22/10/2025
"A new and ongoing supply-chain attack is targeting developers on the OpenVSX and Microsoft Visual Studio marketplaces with self-spreading malware called #GlassWorm that has been installed an estimated 35,800 times." #CyberSecurity #VSCode #SupplyChainAttack www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Self-spreading GlassWorm malware hits OpenVSX, VS Code registries
A new and ongoing supply-chain attack is targeting developers on the OpenVSX and Microsoft Visual Studio marketplaces with self-spreading malware called GlassWorm that has been installed an estimated ...
021
Reposted by Niels Tanis
Dennis "D.C." Dietrich @dcdietrich.bsky.social · 15/10/2025
"Researchers [...] said today that it takes only 250 specially crafted documents to force a generative AI model to spit out gibberish when presented with a certain trigger phrase." #AI #LLM #GenAI #ModelPoisoning #AISecurity #CyberSecurity www.theregister.com/2025/10/09/i...
theregister.com
Data quantity doesn't matter when poisoning an LLM
: Just 250 malicious training documents can poison a 13B parameter model - that's 0.00016% of a whole dataset
021
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 14/10/2025
It's Patch Tuesday and ASP.NET Core has a doozy, with a CVSS score of 9.9, our highest ever. Let's examine why. The bug enables http request smuggling, which on its own for ASP.NET Core would be nowhere near that high, but that's not how we rate things... * Thread- (1/7)
github.com
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability · Issue #371 · dotnet/announcements
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability i...
64841
Reposted by Niels Tanis
Barry Dorrans @blowdart.me · 14/10/2025
And while we're talking about .NET security we have another announcement. Do you build and distribute your own version of .NET? Then you wanted to get early access to upcoming patch information sooner to protect your customers at the same time as we release patches.
031
Reposted by Niels Tanis
Visual Studio User Group @visug.bsky.social · 13/10/2025
⏳ #𝐕𝐢𝐬𝐮𝐠𝐗𝐋 𝟐𝟎𝟐𝟓 is approaching! We’re gearing up for our annual 𝐜𝐨𝐦𝐦𝐮𝐧𝐢𝐭𝐲-𝐝𝐫𝐢𝐯𝐞𝐧 .𝐍𝐄𝐓 𝐜𝐨𝐧𝐟𝐞𝐫𝐞𝐧𝐜𝐞! 💜 The 𝐚𝐠𝐞𝐧𝐝𝐚 𝐢𝐬 𝐚𝐥𝐦𝐨𝐬𝐭 𝐫𝐞𝐚𝐝𝐲, and we can’t wait to share the amazing lineup with you soon! 📅 𝐍𝐨𝐯𝐞𝐦𝐛𝐞𝐫 𝟐𝟖, 𝟐𝟎𝟐𝟓 — 𝐔𝐂𝐋𝐋 𝐋𝐞𝐮𝐯𝐞𝐧 🎟️ Get your 𝐭𝐢𝐜𝐤𝐞𝐭𝐬 here 👉 www.visug.be/Events/102
011
Reposted by Niels Tanis
Chris Wysopal @weld.bsky.social · 10/10/2025
Was this DEFCON eBPF bug talk hallucinated? www.thestack.technology/defcon-ebpf-...
thestack.technology
DEFCON talk on Linux kernel bugs drives AI slop row
"The code would not compile or run. This all points to LLM hallucination..."
183
Reposted by Niels Tanis
Ryan Naraine @ryanaraine.bsky.social · 08/10/2025
For the SecurityConversations show, I interviewed appsec and software supply chain security expert Chris Eng @ceng.bsky.social LISTEN securityconversations.com/episode/chri...
securityconversations.com
Chris Eng on lessons learned from the NSA, @Stake, Veracode, and 20 years in cybersecurity - Security Conversations
This week on Security Conversations, Ryan sits down with Chris Eng, former Chief Research Officer at Veracode, to talk about life after nearly two decades […]
344
Reposted by Niels Tanis
Kelsey Hightower @kelseyhightower.com · 29/09/2025
"We want AI agents that can discover like we can, not which contain what we have discovered. Building in our discoveries only makes it harder to see how the discovering process can be done." - The Bitter Lesson (2019), by Rich Sutton www.incompleteideas.net/IncIdeas/Bit...
The Bitter Lesson by Rich Sutton published on March 13, 2019. The post can be read at http://www.incompleteideas.net/IncIdeas/BitterLesson.html
210719
Reposted by Niels Tanis
Maarten Balliauw @maartenballiauw.be · 25/09/2025
I'm hiring! Looking for an #aspnetcore dev, ideally with identity/oidc experience. Role is support, tech presales, advisory, docs, ... East coast US ideally for timezone overlap in the team Small team and company, big ambition. Reach out if you're interested! duendesoftware.com/careers/cust...
duendesoftware.com
Customer Success Engineer
Duende software looking to fill Customer Success Engineer position
11111
Reposted by Niels Tanis
Richard Campbell @richcampbell.bsky.social · 19/09/2025
Alternative MFA...
0121