Sign in

Alex

@securelayer.co
96 followers 340 following 107 posts

Help bridging the gap between high-level strategy and hands-on engineering to build more secure apps | 10 years+ XP | ex GovFR Signal: securelayer.403 Europe📍 Caribbean

PostsRepliesMedia
Reposted by Alex
Rayna 🤓🇪🇺👩‍💻📚✍️ @maliciarogue.bsky.social · 18/08/2026
Au fait, y a votre dévouée dans 28 minutes sur @artefr.bsky.social ce soir (sur les fuites de données, notamment celle de la DGFIP). Ce sera... vivifiant comme échange 🤓
719264
Reposted by Alex
bobdahacker | Ethical Hacker & Security Enthusiast [Unofficial] @bobdahacker.com.web.brid.gy · 04/08/2026
bobdahacker.com
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
How a missing Firestore security rule on tl;dv exposed 181,874 meetings from 84,312 users across 35,003 domains, including live calls I could join uninvited, and how six months of disclosure got me nothing but seen receipts.
001
Reposted by Alex
Bearstech @bearstech.com · 27/07/2026
Tiens, un article de GitLab sur la mesure de l’empreinte carbone des pipelines CI/CD : about.gitlab.com/fr-... Chez Bearstech, nous travaillons depuis longtemps sur la mesure de l’impact carbone des infrastructures : bearstech.com/servic...
Illustration tirée de l'article gitlab.
062
Reposted by Alex
Steelwise.uk @steelwise.bsky.social · 21/07/2026
NCSC says passkeys first, passwords second. The NCSC has flipped its authentication advice at CYBERUK 2026. Passkeys are now the recommended default, and password plus two-step verification is the fallback. The reasoning is worth understanding. Read the filing #infosec #cybersecurity
steelwise.uk
NCSC says passkeys first, passwords second | Steelwise
NCSC now recommends passkeys as the default and password plus two-step verification as the fallback. Traditional codes are still phishable.
001
Reposted by Alex
CERT-FR @cert-fr.bsky.social · 13/07/2026
Les membres du Centre de Coordination des Crises Cyber ont observé le ciblage et la compromission d’entités françaises au moyen du MOA TURLA opéré par le 16ème Centre du FSB : www.cert.ssi.gouv.fr/cti/CERTFR-2...
074
Reposted by Alex
The Verge @theverge.com · 11/06/2026
Amazon’s data centers used 2.5 billion gallons of water last year www.theverge.com/tech/948534/...
theverge.com
Amazon’s data centers used 2.5 billion gallons of water last year
Amazon’s using a lot of water, but claims it’s using it efficiently.
138243
Reposted by Alex
Alexandre Archambault @archambault-avocat.fr · 10/06/2026
Notification à la Commission 🇪🇺par les autorités 🇫🇷 du projet de décret #SREN précisant les obligations de publication d'indicateurs environnementaux par les fournisseurs #Cloud dont le CA 🇫🇷 > 10 M€ technical-regulation-information-system.ec.europa.eu/fr/notificat...
Projet de décret pris en application loi SREN précisant les obligations de publication d'indicateurs environnementaux par les fournisseurs Cloud établis en France dont le chiffre d'affaires dépasse les 10 millions €Projet de décret pris en application loi SREN précisant les obligations de publication d'indicateurs environnementaux par les fournisseurs Cloud établis en France dont le chiffre d'affaires dépasse les 10 millions €Projet de décret pris en application loi SREN précisant les obligations de publication d'indicateurs environnementaux par les fournisseurs Cloud établis en France dont le chiffre d'affaires dépasse les 10 millions €
001
Reposted by Alex
Jason Koebler @jasonkoebler.bsky.social · 01/06/2026
New: Hackers have been stealing high-profile Instagram accounts by simply asking Meta's AI support chatbot to change the email associated with the account they want to steal. Shockingly easy, terrible flaw associated with offloading support to AI: www.404media.co/hackers-simp...
404media.co
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
The exploit shows the extreme risk of offloading technical support to AI.
431790858
Reposted by Alex
Cloudflare @cloudflare.social · 18/05/2026
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. cfl.re/4eSYw7W
blog.cloudflare.com
Project Glasswing: what Mythos Preview showed us
In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.
0307
Reposted by Alex
La France sur Bluesky/Eurosky @france-atmosphe.re · 24/05/2026
Retrouvez notre kit de démarrage cyber et cybersécurité. Comme pour nos autres kits, nous n'avons pas inclus les personnes, dont de très bons influenceurs, pour nous concentrer sur des institutions : administrations, associations... Un oubli ? Vous savez où nous trouver 😉
3179
Reposted by Alex
La France sur Bluesky/Eurosky @france-atmosphe.re · 21/05/2026
Voici notre kit de démarrage des comptes d'ONG et associations présentes sur Bluesky.
102819
Reposted by Alex
M82 @m82.eurosky.social · 24/05/2026
Si vous avez des comptes à proposer n'hésitez pas contacter @france-atmosphe.re !
042
Reposted by Alex
cybart.eurosky.social @cybart.eurosky.social · 21/05/2026
"C’est davantage à l’Etat d’investir des plateformes numériques saines et bien gouvernées afin d’y attirer le public qu’à ce public d’y aller en espérant que les communicants institutionnels finiront par évoluer." Tout est dans cette phrase. www.lemonde.fr/idees/articl...
lemonde.fr
« La souveraineté numérique se construit par étapes, et si les institutions ne bougent pas, le public ne bougera pas »
TRIBUNE. Dans une tribune au « Monde », les spécialistes des nouvelles technologies Nicolas Hénin et Robin Berjon reviennent sur l’engouement suscité par le compte X piloté par le Quai d’Orsay, French...
0106
Reposted by Alex
The DEFCON Warning System @defconwarningsystem.com · 04/05/2026
NATO strain. Cuba pressure. Hormuz instability. This week’s DEFCON Warning System briefing examines rising alliance tensions, U.S. signalling in the Caribbean, and growing great-power friction around Iran. Read the full report: defconwarningsystem.com/2026/05/04/n...
001
Reposted by Alex
Alexandre Archambault @archambault-avocat.fr · 30/04/2026
Un jour on vous expliquera comment un Gus qui avait poutré le SI d'examen de sa Fac a été recruté par un autre Gus qui 15 ans auparavant avait bien poutré. Pour terminer n°2 du réseau d'un opérateur. Et désormais sémillant premier magistrat de sa commune dévoué au bien commun (et à la cybersécurité)
093
Reposted by Alex
European Commission @ec.europa.eu · 28/04/2026
EU lawmaking is getting simpler and better. We are making EU rules clearer and faster to enforce – so that they really work for people and businesses. Find out more 👉  link.europa.eu/hbkMpB
‘Simpler is better.’ written in bold blue text on a light background  behind the words, and a small European Commission logo in the bottom right corner.
09011
Reposted by Alex
InfoSec @infosec.skyfleet.blue · 27/04/2026
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
thehackernews.com
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations can validate, prioritize, and remediate what it finds. The debate that followed has mostly focused on the right
032
Reposted by Alex
NICOLAS ARPAGIAN @arpagian.bsky.social · 26/04/2026
L’industrie européenne mise sur les faisceaux laser pour assurer ses communications numériques Mes explications sur @franceinfo.fr www.franceinfo.fr/replay-radio... #cyber @thalesaleniaspace.bsky.social @cnes.fr #nouveaumonde
franceinfo.fr
L’industrie européenne mise sur les faisceaux laser pour assurer ses communications numériques
Face aux accidents et attaques conduites contre les câbles sous-marins qui assurent l'essentiel des communications numériques mondiales, l'Europe renforce sa résilience en développant un système sécur...
001
Reposted by Alex
European Commission @ec.europa.eu · 24/04/2026
We are🔓finance for green investments. The EU and financial partner institutions have signed the Global Green Bond Initiative Fund to mobilise up to €20 billion of private capital for sustainable infrastructure projects in partner countries. link.europa.eu/GpVR6M
A landscape photograph of three workers wearing white hard hats and white shirts walking through a grassy field in a solar farm. They are flanked by long, symmetrical rows of solar panels extending into the distance under an overcast sky.

In the foreground, yellow and white text reads: "Global Green Bond Initiative Fund: Mobilising up to €20 billion for sustainable infrastructure projects." A small European Union flag icon is visible in the bottom right corner.
25310
Reposted by Alex
Cloudflare @cloudflare.social · 24/04/2026
Are you watching yours? Cloudflare DNS filtering uses data from 5.7 trillion daily queries to stop threats before they reach your network. Read the overview to see how it works: cfl.re/4tZ7jJD
091
Reposted by Alex
The Register @theregister.com · 23/04/2026
Dev targeted by sophisticated job scam: 'I let my guard down, and ran the freaking code'
go.theregister.com
Dev targeted by sophisticated job scam: 'I let my guard down, and ran the freaking code'
Legit-looking website, camera-on interviews, jokes about backdoors ... it worked EXCLUSIVE  It all started with a LinkedIn message, as so many employment scams do these days.…
0176
Reposted by Alex
The Register @theregister.com · 23/04/2026
GitHub opts all CLI users into telemetry collection whether they want it or not
go.theregister.com
GitHub opts all CLI users into telemetry collection whether they want it or not
Opt-out instructions included if you're not keen on GitHub watching you in the name of product improvement Users of GitHub's command-line interface (CLI) who value privacy, beware. The Microsoft-owned code-hosting platform has quietly begun collecting pseudonymous client-side telemetry from CLI users and enabled it by default.…
142
Reposted by Alex
The Register @theregister.com · 23/04/2026
Using the password 'admin123' wasn't as bad as sharing it on Slack www.theregister.com/2026/04/23/s...
theregister.com
Using password 'admin123' wasn't as bad as Slacking it
PWNED: Keeping it simple for the developers can lead to very complex headaches later
021
Reposted by Alex
HN @hnws.bsky.social · 23/04/2026
Incident with Multple GitHub Services L: www.githubstatus.com/incidents/myrb… C: news.ycombinator.com/item?id=478776… posted on 2026.04.23 at 12:21:55 (c=0, p=2)
011
Reposted by Alex
Sarah Gooding @sarahgooding.bsky.social · 23/04/2026
🔺 We updated our technical analysis for the Bitwarden compromise. Third supply chain compromise in 3 days: a security scanner, an AI agent CLI, and a password manager CLI. Attackers are hammering tools with privileged access to infrastructure, so keep your eyes open this week. This is life now.
0218
Reposted by Alex
EU Tech News by LeafPlaza: EU-sovereign social media @newsbot.app.leafplaza.eu · 23/04/2026
La saga continue : un paquet NPM vérolé de Bitwarden CLI a dérobé des secrets
next.ink
La saga continue : un paquet NPM vérolé de Bitwarden CLI a dérobé des secrets
Le paquet NPM du CLI de Bitwarden publié comme la version 2026.4.0 est en fait un malware qui récupère les secrets, clés SSH et autres identifiants. Cette version a été rapidement étiquetée comme « obsolète » et l’équipe du projet a contacté NPM pour que le paquet soit retiré au plus...
001
Reposted by Alex
Afnic @afnic.bsky.social · 14/04/2026
🏆 Votre organisation veut sa propre extension internet ? 🗓️ Le 30 avril 2026, l'ICANN ouvre un appel à candidatures — opportunité rarissime ! Nos questions, vos réponses : 🧭 Partie 1 : www.afnic.fr/observatoire... 🚀 Partie 2 : www.afnic.fr/observatoire...
011
Reposted by Alex
Afnic @afnic.bsky.social · 15/04/2026
🌐 Vous souhaitez renforcer votre expertise DNS et gagner en autonomie sur des architectures fiables et performantes ? 📅 Inscrivez-vous à notre prochaine date pour la formation Administrateur DNS !du 25 au 26 juin 💻 Formation en ligne par Stéphane Bortzmeyer 🔗 www.afnic.fr/produits-ser...
023
Reposted by Alex
Alexandre Archambault @archambault-avocat.fr · 22/04/2026
First they ignore you, then they laugh at you, then they fail, then you win. Que de chemin parcouru. Bravo aux équipes de #Scaleway qui n’ont rien lâché pour faire mentir les experts de canapé. Scaleway (Iliad/Free) récupère l’hébergement du #HealthDataHub /-)
13412
Reposted by Alex
Alexandre Archambault @archambault-avocat.fr · 23/04/2026
Et officialisation de la migration vers @scaleway.com qui, avec d'autres trublions 🇫🇷et 🇪🇺, oeuvre concrètement à la souveraineté de notre continent depuis de nombreuses années (bien avant que cela ne devienne à la mode) health-data-hub.fr/sites/defaul...
health-data-hub.fr
01610
Reposted by Alex
Libération @liberation.fr · 23/04/2026
Hébergement des données de santé : le gouvernement choisit le français Scaleway pour remplacer Microsoft. La filiale de services cloud du groupe Iliad prend la suite du géant américain par mesure de sécurité contre toute ingérence étrangère. Lire ⤵️
liberation.fr
Hébergement des données de santé : le gouvernement choisit le français Scaleway pour remplacer Microsoft
La filiale de services cloud du groupe français Iliad prend la suite du géant américain par mesure de sécurité contre toute ingérence étrangère.
03923
Reposted by Alex
Signal @signal.org · 22/04/2026
We are very happy that today Apple issued a patch and a security advisory. This comes following 404 Media reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted.
111789473
Reposted by Alex
MDN Web Docs @developer.mozilla.org · 19/04/2026
Generate cryptographically secure UUIDs in the browser 🔐 `crypto.randomUUID()` is built into the Web Crypto API, no npm package needed. Works in all modern browsers and Node.js 14.17+. Learn more 👇 developer.mozilla.org/en-US/docs/...
Code snippet demonstrating the use of `self.crypto.randomUUID()` for generating a UUID in JavaScript, with a sample output shown.
6894
Alex @securelayer.co · 05/11/2025
🎧 New drop on the playlist! Les fondamentaux de la cybersécurité by NoLimitSecu. 👉 Listen now: open.spotify.com/episode/2jhU5m98Ds…
Podcast cover image
010
Alex @securelayer.co · 01/09/2025
🎧 New drop on the playlist! Risky Biz Soap Box: Prowler, the open cloud security platform by Patrick Gray. 👉 Listen now: open.spotify.com/episode/4XoUigGqs6…
Podcast cover image
010
Reposted by Alex
The Register @theregister.com · 22/07/2025
NASA hacked hardware of camera orbiting Jupiter – and fixed it
dlvr.it
NASA hacked hardware of camera orbiting Jupiter – and fixed it
Deliberate overheating brought relief to Juno probe’s camera, twice NASA has revealed that one of the cameras on the Juno craft it sent to Jupiter malfunctioned, and that it fixed it with some very, very, remote hardware hacking.…
04813
Reposted by Alex
Ars Technica @arstechnica.com · 16/07/2025
arstechnica.com
Hackers exploit a blind spot by hiding malware inside DNS records
Technique transforms the Internet DNS into an unconventional file storage system.
35314
Reposted by Alex
Birgitte Breemerkamp 🌈 (she/her) @thebirg.bsky.social · 15/07/2025
For switching to EU/European alternatives for WeTransfer, see: european-alternatives.eu/alternative-...
european-alternatives.eu
European alternatives to WeTransfer | European Alternatives
WeTransfer is a file-sharing service from the United States.
27929
Reposted by Alex
Q₉ @q9f.bsky.social · 15/07/2025
I’ve been using SwissTransfer for 2 years, it’s free, keeps files online for 1 month instead of 15 days, and allows up to 50 GB by link. www.swisstransfer.com
swisstransfer.com
SwissTransfer - Envoi sécurisé et gratuit de gros fichiers
Envoyez jusqu'à 50 Go - Gratuit et sans inscription - Gardez vos transferts jusqu'à 30 jours.
0143
Reposted by Alex
🎃Autopsy of Ashley Lynch 🔪🎞️ @ashleylynch.bsky.social · 15/07/2025
WeTransfer just changed their TOS giving themselves permission to train AI on any content you transfer and produce derivative works based on content you transfer that they are allowed to monetize and you are not allowed payment for. Stop using WeTransfer.
12475515246
Reposted by Alex
HackerNoon @hackernoon.com · 02/07/2025
Blockchain Security Layers: Tradeoffs Between L1, L2, and Hardware TEEs #confidentialsmartcontracts
hackernoon.com
Blockchain Security Layers: Tradeoffs Between L1, L2, and Hardware TEEs
011
Reposted by Alex
HackerNoon @hackernoon.com · 06/07/2025
AI writes your code fast—but is it safe? This guide shows simple ways to avoid common security mistakes in AI-generated apps and projects. #aigeneratedcode
hackernoon.com
40% of AI-Generated Code Is Vulnerable. How to Protect Yours!
011
Reposted by Alex
InfoSec @infosec.skyfleet.blue · 30/06/2025
RIFT – New Open-Source Tool From Microsoft to Analyze Malware Hidden Within Rust Binaries
cybersecuritynews.com
RIFT - New Open-Source Tool From Microsoft to Analyze Malware Hidden Within Rust Binaries
001
Alex @securelayer.co · 30/06/2025
Cybersécurité dans l'espace : comment protéger nos satellites des nouvelles menaces ? www.futura-sciences.com/sciences/act...
"An infographic illustrating a satellite communication system. It features various satellites in orbit, including a 'Trusted Satellite' and a 'Government Satellite,' connected to ground stations and mobile units. The image highlights different cybersecurity threat types and levels of sophistication, categorized by skills and methods, with a color-coded table on the right side detailing the threat levels and their corresponding categories."
010
Alex @securelayer.co · 29/06/2025
How to Harden #GitHub Actions www.wiz.io/blog/github-...
wiz.io
Hardening GitHub Actions: Lessons from Recent Attacks | Wiz Blog
Build resilient GitHub Actions workflows with insights from real attacks, missteps to avoid, and security tips GitHub’s docs don’t fully cover.
010
Alex @securelayer.co · 29/06/2025
Security #BSides Cayman Islands | September 17-19 Get your Tickets => bsides.ky
bsides.ky
Security BSides Cayman Islands – … Coming In 2025
000
Alex @securelayer.co · 28/06/2025
🎧 New drop on the playlist! [Tour de France de la Cyber] Nouvelle-Calédonie : la cyber dans le Pacifique by Leslie Fornero. 👉 Listen now: open.spotify.com/episode/5iwRpbAHcH…
Podcast cover image
000
Reposted by Alex
Alexandre Archambault @archambault-avocat.fr · 24/06/2025
Nouvelle décision rappelant que la non conformité au #RGPD est un motif de résolution du contrat de développement de site Internet. Ici l'agence & société de financement condamnées à restituer les montants perçus. (CA Bordeaux, 11/06/2025, 23/02206) www.courdecassation.fr/decision/684...
073
Reposted by Alex
Anaïs Meunier @principedebase.bsky.social · 20/06/2025
Jean Kevin ou Jean-Michel citations ? Mais je plussois :)
011