1. X
  2. CredShields
Log inSign up
CredShields
2,091 posts
CredShields profile banner
user avatar

CredShields

@CredShields
Full Scope Cybersecurity | Human Driven, AI Accelerated Pentesting | Continuous Monitoring | SOC2 Type II Audited
credshields.com
Joined December 2021
82
Following
3,396
Followers
RepliesRepliesArticlesArticlesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    user avatar
    CredShields
    @CredShields
    Feb 12
    CredShields and @SolidityScan are proud to contribute to the release of the @owasp Smart Contract Top 10 2026. OWASP Smart Contract Top 10 defines the primary contract-level failure patterns that repeatedly lead to loss in blockchain systems. Sincere gratitude to @ethereumfndn
    Image
  • user avatar
    CredShields
    @CredShields
    Aug 25
    500+ Medusa victims. Some newly disclosed flaws have been weaponized within 24 hours. If you can’t quickly tell whether you run the affected software and whether it’s exposed, patch speed isn’t the first bottleneck. Prioritize exploitation + exposure + business criticality.
    CredShields graphic on Medusa ransomware showing 500+ identified victims and noting that some newly disclosed vulnerabilities were weaponized within 24 hours. It highlights exposure visibility as the first bottleneck and recommends prioritizing active exploitation, exposure, and business criticality.
  • user avatar
    CredShields
    @CredShields
    Aug 25
    475M views in 24 hours. The game hadn’t even launched yet. GTA VI leak is a reminder that software can carry enormous value long before production. If a pre-release build leaves its intended environment, three questions matter: - who can get it, - where can it run, - and
    Image
    Image
    Image
  • user avatar
    CredShields
    @CredShields
    Aug 25
    You can outsource a critical system. You can’t always outsource the responsibility. For covered providers of essential services in Singapore, relying on a third-party system can still leave cybersecurity responsibility with them. So don’t audit only what you own. Start with
    CredShields “Risk Shift · Singapore” graphic showing an essential service inside an organisation depending on a system owned by a third party that is critical to keeping the service running. Headline: “Your audit can’t stop at systems you own.” Takeaway: “Map what your service relies on first.”
  • user avatar
    CredShields
    @CredShields
    Aug 21
    “Fixed” is useful. Verified is better. If a pentest finding disappears into tickets, Slack threads and status updates after delivery, proving what happened later gets messy fast. Here’s what the path to verified closure should look like 👇 Best experienced with sound on 🔊
    Image
    00:00
Advertisement
Advertisement