1. X
  2. Sebastien Gioria
Log inSign up
Sebastien Gioria
30.6K posts
user avatar
Sebastien Gioria
@SPoint
#OWASP France Leader/Expert Judiciaire #Application #Security/Life tweets. DevSecOPS Officer @LectraOfficial. Every tweet is personal, not company
France
blog.gioria.org
Born January 1, 1970
Joined May 2007
2,068
Following
2,287
Followers
RepliesRepliesMediaMedia
  • user avatar
    Sebastien Gioria
    @SPoint
    13h
    AsyncAPI compromis : le pwn request que j'annonçais en juin, version grandeur nature blog.gioria.org/fr/cybersec/as… #SupplyChainSecurity #DevSecOps
    blog.gioria.org
    AsyncAPI compromis : le pwn request que j’annonçais en juin, version grandeur nature
    Retour sur la compromission des pipelines AsyncAPI (miasma-train-p1, juillet 2026) : un cas réel de pwn request via pull_request_target sur des branches de pré-production non protégées.
    66
  • user avatar
    Sebastien Gioria
    @SPoint
    Aug 3
    Quand un agent IA se balade dans un ministère des finances bit.ly/45HV0ap #AgenticAI #CyberSec
    blog.gioria.org
    Quand un agent IA se balade dans un ministère des finances
    Analyse de l’attaque contre le ministère des Finances thaïlandais menée via l’agent IA open source Hermes en mode YOLO : LinPEAS, HiveServer2, implant Hades, 470 Mo d’outils stagés. STRIDE, impact,...
    111
  • user avatar
    Sebastien Gioria
    @SPoint
    Jul 31
    OWASP CVE Lite CLI passe en statut Lab Project blog.gioria.org/fr/devsecops/o… #OWASP #DevSecOps #SCA
    blog.gioria.org
    OWASP CVE Lite CLI passe en statut Lab Project
    OWASP CVE Lite CLI graduate en Lab Project : ce que fait l’outil et pourquoi ça compte.
    88
  • user avatar
    Sebastien Gioria
    @SPoint
    Jul 30
    RabbitMQ : un GET non authentifié pour prendre le contrôle complet du broker blog.gioria.org/fr/devsecops/r… #RabbitMQ #CVE #CyberSecurity
    blog.gioria.org
    RabbitMQ : un GET non authentifié pour prendre le contrôle complet du broker
    Analyse des CVE-2026-57219 (fuite du secret OAuth via /api/auth, CVSS 8.7) et CVE-2026-57221 (contournement d’autorisation sur les declare passifs) découvertes par Miggo dans RabbitMQ, avec STRIDE,...
    180
  • user avatar
    Sebastien Gioria
    @SPoint
    Jul 29
    AI Controls Matrix v1.1 : la CSA muscle son référentiel, et voilà ce que ça change blog.gioria.org/fr/ai/ai-contr… #CyberSecurity #AICM #AIGovernance
    blog.gioria.org
    AI Controls Matrix v1.1 : la CSA muscle son référentiel, et voilà ce que ça change
    Analyse de l’AI Controls Matrix v1.1 de la Cloud Security Alliance : nouveautés vs v1.0, mappages avec BSI AIC4, ISO 42001, EU AI Act et NIST AI RMF, et positionnement par rapport à MAESTRO, AISVS et...
    76

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement