EdgeBit @EdgebitIO
Real-time supply chain security that connects builds/SBOMs to the kernel, enabling security teams to target & coordinate vulnerability remediation without toil. edgebit.io Fully Remote Joined May 2022-
Tweets65
-
Followers92
-
Following3
-
Likes27
EdgeBit is leaning hard into a “find, fix and merge” ethos by introducing Dependency Autofix to our security platform. Dependency Autofix makes your code branches have the latest & safest set of dependencies, using AI and static analysis under the hood. edgebit.io/blog/announcin…
EdgeBit now supports syncing workloads from ECS in addition to existing EKS, Kubernetes, EC2 and other Linux workloads. Runtime context is the only way to understand your risk *right now* and powers a highly automated security program. More: edgebit.io/blog/sync-ecs-…
We’ve partnered with Vanta to give EdgeBit customers greater context and increased automation around vulnerability management in their compliance programs. More on the blog or log in to Vanta or EdgeBit to get started. edgebit.io/blog/vanta-com…
We're looking for a Graduate-level Software Engineering Intern to join the team this summer to focus on code analysis. Ideal candidates have a focus or concentration in programming language theory or compiler construction. See our careers page for more: edgebit.io/careers/
Can Linux enforce that a workload's SBOM remains a truthful representation of the running app? EdgeBit authored a paper covering the research to find out. This will be published in an ACM journal but you can find more detail & background on our blog today edgebit.io/blog/enforcing…
EdgeBit is speaking all over at the end of November: - Nov 16th @ Bay Area SLSA meetup: resources.github.com/github-slsa-me… - Nov 17th @ RVA.js conf: rvatech.com/rvatech-events… - Nov 30th @ ACM Workshop on Software Supply Chain Offensive Research & Ecosystem Defenses: scored.dev/workshop_infor…
A "critical" vuln score is actually a CVSS score. v4 just came out, and we break it down here: edgebit.io/blog/understan… Super excited about bringing more environmental context to scoring. CVSS has its issues, but this is a step in the correct direction.
Software inventory is still hard. Last week's curl and Rapid Reset vulns were a scramble – unless you have an up-to-date inventory and bill of materials for your apps
A security scanner detects 73 vulnerabilities. If all CVEs correspond to dormant code…how many issues do you have? 0 or 73? We used EdgeBit's tracking of base OS vulnerabilities to reverse engineer the patching practices of EKS & GKE to find out. edgebit.io/blog/base-os-v…
Our CEO @robszumski joined the All Aboard pod to chat about SBOMs, vulnerability management and the latest on government supply chain regulations. Do you think NIST rolled out supply chain standards correctly? Listen in for Rob's take: conductorone.com/podcast/sboms-…
Solving AI dependency sprawl: layers of transitive dependencies make it challenging to understand your risk. EdgeBit prioritization based on real time risk cuts through the noise. Read how: edgebit.io/blog/ai-depend…
OpenVEX is complementary to SBOMs, allowing suppliers to communicate precise metadata about the vulnerability status of products directly to consumers and end users. More on this debate with @robszumski of @EdgebitIO @puerco of @chainguard_dev youtube.com/watch?v=b05kn_…
Introducing EdgeBit Components: a stream of SBOMs enriched with data & tied to running workloads. Instantly ingested from CI/CD Enriched with vuln findings, SLAs & auto resolution Mapped to active workloads Prioritization based on whats running *now* edgebit.io/blog/component…
Just out: National Cybersecurity Strategy Implementation Plan with an entire pillar for SBOM maturity and implementation. Read more: whitehouse.gov/briefing-room/…
New FDA cybersecurity regs are catching folks by surprise. Enforcement starts in October 2023. Learn more about the requirements to submit software bills of materials for Software as a Medical Device (SaMD): edgebit.io/blog/fda-cyber…
Breaking down successful vulnerability management programs: examples from Lyft, Elastic & research from Sysdig and Kenna. What's in common? CONTEXT! It's essential for your engineers. edgebit.io/blog/successfu…
Vulnerability management gone wrong...with huge impact on voting systems in GA. Prioritize what you patch and make time to do it! edgebit.io/solutions/vuln…
Vulnerability management gone wrong...with huge impact on voting systems in GA. Prioritize what you patch and make time to do it! edgebit.io/solutions/vuln…

Jonathan Foote @JFoote2715
4 Followers 899 Following
jeremie @jeremie0
179 Followers 1K Following
JackSun @evilbinary
7 Followers 398 Following
Supply-Assure @SupplyAssure
21 Followers 116 Following Transforming Supply Chain Security into Competitive Advantage #SupplyChainSecurity #SecurityAssurance #Confidence #Trust #Advantage
Ashish Desai @developerhughes
142 Followers 3K Following
Maya @MayaCostantini
113 Followers 337 Following Software Engineer @Microsoft | previously @RedHat • 🐍 Python & Open Source security • Declare variables not war
ketl.xyz - for founde... @ketlxyz
545 Followers 3K Following 🕯️🫖 Exclusive anonymous app for founders & VCs: https://t.co/sPAwZJQ5GG 🔮 Join over 500 YC + venture backed founders and VCs from the top funds today
💜 sumo at hachyder... @SumoOfShinovar
333 Followers 2K Following profiling & eBPF 🐝 things @PolarSignalsIO 🌁 @outreachy'21 & Community Bridge'20 alum at Linux Kernel. 🦀🐪 Rageposting pikka bird. She/her.
Pat Skinner @onpaws
224 Followers 2K Following Builder, learner, tinkerer. I love helping people reach their potential. Really, really tall. Against qualified immunity #FreePalestine 🇵 #BDS
Halyna Y @yhalinka
266 Followers 732 Following
www.CloudMalwareAnaly... @AnalysisGroups
476 Followers 5K Following CloudMalwareAnalysisGroups@CloudMalwareAnalysisGroups.vulnerabilities
Bruce ZHANG @BruceZHANGCCC
345 Followers 2K Following Dedicated in Cybersecurity. Founder of Z-ONE consulting, partner of NovaCyberVentures, seed fund for China Cybersecurity.
CyberSecurityMew @CSMewMew
284 Followers 2K Following CyberSecurityMew, affiliation of Z-ONE consulting, is the leading vertical media for China Cyber Security business news.
Adam Shannon @adamdecaf
501 Followers 739 Following I'm curious about everything. Software and Infra at @moov and open-source. $BTC $TAO - https://t.co/GSnTWS12Ix
Jordi Mon Companys @JordiMonPMM
790 Followers 1K Following Product | Software Delivery, Langtech and Software Supply Chain Security. @openuk_uk 🇬🇧 ambassador
garnet @garnet_labs
92 Followers 278 Following Runtime security monitoring and protection for modern infrastructure.
Ruben M @ruboinc
658 Followers 3K Following Chief Technologist playing with K8S+EKS+GitOps, Space nut, make no little plans // Fmr: KCI-3M : Rockwell : NASA : Red Hat : @BoozAllen
Nadav Z @nadavzing
10 Followers 888 Following
t12345cool @t12345cool
1 Followers 63 Following
Luke Hinds @decodebytes
3K Followers 733 Following No longer active here; find me on: https://t.co/bdAWiJOO1e
French @nfFrenchie
4K Followers 5K Following InfoSec geek for Cloud/Clusters/Containers/things-starting-with-C ex: @BrexHQ & @Cruise. founder @ensignia_dev honk the planet
Giri Sreenivas @giri_sreenivas
2K Followers 2K Following Currently: SVP Product, Klaviyo. Previously: 2x founder (Mobilisafe / Helm), exits (Mobilisafe acq by Rapid7, then an IPO), VP/GM + CPO @ Docker.
Nathan Wallace @nathanwallace
506 Followers 1K Following Founder @turbothq. Building @steampipeio, @flowpipeio, @powerpipeio, @tailpipeio. Father, husband, traveler, nerd, 🍔-lover.
FoodHack @foodhackglobal
2K Followers 4K Following 💡Where the Future of Food starts & scales + Weekly newsletter 📧 + Meetups in 40+ cities 🌍 + Must-attend HackSummit 🤝 + 30 investments in leading Startups🚀
Shreyas Mavanoor @shreyasmav
678 Followers 5K Following 🇺🇸🇮🇳cybersecurity | @GeorgiaTech @sppgatech alum 🐝🎓 | ex-@PwCUS @StanfordUIT | CLT👑ATL🍑SFO🌉BLR🏰 | @_buildspace n&w s5 irl @hackwithtrees
msungwi @Msungwi1
171 Followers 2K Following Conservative, pro innovation, creative mindset, husband,father and entrepreneur.
Duffie Cooley @mauilion
9K Followers 2K Following Field CTO Isovalent at Cisco // Proud CNCF Ambassador // I am committed to seeing others succeed. // @[email protected]
Paweł Krupa @paulfan... @paulfantom
325 Followers 308 Following Observability aficionado drinking too much tea
Tiago Santana @worldwithTiago
192 Followers 2K Following creating worlds. debugging my own existence.
Arve Knudsen @hochgenuss
291 Followers 558 Following Full-stack software developer, based in Lachen, Switzerland. Working at Grafana Labs.
Joe Doss migrated to ... @jdoss
967 Followers 2K Following Software Engineer @smallsteplabs Fedora Linux user. Passionate about enabling others to improve their lives with Free Open Source Software.
Enclaver @EnclaverApp
4K Followers 5K Following An open-world, crazy fun text & 3D life simulator for iOS and Android🔥🤣 Check what’s the all hype is about 😎😱! ↘️Free Download link↘️
Matthew Bates @mattbates25
1K Followers 3K Following Founder/CEO at @cofidesec. Ex-CTO @Venafi, Co-founder/CTO @JetstackHQ (acq.), engineering/product. Interested in distributed systems, cloud and cybersecurity.
@smindusis @smindusis
31 Followers 438 Following
Platform Security Sum... @platformsec
979 Followers 4K Following Conference on composable software supply chain integrity and hardware-assisted platform security, with OpenEmbedded, OpenXT and other ecosystems
cocky @mycocky1610
4 Followers 390 Following
Joe Thompson @caffeinepresent
922 Followers 1K Following GitHub: omkensey k8s Slack: kensey Employment: Terraforming your infrastructure @HashiCorp! (but I don't speak for them here, they have people for that)
hexfusion @hexfusion
503 Followers 516 Following Opinions are my own and not the view of any reasonable person.
Russell Haering @russell_h
653 Followers 1K Following Head of engineering @ConductorOneInc. Clean OPSEC. Let’s ship!