-
Tweets140
-
Followers41
-
Following77
-
Likes57
One runtime security advantage. Six major frameworks. DORA. PCI DSS 4.0.1. SOC 2. ISO 27001. NIST SP 800-53. FedRAMP. Next-generation runtime security helps teams see what’s actually executing, block covered exploit behavior, and retain evidence that the control operated. So when the patch is weeks away, you have a stronger answer to: “What protects the application today?” Protect sooner. Prove it operated. Patch when ready. Read the full blog: na2.hubs.ly/H07L1Rw0 #RuntimeSecurity #ApplicationSecurity #Cybersecurity #Compliance
Family 10 of the Raven Power List: Parsing, Decoding & Deserialization — "The Customs Officer." It opens every package that arrives. Parsers and deserializers process untrusted input before anything else validates it — the very first thing an attacker can reach. That's why insecure deserialization, XXE and RCE keep this family busy. The Customs Officer's risk lives at runtime: what it was handed, and what it turned that input into. Among the 14 most powerful families in software, this one checks the incoming crates. Download the research: na2.hubs.ly/H07KQbD0 #Deserialization #ApplicationSecurity #Cybersecurity #OpenSourceSecurity
What if AI finds the next critical software vulnerability before it has a CVE, advisory, or patch? Join Raven on October 8 for Before the CVE: The 14 Software Libraries AI Will Target First, featuring @ , @ Omer Yair and @ James Berthoty. They’ll explore: • Why focusing only on known CVEs leaves a critical gap • How dangerous components become difficult to see once an application is running • What cases like Log4j2 reveal about traditional defenses • How runtime attribution connects suspicious behavior to the exact library, function, input, and call chain responsible Save your spot: na2.hubs.ly/H07HRfW0 #Cybersecurity #ApplicationSecurity #OpenSourceSecurity
See the research: raven.io/the-14-most-po…
Family 09 of the Raven Power List: Code, Template & Expression Evaluation — "The Ventriloquist." It turns words into deeds. eval, template engines and expression evaluators execute text with access to your application context. Whoever influences that text influences what the app does — which is why code injection, SSTI and RCE concentrate here. The Ventriloquist can be fully patched and still speak an attacker's words at runtime. The question is never the CVE — it's the input. 14 families run modern software. This one puts words in its mouth. Download the research 👇 #SSTI #ApplicationSecurity #Cybersecurity #OpenSourceSecurity
Get your copy here: raven.io/the-14-most-po…
Family 08 of the Raven Power List: Dynamic Modules with Native Code — "The Smuggler." It crosses into unmanaged territory. Modules that bridge managed code into native libraries leave the safety of the runtime behind. Past that border live memory corruption, RCE and sandbox escape — the heavy, low-level outcomes. You won't spot the Smuggler's crossing in a package manifest. You see it at runtime, when managed code hands data to native memory. One of 14 families in our new research on library power. Download the research 👇 #MemorySafety #ApplicationSecurity #Cybersecurity #OpenSourceSecurity
What can EDR see when an attack moves inside a server application and what context is missing? In this clip, Raven Co-Founder and Chief Research Officer Omer Yair explains why application-level visibility matters when investigating an attack. Watch the full on-demand webinar to see a live attack and compare what EDR detects with what ADR reveals, down to the responsible library, function, and call chain. Watch on demand: na2.hubs.ly/H07Bb2N0
Download the research here: raven.io/the-14-most-po…
Family 07 of the Raven Power List: OS-Command & Remote-Shell Execution — "The Enforcer." It makes things happen with muscle. Libraries that spawn processes or run shell commands turn a string into an action on the host. It's the shortest path from input to command injection, RCE and a reverse shell. The Enforcer doesn't need a vulnerability to be dangerous — it needs untrusted input reaching the wrong call. That's a runtime question, not a CVE one. Among the 14 most powerful families in software, this is the one with hands. Download the research 👇 #RCE #ApplicationSecurity #Cybersecurity #OpenSourceSecurity
Download the power list: raven.io/the-14-most-po…
Family 06 of the Raven Power List: Cryptocurrency, Blockchain & Web3 Clients / SDKs — "The Money Mover." Irreversible transfers, signed quietly. Wallet SDKs and chain clients handle keys and sign transactions that can't be undone. The stakes are absolute — which is why key theft, fund drains and supply-chain attacks target this family hardest. The Money Mover's risk isn't in a CVE feed. It's in what gets signed at runtime, with which key, on whose instruction. 14 families, one research report. This one moves the money. Download the research 👇 #Web3Security #Blockchain #Cybersecurity #OpenSourceSecurity
A new Log4j RCE technique is making noise. No CVE. No signature. Yes, AI found it. We reproduced it in our lab. Raven prevented the exploit at runtime with no prior knowledge. 😎 Read our findings: na2.hubs.ly/H07thtL0
We are entering a CVE-less world. Attackers are using AI to find and weaponize weaknesses before they have a CVE, signature, patch, or detection rule. If your defenses depend on knowing the vulnerability first, you are already behind. Security teams need a way to recognize and stop malicious execution at runtime, whether a CVE exists or not. Watch the clip, then catch the full ADR vs. EDR webinar on demand: na2.hubs.ly/H07q57s0 #RuntimeSecurity #ApplicationSecurity #ZeroDay #ADR #Cybersecurity #AI
Family 05 of the Raven Power List: Network Egress & Client Transport — "The Courier." It carries anything, anywhere — credentials in hand. HTTP clients, URL fetchers and resolvers can originate connections from your server's trusted position, to places an outside attacker could never reach directly. That's why SSRF, data leaks and DoS trace back to this family. A patched, CVE-clean client can still hand an attacker control over the destination. Only runtime tells you where the Courier actually went. One of 14 families in our new research. Download the research: na2.hubs.ly/H07p3zM0
Security spent years getting very good at stopping postinstall attacks. Attackers moved on. More than 700 malicious npm packages skipped install hooks entirely. The malware executed when developers followed one ordinary README instruction: require() the library. The name can lie. The signature can change. The behavior cannot. Read: Postinstall Was the Labubu → na2.hubs.ly/H07d59x0
🆕 New research you won’t find anywhere else: The 14 Most Powerful Families in Software. After analyzing millions of open-source libraries, we identified 14 families with the most influence on modern applications and their risk. The research looks beyond known CVEs to evaluate what software is capable of doing at runtime. The link is in the comments.
Last chance to register: EDR vs. ADR with a live attack demo 🥷 Watch the same attack through two very different lenses and see where EDR visibility stops and how ADR traces suspicious behavior to the responsible library, function, and call chain. Join Raven’s Roi Abitboul and Omer Yair with Futurum's Fernando Montenegro. 📅 August 19 at 11:00 a.m. ET Save your spot: na2.hubs.ly/H07cVxm0
Get the research here: raven.io/the-14-most-po…
Family 03 of the Raven Power List: Database & Data-Store / Query Tier — "The Bookkeeper." It holds the ledgers. Every query builder, ORM and data-store client sits between your application and the data an attacker actually wants. That's its legitimate business — and why SQL injection, data exfiltration and tampering live here. You can't see the Bookkeeper's risk in a dependency list. You see it at runtime: which query ran, built from whose input, touching which records. We mapped 14 families with the most sensitive behavior in software. The Bookkeeper is one. Download the research 👇 #DataSecurity #ApplicationSecurity #Cybersecurity #OpenSourceSecurity
Andrew @4ndr3w6S
3K Followers 3K Following Detection Engineering @HuntressLabs | Prev. Practice Lead, TAC (Purple Team) @TrustedSec | @SpursOfficial Super Fan - COYS!
Boaz Babai @IsraelTechNews
27K Followers 18K Following Brand awareness and business impact for Israeli #B2B companies with innovative products and services.
Pierre | fresh market... @aipierrepierre
444 Followers 260 Following Get all the market signals delivered to your inbox👇
Unusual Ventures @Unusual_VC
7K Followers 937 Following The product-market fit partner for technical enterprise founders.
Justin Elze @HackingLZ
72K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
CaV @cybercharlesav
24 Followers 2K Following
Lil Bindle @YungBindlestiff
111 Followers 6K Following
isiah.gu @isiah_gu
8 Followers 716 Following
jIeZHaNG @nanothyll
627 Followers 2K Following Security researcher and a boy's father. Opinions are all yours!
Lemon @Lemon2023888588
31 Followers 4K Following
assaf r.l @ArelAssaf
3 Followers 70 Following
Rohit @r007hitwastaken
8 Followers 87 Following
Mohammad Almusilhi @DaRealMushi
0 Followers 3K Following
Fleighez @FleighezSupA
56 Followers 4K Following
Jaka Hudoklin @offlinehacker
3K Followers 613 Following Dev+Ops, web, security, cryptocurrencies. Loves @nixpkgs, K8S, Docker. F(X), deterministic and fully declarative. Also js, go, good food & latte macchiato
Katherine Rosiitas @KRosiitas37178
0 Followers 4 Following
shani goldberg @shanigoldberg3
2 Followers 47 Following
Anuj Bhartiya @anuj7784
6 Followers 52 Following
Daniel Pacak @d_pacak
351 Followers 1K Following Threat Hunting, Threat Detection and Response, ADR, CDR, EDR, Kubernetes, Linux Containers and eBPF
Rafael David Tinoco @rafaeldtinoco
689 Followers 603 Following Security R&D at Miggo | eBPF, Tracing, OS | Jibril Runtime Creator | Former Tracee Runtime Security Maintainer, Ubuntu Core Dev and Mainframer.
Roy Cagan @roycagan
24 Followers 183 Following
Tough @Tough_wyt8v_
62 Followers 7K Following
Jaromir Hamala @jerrinot
2K Followers 2K Following I play with distributed systems by day and poke various runtimes by night. Engineer @QuestDB, @Hazelcast alumnus.
Greatness @gre8tness
1K Followers 4K Following Senior SRE Building AI native healthcare system: Dokitab
Inverted Triangle @invrtd_triangle
29 Followers 673 Following
Dejan Lukan @dejanlukan
120 Followers 119 Following
Lori Vardi @lorivardi
4 Followers 33 Following
💛💙либиди�... @boar_from_haifa
58 Followers 339 Following
Danny Hadar @dannyhadar
657 Followers 742 Following Seed VC backing Israeli founders worldwide. AI-native · cyber · healthcare. Co-founder @ Jibe Ventures
🤖 Alexander Haase @herrhaase
927 Followers 4K Following Design for a world with safe AI – @apolloaievals, @bluedotimpact, @epochairesearch, @horizonIPS.
Guy Franco @guy_franc
8 Followers 214 Following
Omer Yair 🟣 @yair_omer
857 Followers 915 Following Chief Research Officer at https://t.co/mfyQcbuLW0 | Previously: Javelin Networks (acquired by Symantec), Trusteer (IBM) | Photographer | Strives to be a better ally | he/him
Roi Abutbul @RoiAbutbul
313 Followers 946 Following Co-founder and CEO @ravencloudinc | Former Co-founder & CEO @JavelinNetworks (acquired by Symantec)
Mark E. Dawson, Jr. @medawsonjr
3K Followers 219 Following CEO of JabPerf, Contributing Author to "Performance Analysis & Tuning on Modern CPUs" (1st & 2nd Edition available on Amazon), Blogger, and Former Amateur Boxer
Mistral AI @MistralAI
207K Followers 2 Following Frontier AI in your hands. Get work done with @MistralVibe at https://t.co/JsGnCVMUFq.
Shuly Galili @shulygalili
5K Followers 2K Following Founding Partner @UpWestVC. First Investor @SentinelOne @stampli @Zenitysec @HoneyBook Making things happen at Silicon Valley/TelAviv tech junction.
latio @latiotech
67 Followers 3 Following
Lineaje @Lineaje_Inc
85 Followers 48 Following Lineage solves critical software supply chain security problems faced by every organization that builds or sells software.
Javed Hassan @javedhassan
78K Followers 345 Following Fmr Chair NAVTTC; Fmr Senior Visiting Fellow Fudan University; London Business School & Imperial College Alum; https://t.co/waMzMi71nt
Cloud Security Podcas... @CloudSecPod
4K Followers 1 Following Award Winning Top 10 Ranked CyberSecurity Podcast in US,UK and Aus. Learn Cloud Security in Public Cloud the unbiased way from CyberSecurity Host: @hashishrajan
Chris Hughes @ResilientCyber
482 Followers 203 Following Securing AI @ Noma | Founder @ Resilient Cyber | 3x Author | Veteran | Advisor
Palo Alto Networks @PaloAltoNtwks
130K Followers 480 Following Our Mission: Cybersecurity partner of choice, protecting our digital way of life.
SentinelOne @SentinelOne
58K Followers 1K Following ONE autonomous platform to prevent, detect, respond, and hunt. Do more, save time, secure your enterprise: https://t.co/N75g1HAnCs 🐱💻
CrowdStrike @CrowdStrike
112K Followers 790 Following The first cloud-native platform that protects endpoints and cloud workloads, identity & data. #WeStopBreaches. Free trial: https://t.co/msBcUPjFKo
Kondah Mouad @deepkondah
5 Followers 1 Following
James Berthoty @JamesBerthoty
1K Followers 418 Following Security Engineer Turned Industry Analyst @latiotech
Cyburger @Cyburgerim
4K Followers 370 Following Cyber. M&A. Investments. Trends. Product. Nonsense. English RTs @Cyburgerzz
Abhinav Upadhyay @abhi9u
19K Followers 2K Following NetBSD Dev | Python Internals, AI, compilers, databases, & performance engineering | Join 16k+ other readers at https://t.co/OQfxW0443i
Google Site Reliabili... @googlesre
16K Followers 8 Following ⌨️🛠️📊 #SRE resources from the @Google Site Reliability Engineering team.
OpenTelemetry @opentelemetry
18K Followers 31 Following OpenTelemetry makes robust, portable telemetry a built-in feature of cloud-native software. NOTE - This account is no longer monitored.
Datadog, Inc. @datadoghq
51K Followers 65 Following Datadog is the monitoring and security platform for cloud applications
Dynatrace @Dynatrace
19K Followers 2K Following Dynatrace is the leading AI-powered observability platform that enables you to transform complexity into your greatest asset and drive your business forward.
Splunk AppDynamics @AppDynamics
21K Followers 2K Following We’ve moved! Follow @splunk for updates about the Splunk Observability portfolio, now supercharged by Splunk AppDynamics (formerly Cisco AppDynamics).
Grafana @grafana
73K Followers 165 Following ☁️ Open observability cloud ☁️ Join the Grafana community 👇
johnnysswlab.com @johnnysswlab
2K Followers 29 Following We help development teams speed up their C/C++ software. Performance-related blog: https://t.co/FqGMpbEH2w Direct help: https://t.co/3Dn3HMlgqM
Danny Hadar @dannyhadar
657 Followers 742 Following Seed VC backing Israeli founders worldwide. AI-native · cyber · healthcare. Co-founder @ Jibe Ventures
Omer Yair 🟣 @yair_omer
857 Followers 915 Following Chief Research Officer at https://t.co/mfyQcbuLW0 | Previously: Javelin Networks (acquired by Symantec), Trusteer (IBM) | Photographer | Strives to be a better ally | he/him
PrometheusMonitoring @PrometheusIO
52K Followers 87 Following An open-source service monitoring system and time series database.
Firedancer 🔥💃�... @jump_firedancer
36K Followers 11 Following A new independent validator client for the @solana blockchain, built by @jump_.
Helm @HelmPack
38K Followers 215 Following the package manager for @kubernetesio // a @CloudNativeFdn graduated project // check out Helm V3 now
argoproj @argoproj
22K Followers 26 Following Argo is the premier open source GitOps and MLOps CNCF project
Kubernetes @kubernetesio
326K Followers 86 Following #Kubernetes: open source production-grade container orchestration management. #CNCF #K8s
CNCF @CloudNativeFdn
113K Followers 769 Following CNCF is the home of @kubernetesio, @prometheusio, @envoyproxy, and many more. Join us at #KubeCon November 9-12 in Salt Lake City!
Kubecon_ @KubeCon_
44K Followers 66 Following The #Kubernetes & @CloudNativeFdn community conference. Join us at https://t.co/I1qXBvTytY #KubeCon + #CloudNativeCon
Matt @matt_dz
6K Followers 3K Following C++, Compilers, Computer Architecture, Generic Programming, GPGPU, HPC, Machine Learning, Numerics, Parallel Computing, Quantitative Finance
Craig Topper @aurigas81
164 Followers 223 Following LLVM developer. Compiler engineer at SiFive. Opinions are my own.
Chronicle Software @Chronicle_SW
458 Followers 135 Following Founded in 2013 by Java Champion Peter Lawrey, Chronicle is on a mission to revolutionise financial technology through proven practices and collaboration.
Parca @ParcaDev
902 Followers 9 Following Open-source continuous profiling of CPU. Save cost & improve performance! #opensoure #eBPF #kubernetes Originally created by @PolarSignalsIO.
Rafael David Tinoco @rafaeldtinoco
689 Followers 603 Following Security R&D at Miggo | eBPF, Tracing, OS | Jibril Runtime Creator | Former Tracee Runtime Security Maintainer, Ubuntu Core Dev and Mainframer.
DHH @dhh
878K Followers 413 Following Father of three, Creator of Ruby on Rails + Omarchy, Co-owner & CTO of 37signals, Shopify director, NYT best-selling author, and Le Mans 24h class-winner.
Reuven M. Lerner @reuvenmlerner
26K Followers 1K Following Boosting Python confidence since 1995. https://t.co/pQi0LDnNuA • Python tips: https://t.co/cJD1MrLB6L • YouTube: https://t.co/hgoyNrE2m8
Selçuk Korkmaz @selcukorkmaz
18K Followers 280 Following Passionate about data | Building tools to simplify complex problems | Founder of https://t.co/2dhtzQzC3u
Brandon Falk @gamozolabs
22K Followers 278 Following I find and exploit 0day, develop OSes, hypervisors and emulators, design massively parallel data structures and code, and do precision machining! Optimization❤️
Rico Mariani @ricomariani
2K Followers 105 Following I'm a software engineer, I specialize in software performance engineering and programming tools generally. These days I work on MS Defender.
Nadav Rotem @nadavrot
4K Followers 417 Following Engineering director at Facebook. Interested in systems, compilers, ML, performance, and other stuff. 🇮🇱
Peter Veentjer @PeterVeentjer
2K Followers 196 Following Performance engineer @ Adapative, ex-Scylla, ex-Hazelcast.












