#developersecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #developersecurity, aggregated by home.social.
-
#HandsOnWorkshop
Adversary Village at @defcon 34!
Michael Chan from @kpmg Canada takes the Adversary Village Workshop Stage with “Vibe Check: How Adversaries Exploit Developer Trust from Malicious Repos to AI Agents” on 8 Aug 2026.
Adversary Village schedule:
https://adversaryvillage.org/adversary-events/DEFCON-34/
More info on the session: https://adversaryvillage.org/adversary-events/DEFCON-34/Michael-Chan/
#AdversaryVillage #DEFCON34
#AdversaryTactics #HandsOnWorkshop #AISecurity #AdversaryTactics
#SupplyChainSecurity #DeveloperSecurity #OffensiveTradecraft -
#HandsOnWorkshop
Adversary Village at @defcon 34!
Michael Chan from @kpmg Canada takes the Adversary Village Workshop Stage with “Vibe Check: How Adversaries Exploit Developer Trust from Malicious Repos to AI Agents” on 8 Aug 2026.
Adversary Village schedule:
https://adversaryvillage.org/adversary-events/DEFCON-34/
More info on the session: https://adversaryvillage.org/adversary-events/DEFCON-34/Michael-Chan/
#AdversaryVillage #DEFCON34
#AdversaryTactics #HandsOnWorkshop #AISecurity #AdversaryTactics
#SupplyChainSecurity #DeveloperSecurity #OffensiveTradecraft -
https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
#CyberSecurity #InfoSec #SupplyChainSecurity #SoftwareSupplyChain #NPM #OpenSourceSecurity #AppSec #DevSecOps #ThreatIntel #Malware #JavaScript #NodeJS #CICD #GitHubActions #CloudSecurity #TypeScript #ReactJS #WebDev #OpenSource #DevTools #SoftwareEngineering #DeveloperSecurity #SecureCoding #GitHub #SupplyChainAttack #Programming #TechNews #DevOps #ApplicationSecurity #ThreatResearch #SecurityEngineering #CyberAttack #Hackers #MalwareAlert #SecurityResearch #DevCommunity -
https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
#CyberSecurity #InfoSec #SupplyChainSecurity #SoftwareSupplyChain #NPM #OpenSourceSecurity #AppSec #DevSecOps #ThreatIntel #Malware #JavaScript #NodeJS #CICD #GitHubActions #CloudSecurity #TypeScript #ReactJS #WebDev #OpenSource #DevTools #SoftwareEngineering #DeveloperSecurity #SecureCoding #GitHub #SupplyChainAttack #Programming #TechNews #DevOps #ApplicationSecurity #ThreatResearch #SecurityEngineering #CyberAttack #Hackers #MalwareAlert #SecurityResearch #DevCommunity -
OpenAI warns macOS users to update ChatGPT and Codex apps after Axios supply chain scare
https://fed.brid.gy/r/https://nerds.xyz/2026/04/openai-macos-app-update-axios/
-
OpenAI warns macOS users to update ChatGPT and Codex apps after Axios supply chain scare
https://web.brid.gy/r/https://nerds.xyz/2026/04/openai-macos-app-update-axios/
-
A trusted Solidity extension turned traitor – the SleepyDuck Trojan used blockchain to stealthily control developers’ tools. Could your favorite extension be hiding a dark secret?
#sleepyduck
#soliditysecurity
#openvsx
#blockchainmalware
#vscodeextension
#cyberthreats
#malwareanalysis
#developersecurity
#infosec -
A trusted Solidity extension turned traitor – the SleepyDuck Trojan used blockchain to stealthily control developers’ tools. Could your favorite extension be hiding a dark secret?
#sleepyduck
#soliditysecurity
#openvsx
#blockchainmalware
#vscodeextension
#cyberthreats
#malwareanalysis
#developersecurity
#infosec -
Anil Bhasin from Wiz told TechNadu, “Rather than asking developers to decode generic alerts, the focus should be on delivering clear, contextual findings.”
He explains how developer-first security empowers innovation through automation, collaboration, and shared ownership. https://www.technadu.com/the-security-dilemma-creating-a-supportive-security-ecosystem-that-enables-speed-and-developer-empowerment/611717/#CyberSecurity #DevSecOps #AppSec #Wiz #DeveloperSecurity #TechNadu
-
The DevOps space is under siege.
GlassWorm, a self-propagating worm in VS Code extensions, uses Solana blockchain for C2, invisible Unicode for stealth, and targets developer credentials, crypto wallets, and Git repositories. Auto-updating extensions make the threat persistent.
💬 InfoSec pros: how should organizations defend against this evolving supply chain risk?
🔁 Share & follow TechNadu for expert analysis on emerging malware and blockchain-enabled attacks.#GlassWorm #VSCode #SupplyChainAttack #DevSecOps #BlockchainSecurity #Malware #InfoSec #DeveloperSecurity #CyberThreats #TechNews
-
The DevOps space is under siege.
GlassWorm, a self-propagating worm in VS Code extensions, uses Solana blockchain for C2, invisible Unicode for stealth, and targets developer credentials, crypto wallets, and Git repositories. Auto-updating extensions make the threat persistent.
💬 InfoSec pros: how should organizations defend against this evolving supply chain risk?
🔁 Share & follow TechNadu for expert analysis on emerging malware and blockchain-enabled attacks.#GlassWorm #VSCode #SupplyChainAttack #DevSecOps #BlockchainSecurity #Malware #InfoSec #DeveloperSecurity #CyberThreats #TechNews
-
Critical Figma MCP Server Flaw Allows Remote Code Execution https://dailydarkweb.net/critical-figma-mcp-server-flaw-allows-remote-code-execution/ #RemoteCodeExecution #DeveloperSecurity #commandinjection #Vulnerability #CyberSecurity #vulnerability #CVE202553967 #Figma #patch #MCP #RCE
-
Critical Figma MCP Server Flaw Allows Remote Code Execution https://dailydarkweb.net/critical-figma-mcp-server-flaw-allows-remote-code-execution/ #RemoteCodeExecution #DeveloperSecurity #commandinjection #Vulnerability #CyberSecurity #vulnerability #CVE202553967 #Figma #patch #MCP #RCE
-
WhiteCobra threat group targets developers with malicious VSCode extensions, stealing cryptocurrency from wallets. They've already stolen $500K+ and can generate fake credibility with 50K fake downloads in hours. Even experienced security professionals have fallen victim to these sophisticated attacks. #CyberSecurity #DevSecurity #VSCode #Malware #CryptoCurrency #DeveloperSecurity #WhiteCobra https://devops.com/whitecobra-targets-developers-with-dozens-of-malicious-extensions/
-
WhiteCobra threat group targets developers with malicious VSCode extensions, stealing cryptocurrency from wallets. They've already stolen $500K+ and can generate fake credibility with 50K fake downloads in hours. Even experienced security professionals have fallen victim to these sophisticated attacks. #CyberSecurity #DevSecurity #VSCode #Malware #CryptoCurrency #DeveloperSecurity #WhiteCobra https://devops.com/whitecobra-targets-developers-with-dozens-of-malicious-extensions/
-
DNS attacks are not just legacy threats – they’re evolving.
In my new article series, I explore modern DNS attack vectors like cache poisoning, tunneling, hijacking & spoofing – and how we as developers can defend at the protocol edge.
A must-read if you're building Java-based backend systems or securing internal services.
🔗 https://svenruppert.com/2025/04/07/dns-attacks-explained/
#CyberSecurity #DNS #Java #Infosec #NetworkSecurity #SecureCoding #DNSAttack #DeveloperSecurity #PrivacyByDesign
-
DNS attacks are not just legacy threats – they’re evolving.
In my new article series, I explore modern DNS attack vectors like cache poisoning, tunneling, hijacking & spoofing – and how we as developers can defend at the protocol edge.
A must-read if you're building Java-based backend systems or securing internal services.
🔗 https://svenruppert.com/2025/04/07/dns-attacks-explained/
#CyberSecurity #DNS #Java #Infosec #NetworkSecurity #SecureCoding #DNSAttack #DeveloperSecurity #PrivacyByDesign
-
GitHub detected 39 million exposed secrets in 2024! Learn how their major security upgrade protects your code with AI-powered scanning, free risk assessment, and enhanced push protection. Don't let your API keys become the next compromise.
#SecurityLand #BusinessShield #CyberSecurity #GitHub #DeveloperSecurity
Read More: https://www.security.land/github-bolsters-security-after-39-million-secret-leaks-in-2024/
-
My new blog post addresses my issues with the concept of "shift left security." It's not wrong, it's just misunderstood.
Shifting left is about empowering developers to better secure their applications, freeing up security teams to scale to better support them. Security teams need to work with development throughout the SDLC to drive efficiency for remediation - helping both teams.
#devsecops #cloudsecurity #infosec #developersecurity #cnapp #applicationsecurity #appsec
-
My new blog post addresses my issues with the concept of "shift left security." It's not wrong, it's just misunderstood.
Shifting left is about empowering developers to better secure their applications, freeing up security teams to scale to better support them. Security teams need to work with development throughout the SDLC to drive efficiency for remediation - helping both teams.
#devsecops #cloudsecurity #infosec #developersecurity #cnapp #applicationsecurity #appsec
-
New #infographic on developer-focused security based on my latest research: Walking the Line: GitOps and Shift Left Security https://www.esg-global.com/research/infographic-walking-the-line-gitops-and-shift-left-security
#devsecops #infosec #cybersecurity #cloudsecurity #developersecurity #shiftleft #CloudSecurityOperations -
My thoughts on the Palo Alto Networks acquisition of Cider security to help security teams incorporate developer-focused security in Prisma Cloud by Palo Alto Networks. This includes some stats from my latest Enterprise Strategy Group report.
https://venturebeat.com/security/palo-alto-networks-acquires-supply-chain-security-provider-harden-application-security/