home.social

#devsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #devsec, aggregated by home.social.

fetched live
  1. On May 11, 2026, the Patchstack team notified me about a vulnerability in Embed Privacy version 1.12.3 and lower that allowed a malicious actor to delete any file PHP has access to. Let’s checkout what happened.

    […]

    epiph.yt/en/blog/2026/mitigate #DevSec #ITSec #Patchstack #Plugin #Security #Update #WordPress
  2. Am 11. Mai 2026 benachrichtigte mich das Team von Patchstack über eine Sicherheitslücke in Embed Privacy 1.12.3 und niedriger, die es einem Angreifer ermöglichte, jegliche Datei, auf die PHP Zugriff hatte, zu löschen. Nachfolgend möchte ich darlegend, was dann passierte.

    […]

    epiph.yt/blog/2026/behoben-loe #DevSec #ITSec #Plugin #Ptchstack #Sicherheit #Update #WordPress
  3. Am 11. Mai 2026 benachrichtigte mich das Team von Patchstack über eine Sicherheitslücke in Embed Privacy 1.12.3 und niedriger, die es einem Angreifer ermöglichte, jegliche Datei, auf die PHP Zugriff hatte, zu löschen. Nachfolgend möchte ich darlegend, was dann passierte.

    […]

    epiph.yt/blog/2026/behoben-loe #DevSec #ITSec #Plugin #Ptchstack #Sicherheit #Update #WordPress
  4. VS Code zero-day: one click on a Jupyter notebook steals your GitHub OAuth token — full access to every repo, including private. Researcher dropped the PoC after Microsoft dragged its feet.
    Fixed June 3. Audit CI/CD access now.

    #CyberSecurity #GitHub #DevSec

  5. VS Code zero-day: one click on a Jupyter notebook steals your GitHub OAuth token — full access to every repo, including private. Researcher dropped the PoC after Microsoft dragged its feet.
    Fixed June 3. Audit CI/CD access now.

    #CyberSecurity #GitHub #DevSec

  6. Want to build more secure apps? 💻 Security engineers are shifting left and integrating checks into your CI/CD pipeline. Learn about tools like Trivy, SonarQube, and Dependabot in this quick #shorts! Check it out! #SecurityEngineer #CICD #DevSec

    youtube.com/watch?v=Sqi4_LIo3qU

  7. AI's changing how we build apps, but are they safe? 😬 Developers, are you skipping security steps? This short dives into why expert oversight is key to avoiding vulnerabilities like hard-coded passwords. New video – check it out! #AIsecurity #SoftwareSecurity #DevSec

    youtube.com/watch?v=DcwHnRlZvTQ

  8. LiteLLM supply chain attack: 97M monthly downloads, one malicious update, every secret stolen. The library helps AI apps connect to different models, so when hackers poisoned it, the damage spread to countless dependent projects. This is why we isolate our Python environments. #AISupplyChain #CyberSecurity #PythonSecurity #DevSec #AITools

  9. NEW: Developers, crypto users, and job seekers beware - North Korea’s Lazarus Group is deploying a new #BeaverTail variant to steal credentials and crypto via fake job offers, dev tools and smart contracts.

    Read: hackread.com/lazarus-embed-bea

    #CyberSecurity #Lazarus #NorthKorea #DevSec #InfoStealer

  10. NEW: Developers, crypto users, and job seekers beware - North Korea’s Lazarus Group is deploying a new #BeaverTail variant to steal credentials and crypto via fake job offers, dev tools and smart contracts.

    Read: hackread.com/lazarus-embed-bea

    #CyberSecurity #Lazarus #NorthKorea #DevSec #InfoStealer

  11. Aufgrund einer fehlenden Prüfung auf den Dateityp war es in Form Block möglich, jede Art von Datei hochzuladen, indem man dem Server eine falsche Information über den Dateityp mitgab. Dieses Problem ist mit Form Block 1.5.6 behoben, ein Update wird empfohlen.

    […]

    epiph.yt/blog/2025/beliebiger-

    #DevSec #FormBlock #Plugin #Sicherheit #Update #WordPress

  12. Due to a missing file type check, it was possible to upload files of any type in Form Block, just by telling the server that it is a different type. This has been fixed in Form Block 1.5.6, updating is highly recommended.

    […]

    epiph.yt/en/blog/2025/fixing-a

    #DevSec #FormBlock #Plugin #Security #Update #WordPress

  13. Criei um labzinho de desenvolvimento seguro espefico para uma linguagem e vulnerabilidade que estava pegando aqui com os devs, tem td um passo a passo, quem quiser. #js #appsec #devsec #learn github.com/fguisso/backoffice-

  14. 🚨 Mark your calendars! 🚨

    Join us for the OWASP Global AppSec US Conference in Washington, D.C., November 3–7, 2025 at the Marriott Marquis!

    We're thrilled to announce our keynote speaker: Adam Shostack

    Ready to level up your skills, grow your network, and ignite your passion for security?

    🎟️ Register now and be part of the future of cybersecurity! owasp.glueup.com/event/131624/

    #OWASP #AppSec #Cybersecurity #ThreatModeling #GlobalAppSecUS #SecureCoding #DevSecOps #DevSec #WashingtonDC #Hacking

  15. 🚨 Mark your calendars! 🚨

    Join us for the OWASP Global AppSec US Conference in Washington, D.C., November 3–7, 2025 at the Marriott Marquis!

    We're thrilled to announce our keynote speaker: Adam Shostack

    Ready to level up your skills, grow your network, and ignite your passion for security?

    🎟️ Register now and be part of the future of cybersecurity! owasp.glueup.com/event/131624/

    #OWASP #AppSec #Cybersecurity #ThreatModeling #GlobalAppSecUS #SecureCoding #DevSecOps #DevSec #WashingtonDC #Hacking

  16. Join Liran Tal at OWASP Global AppSec EU 2025 in Barcelona for an eye-opening session on the real security implications of TypeScript!

    🛡️ Friend or Foe? TypeScript Security Fallacies
    📅 Thursday, May 29, 2025
    ⏰ 2:15 PM – 3:00 PM CEST

    🔗 Register: owasp.glueup.com/event/123983/

    With live demos and actionable insights, this talk is a must for anyone building with TypeScript.

    #OWASP #AppSecEU2025 #TypeScriptSecurity #SecureCoding #DevSecOps #AppSec #DevSec #Barcelona

  17. Join Liran Tal at OWASP Global AppSec EU 2025 in Barcelona for an eye-opening session on the real security implications of TypeScript!

    🛡️ Friend or Foe? TypeScript Security Fallacies
    📅 Thursday, May 29, 2025
    ⏰ 2:15 PM – 3:00 PM CEST

    🔗 Register: owasp.glueup.com/event/123983/

    With live demos and actionable insights, this talk is a must for anyone building with TypeScript.

    #OWASP #AppSecEU2025 #TypeScriptSecurity #SecureCoding #DevSecOps #AppSec #DevSec #Barcelona

  18. Join Dag Flachet at OWASP Global AppSec EU 2025 in Barcelona for a powerful session on building better AppSec programs—one small step at a time.

    🔄 Kaizen for Your AppSec Program: Turning Big Problems into Small Steps
    📅 Thursday, May 29, 2025
    ⏰ 3:30 PM – 4:15 PM CEST

    🔗 Register: owasp.glueup.com/event/123983/

    Perfect for AppSec managers and anyone looking to build sustainable, human-centered security practices.

    #OWASP #AppSecEU2025 #DevSec #AppSec #SecureDevelopment #Barcelona

  19. Join Dag Flachet at OWASP Global AppSec EU 2025 in Barcelona for a powerful session on building better AppSec programs—one small step at a time.

    🔄 Kaizen for Your AppSec Program: Turning Big Problems into Small Steps
    📅 Thursday, May 29, 2025
    ⏰ 3:30 PM – 4:15 PM CEST

    🔗 Register: owasp.glueup.com/event/123983/

    Perfect for AppSec managers and anyone looking to build sustainable, human-centered security practices.

    #OWASP #AppSecEU2025 #DevSec #AppSec #SecureDevelopment #Barcelona

  20. @zendis

    #DevSecOps by Zendis, jedenfalls die #DevSec Seite

    Das ist genau der richtige Weg!

  21. @zendis

    #DevSecOps by Zendis, jedenfalls die #DevSec Seite

    Das ist genau der richtige Weg!

  22. At 2 pm our talk "Effective Infrastructure Testing: Lessons Learned from the Field" is taking place at #CfgMgmtCamp B.Con Main: cfp.cfgmgmtcamp.org/ghent2025/

    There is also an online stream available: youtube.com/watch?v=ly8ORuvsqe

    #testinfra #DevSec #automation #CfgMgmtCamp2025

  23. At 2 pm our talk "Effective Infrastructure Testing: Lessons Learned from the Field" is taking place at #CfgMgmtCamp B.Con Main: cfp.cfgmgmtcamp.org/ghent2025/

    There is also an online stream available: youtube.com/watch?v=ly8ORuvsqe

    #testinfra #DevSec #automation #CfgMgmtCamp2025

  24. Today and tomorrow I am attending the heise #devSec conference in cologne. Topics today are for example "how to make your software secure by design", "how to write secure software" and more.
    #heisedevsec

  25. Während ich auf dem Weg zur #INFORMATIK24 bin, darf mein Freund und Kollege @theseer auf der Heise #devsec der „nervigen Kassandra der Security-Branche“ lauschen. #fomo

  26. Während ich auf dem Weg zur #INFORMATIK24 bin, darf mein Freund und Kollege @theseer auf der Heise #devsec der „nervigen Kassandra der Security-Branche“ lauschen. #fomo

  27. 2024 OWASP AppSec Days Singapore - Oct 1 Training

    Our training courses are designed to equip private and public sector infosec professionals, developers, defenders, and advocates to build a more secure web.

    The training courses on day one will be led by Abraham Aranguren, Paul McCarty, and John Dileo.

    Register to attend these training courses and more now by visiting our website ➡️ owaspappsecdayssingapore2.rsvp

    #Singapore #OWASP #AppSec #InfoSec #PenTester #Devsec

  28. 2024 OWASP AppSec Days Singapore - Oct 1 Training

    Our training courses are designed to equip private and public sector infosec professionals, developers, defenders, and advocates to build a more secure web.

    The training courses on day one will be led by Abraham Aranguren, Paul McCarty, and John Dileo.

    Register to attend these training courses and more now by visiting our website ➡️ owaspappsecdayssingapore2.rsvp

    #Singapore #OWASP #AppSec #InfoSec #PenTester #Devsec

  29. 🚨Developers and Security Pros: Join us for OWASP Developer Day in San Francisco on Sep 25!

    Featuring a conference talk by Munawar Hafiz among our full day of developer -focused events.

    See the full schedule and register using the link below!

    eventbrite.com/e/owasp-develop

    #SanFran #Developers #DevSec #Security #AppSec

  30. 🚨Developers and Security Pros: Join us for OWASP Developer Day in San Francisco on Sep 25!

    Featuring a conference talk by Munawar Hafiz among our full day of developer -focused events.

    See the full schedule and register using the link below!

    eventbrite.com/e/owasp-develop

    #SanFran #Developers #DevSec #Security #AppSec

  31. 🚨 REGISTER NOW to attend Global AppSec San Francisco 2024 Conference and Training!

    Join Harold Blankenship and Mat Tesauro for their 2-day training titled, "OWASP in Action - ASPM with OWASP Projects".

    This two-day course streamlines application security posture management using OWASP open source projects optimized for DevSecOps workflows.

    Follow this link to register now!

    eventbrite.com/e/owasp-global-

    #AppSec #SanFran #DevSec #Hacking #Developers

  32. 🚨 REGISTER NOW to attend Global AppSec San Francisco 2024 Conference and Training!

    Join Harold Blankenship and Mat Tesauro for their 2-day training titled, "OWASP in Action - ASPM with OWASP Projects".

    This two-day course streamlines application security posture management using OWASP open source projects optimized for DevSecOps workflows.

    Follow this link to register now!

    eventbrite.com/e/owasp-global-

    #AppSec #SanFran #DevSec #Hacking #Developers

  33. Global AppSec San Francisco 2024 Conference and Training is happening NEXT MONTH

    Join Jim Manico for an intensive 2-day training session delving into core and advanced application security topics.

    This course will cover essential areas such as input validation, HTTP security, SOP and CORS, SQL injections, CSRF, secure file handling, and third-party library management.

    REGISTER👇

    eventbrite.com/e/owasp-global-

    #AppSec #SanFran #DevSec #Hacking #Developers

  34. Global AppSec San Francisco 2024 Conference and Training is happening NEXT MONTH

    Join Jim Manico for an intensive 2-day training session delving into core and advanced application security topics.

    This course will cover essential areas such as input validation, HTTP security, SOP and CORS, SQL injections, CSRF, secure file handling, and third-party library management.

    REGISTER👇

    eventbrite.com/e/owasp-global-

    #AppSec #SanFran #DevSec #Hacking #Developers

  35. Calling all Developers and Security Pros! Join us for OWASP Developer Day in San Francisco on Sep 25!

    Developers: Share your insights and experiences with security.
    Security Experts: Hear directly from developers about what's effective and what needs improvement.

    Don't miss this chance to bridge the gap and enhance app security together!

    REGISTER NOW!

    eventbrite.com/e/owasp-develop

    #SanFran #Developers #DevSec #Security #AppSec

  36. Calling all Developers and Security Pros! Join us for OWASP Developer Day in San Francisco on Sep 25!

    Developers: Share your insights and experiences with security.
    Security Experts: Hear directly from developers about what's effective and what needs improvement.

    Don't miss this chance to bridge the gap and enhance app security together!

    REGISTER NOW!

    eventbrite.com/e/owasp-develop

    #SanFran #Developers #DevSec #Security #AppSec

  37. Have you registered for the Global AppSec San Francisco 2024 Conference and Training Sessions?

    Join Fabio Cerullo for beginner friendly training session, "Web Application Security Essentials".

    Learn more and register by following the link below 👇

    eventbrite.com/e/owasp-global-

    #AppSec #SanFran #DevSec #Hacking #Developers

  38. Have you registered for the Global AppSec San Francisco 2024 Conference and Training Sessions?

    Join Fabio Cerullo for beginner friendly training session, "Web Application Security Essentials".

    Learn more and register by following the link below 👇

    eventbrite.com/e/owasp-global-

    #AppSec #SanFran #DevSec #Hacking #Developers

  39. Data sanitization in preview environments: A critical practice for modern DevOps

    💡 Key points:
    - Protects sensitive data while maintaining realistic testing
    - Techniques: anonymization, pseudonymization, masking, scrambling
    - Implement via CI/CD pipeline for efficiency

    💪 Benefits: enhanced security, compliance, reduced breach risk

    🎯 Developers: This approach ensures you work with representative data without compromising security.

    Read more: brnw.ch/21wL7vf

    #devops #devsec #data

  40. 🔒 Unlocking DevSecOps secrets: Logging isn't just a record, it's your digital guardian! Learn why every developer needs to embrace logging for tighter security.
    withstandsecurity.com/blog-ins

    #DevSec #Logging #CyberSecurity

  41. Ich bin ja gerade auf der #heise #devSec in Hannover. Der gestrige Tag widmete sich komplett Sicherheitsaspekten in der Software Supply Chain. Ich nehme viele Gedanken und Vorsätze mit nach Hause. Hier ein ungeordneter Dump.

  42. Ich bin ja gerade auf der #heise #devSec in Hannover. Der gestrige Tag widmete sich komplett Sicherheitsaspekten in der Software Supply Chain. Ich nehme viele Gedanken und Vorsätze mit nach Hause. Hier ein ungeordneter Dump.

  43. @heisec der erste Talk von @ci war schon Mal Recht nett. Leider wenig neues für mich dabei, mein Kollege hat aber durchaus was mitnehmen können und war ein guter Einstieg ins Thema. 😎 #devSec

  44. Dann gucken wir doch Mal was die @heisec #devSec so kann. 😎

  45. Hey all you #AppSec types out there, I'll be presenting at #Optiv #SourceZeroCon tomorrow at 11 AM Eastern. It's online and free. My talk is titled "Developers Gone Wild!" and is about some of the stranger things I've seen in #security testing applications. Details at the link: go.optiv.com/2023SourceZeroCon #DevSec #ApplicationTesting #SZC2023 #SourceZeroCon2023