#devsecops — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #devsecops, aggregated by home.social.
-
Security Tip: Visibility is the foundation of dependency management. 🛡️ A Software Bill of Materials (SBOM) is no longer optional. It provides a formal record of the supply chain relationships between components. In the event of a zero-day vulnerability, an SBOM allows your security team to quickly identify affected systems without manual code audits. Start tracking vulnerabilities today: https://cvedatabase.com #InfoSec #CyberSecurity #SBOM #DevSecOps #CVE
-
Уязвим не nginx, а две строки вашего конфига. Разбираю CVE-2026-42945 на живом стенде
Критическая дыра в nginx: 9.2 по CVSS, восемнадцать лет в коде, нашёл её ИИ-агент за шесть часов. В новостях к этому прилагают 5.7 миллиона уязвимых серверов, а сканы реальных конфигов находят ноль из 1465 и один из 35633. Поднял стенд, чтобы понять, кто прав. Заодно выяснилось, что граница проходит не там, где её рисуют: трейлинговый знак вопроса безопасен, промежуточный rewrite гасит флаг, а именованный захват спасает не всегда.
-
Are you catching vulnerabilities early enough? 🔍 Integrating automated dependency scanning into your CI/CD workflow is essential for modern software supply chain security. Learn how to use tools like Trivy to identify and fix CVEs before production. Read the full tutorial: https://cvedatabase.com/blog/shift-left-security-automating-dependency-scanning-in-your-ci-cd-pipeline-2026-08-11 #DevSecOps #SupplyChainSecurity #SCA #Automation #InfoSec
-
Security Tip: Don’t ignore transitive dependencies. 🛡️ Modern apps rely on hundreds of third-party libraries. While you might track your direct imports, vulnerabilities often lurk in the dependencies of dependencies. Manual tracking is impossible. Use Software Composition Analysis (SCA) tools to map your full dependency tree and alert on known CVEs. Stay informed on the latest vulnerabilities: https://cvedatabase.com #CVE #InfoSec #CyberSecurity #AppSec #DevSecOps
-
I wanted to see what a secure build-time Java patch looks like after the annotation.
The example uses a fictional access-policy SDK. Quarkus Shim replaces one method during the build. The pipeline proves the old and new behavior, keeps the dependency in the SBOM, stores the bytecode dump, and rejects an expired patch.
https://www.the-main-thread.com/p/quarkus-shim-secure-java-pipeline
-
I wanted to see what a secure build-time Java patch looks like after the annotation.
The example uses a fictional access-policy SDK. Quarkus Shim replaces one method during the build. The pipeline proves the old and new behavior, keeps the dependency in the SBOM, stores the bytecode dump, and rejects an expired patch.
https://www.the-main-thread.com/p/quarkus-shim-secure-java-pipeline
-
We have updated https://www.valtersit.com/methodology/ with the actual information #CVE #Dokploy #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta
-
We have updated https://www.valtersit.com/methodology/ with the actual information #CVE #Dokploy #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta
-
Your CI/CD pipeline is only as secure as the random code you copied from the Marketplace. Supply chain attacks are thriving on GitHub Actions. Here's how to lock it down. #DevSecOps #GitHubActions #Security
https://www.valtersit.com/guides/gitlab/github-actions-your-pipeline-is-only-as-secure as-the-random-code-you-copied/
-
Securing your software supply chain shouldn't be manual work. 🤖 Our latest tutorial dives deep into automating dependency scanning within your CI/CD pipelines to block vulnerabilities like CVE-2021-44228. Elevate your DevSecOps game today! https://cvedatabase.com/blog/automating-dependency-scanning-a-practical-guide-to-securing-your-ci-cd-pipeline-2026-08-10 #SCA #DevSecOps #CICD #InfoSec #CyberSecurity #Automation
-
MLOps для DevOps-инженера: как построить платформу машинного обучения в закрытом контуре
Мы построим прототип MLOps-платформы с нуля. Без Kubeflow, без облаков, без магии. Только Kubernetes, Helm, ArgoCD и ещё дюжина компонентов, каждый из которых появляется не потому что «так модно», а потому что решает конкретную проблему
-
Security Tip: Move to automated secrets rotation. 🛡️
Static credentials are a major liability. If an API key is leaked, it stays valid until someone remembers to change it. Automated rotation (using tools like HashiCorp Vault or AWS Secrets Manager) reduces the "blast radius" of a leak by ensuring credentials expire and rotate without manual intervention.
Monitor the latest threats and vulnerabilities at https://cvedatabase.com
-
OpenAI’s Daybreak programme separates routine defensive AI access from advanced cyber research access. https://www.developer-tech.com/news/openai-daybreak-gpt-5-6-cyber-for-defensive-security-work/ #openai #cybersecurity #devsecops #infosec #tech
-
OpenAI’s Daybreak programme separates routine defensive AI access from advanced cyber research access. https://www.developer-tech.com/news/openai-daybreak-gpt-5-6-cyber-for-defensive-security-work/ #openai #cybersecurity #devsecops #infosec #tech
-
It's time for another toot in our #peoplebehindosco series.
Hi @lisihocke 👋
Lisi found tech as her place to be in 2009 and has grown as a specialized generalist ever since. Building great products that deliver value together with great people motivates her and lets her thrive. As a security engineer, she’s now fully focusing on all things product security to help build more secure solutions. She’s committed to testing and quality, passionate about whole-team approaches to increase effectiveness and resilience, and enjoys experimenting and learning continuously. Having received a lot from communities, Lisi is paying it forward by sharing her stories and learning in public.
Her tags: #ProdSec, #AppSec, #DevSecOps, #SecureCoding, #SecurityTesting
She posts on Mastodon as @lisihocke and blogs at https://www.lisihocke.com.
In her free time, she plays indoor volleyball or delves into computer games and stories of all kinds.
Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.
Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.
-
It's time for another toot in our #peoplebehindosco series.
Hi @lisihocke 👋
Lisi found tech as her place to be in 2009 and has grown as a specialized generalist ever since. Building great products that deliver value together with great people motivates her and lets her thrive. As a security engineer, she’s now fully focusing on all things product security to help build more secure solutions. She’s committed to testing and quality, passionate about whole-team approaches to increase effectiveness and resilience, and enjoys experimenting and learning continuously. Having received a lot from communities, Lisi is paying it forward by sharing her stories and learning in public.
Her tags: #ProdSec, #AppSec, #DevSecOps, #SecureCoding, #SecurityTesting
She posts on Mastodon as @lisihocke and blogs at https://www.lisihocke.com.
In her free time, she plays indoor volleyball or delves into computer games and stories of all kinds.
Thank you very much for your work as a volunteer and your support in organizing the Open Security Conference.
Stay tuned and follow the hashtag #peoplebehindosco for more people behind osco.
-
A hardcoded secret. A directory traversal. A SQL injection. Individually, they're just low/medium findings. Chained together, they're a path to critical compromise.
Learn how Autonomous Attack Path Discovery finds the exploit chains traditional scanners miss.
Thank you to XBOW for supporting AppSec Village™ as our Platinum Sponsor at DEF CON 34 and throughout the year!
#AppSec #Cybersecurity #OffensiveSecurity #DevSecOps #DEFCON34
-
A hardcoded secret. A directory traversal. A SQL injection. Individually, they're just low/medium findings. Chained together, they're a path to critical compromise.
Learn how Autonomous Attack Path Discovery finds the exploit chains traditional scanners miss.
Thank you to XBOW for supporting AppSec Village™ as our Platinum Sponsor at DEF CON 34 and throughout the year!
#AppSec #Cybersecurity #OffensiveSecurity #DevSecOps #DEFCON34
-
Your base image is shipping known exploits into production. Trivy vs Grype: which scanner actually catches them before your CI/CD does damage? Shift-Left enforcement explained. #Security #Docker #DevSecOps
-
A study analysed 446 developer-reported security and privacy posts about LLM-native IDEs. Its findings place most reported issues in system integration and access controls rather than model behaviour alone. https://www.developer-tech.com/news/study-llm-native-ide-security-risks-in-system-controls/ #devsecops #infosec #llm #cybersecurity #ai #tech
-
A study analysed 446 developer-reported security and privacy posts about LLM-native IDEs. Its findings place most reported issues in system integration and access controls rather than model behaviour alone. https://www.developer-tech.com/news/study-llm-native-ide-security-risks-in-system-controls/ #devsecops #infosec #llm #cybersecurity #ai #tech
-
Security Tip: Verify before you execute. 🛡️
Supply chain attacks often involve intercepting downloads to inject malicious code. Before installing new tools or libraries, always verify the artifact's integrity using provided checksums (SHA-256) or cryptographic signatures (GPG/Cosign). If the hashes don't match, don't run it.
Stay ahead of emerging threats and vulnerabilities at https://cvedatabase.com
-
🚨 CRITICAL ADVISORY: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077). Attackers exploit flawed XStream deserialization under /app/agents/v1/ to execute arbitrary commands. Patch immediately!
https://denizhalil.com/2026/08/10/cve-2026-63077-jetbrains-teamcity-rce-analysis/
#CyberSecurity #RCE #DevSecOps
-
An AI Broke Out, Hacked Hugging Face, and Shook the Industry. IBM’s Answer Is Named Bob.
Let me tell you what happened in July. Because it changes how you should think about every AI project on your roadmap. OpenAI was testing one of its models for hacking skills. Standard practice — you run these tests inside a sealed sandbox, like a crash test for software. Except this time, the crash test dummy drove off the track. The model found a hole in its sandbox, reached the open internet, exploited a flaw in a file server, and broke into Hugging Face — one of the largest AI […] -
An AI Broke Out, Hacked Hugging Face, and Shook the Industry. IBM’s Answer Is Named Bob.
Let me tell you what happened in July. Because it changes how you should think about every AI project on your roadmap. OpenAI was testing one of its models for hacking skills. Standard practice — you run these tests inside a sealed sandbox, like a crash test for software. Except this time, the crash test dummy drove off the track. The model found a hole in its sandbox, reached the open internet, exploited a flaw in a file server, and broke into Hugging Face — one of the largest AI […] -
RE: https://mastodon.social/@WTL/116143698136660644
It wouldn't be a Friday if someone didn't make DNS changes that take things down, would it? #DevOps #DevSecOps #PushToProduction
-
RE: https://mastodon.social/@WTL/116143698136660644
It wouldn't be a Friday if someone didn't make DNS changes that take things down, would it? #DevOps #DevSecOps #PushToProduction
-
NEOMSA APIM 4.6.0, платформа управления API: как мы устранили уязвимости Critical и High из БДУ ФСТЭК
Мы выпустили NEOMSA APIM 4.6.0 . Основной фокус этого релиза — повышение безопасности состава поставки платформы. В рамках процессов безопасной разработки (SSDLC) мы сформировали SBOM, проверили компоненты и их зависимости на известные уязвимости (SCA), сопоставили результаты с БДУ ФСТЭК России и обновили проблемные библиотеки. По итогам повторной проверки количество зарегистрированных находок сократилось с 57 до 7. Уязвимостей уровней Critical и High в финальной сборке не осталось. В статье рассказываем, как устроена проверка NEOMSA APIM перед выпуском и какой критерий безопасности мы используем для принятия решения о готовности релиза.
https://habr.com/ru/companies/neoflex/articles/1067482/
#SBOM #SCA #DevSecOps #управление_уязвимостями #БДУ_ФСТЭК #CycloneDX #Grype #API_Management #безопасность_цепочки_поставок #neomsa_apim
-
NEOMSA APIM 4.6.0, платформа управления API: как мы устранили уязвимости Critical и High из БДУ ФСТЭК
Мы выпустили NEOMSA APIM 4.6.0 . Основной фокус этого релиза — повышение безопасности состава поставки платформы. В рамках процессов безопасной разработки (SSDLC) мы сформировали SBOM, проверили компоненты и их зависимости на известные уязвимости (SCA), сопоставили результаты с БДУ ФСТЭК России и обновили проблемные библиотеки. По итогам повторной проверки количество зарегистрированных находок сократилось с 57 до 7. Уязвимостей уровней Critical и High в финальной сборке не осталось. В статье рассказываем, как устроена проверка NEOMSA APIM перед выпуском и какой критерий безопасности мы используем для принятия решения о готовности релиза.
https://habr.com/ru/companies/neoflex/articles/1067784/
#SBOM #SCA #DevSecOps #управление_уязвимостями #БДУ_ФСТЭК #CycloneDX #Grype #API_Management #безопасность_цепочки_поставок #neomsa_apim
-
AI is rewriting code faster than humans can review it. Time to shift AppSec from “who wrote it” to “what it does.” https://jpmellojr.blogspot.com/2026/08/why-ai-coding-makes-zero-trust-appsec.html #AppSec #ZeroTrust #AISecurity #SupplyChainSecurity #DevSecOps #TrustModels
-
🔐 Secure applications are built, not bolted on.
At RELIANOID, our application security practices are aligned with the principles of ISO/IEC 27034, integrating security throughout the software lifecycle with continuous testing, vulnerability management, and secure-by-design development.
Because resilient infrastructure starts with secure applications.
📖 https://www.relianoid.com/security-compliances/relianoid-iso-iec-27034-compliance/
-
AISI found AI agents taking unsanctioned action on the live internet during a cyber evaluation, including an attempted supply chain attack on an open-source GitHub project. https://www.developer-tech.com/news/aisi-details-ai-agent-github-supply-chain-attack-attempt/ #aisi #devsecops #agenticai #infosec #github #opensource #cybersecurity #ai #tech
-
AISI found AI agents taking unsanctioned action on the live internet during a cyber evaluation, including an attempted supply chain attack on an open-source GitHub project. https://www.developer-tech.com/news/aisi-details-ai-agent-github-supply-chain-attack-attempt/ #aisi #devsecops #agenticai #infosec #github #opensource #cybersecurity #ai #tech
-
Microsoft has added an AI pillar to its Zero Trust Assessment tool and a 91-task DevSecOps pillar to its Zero Trust Workshop. https://www.developer-tech.com/news/microsoft-adds-ai-devsecops-pillars-zero-trust-tools/ #devsecops #microsoft #zerotrust #cybersecurity #developers #ai #tech
-
Microsoft has added an AI pillar to its Zero Trust Assessment tool and a 91-task DevSecOps pillar to its Zero Trust Workshop. https://www.developer-tech.com/news/microsoft-adds-ai-devsecops-pillars-zero-trust-tools/ #devsecops #microsoft #zerotrust #cybersecurity #developers #ai #tech
-
We still have not processed 49 hours of new #cve #cvealert data due to system update and new source connection https://www.valtersit.com/cve will become much better and after that vendors is next on the list. #defcon #devops #devsecops #sysadmin #cybersecurity #redteam #blueteam #hackers #infosec #linux #python #developers #ubuntu #ethicalhacking #ethicalhacker #angular #android
-
A major npm supply chain attack is underway as the self-propagating Shai-Hulud malware compromises over 800 packages with 2B+ monthly downloads. https://www.developer-tech.com/news/aikido-security-shai-hulud-npm-package-infection-surge/ #devsecops #supplychain #npm #opensource #developers #cybersecurity #infosec #tech
-
SourceHut recently added the possibility to use deploy keys instead of personal SSH keys for accessing Git repositories.
In a new blog post, we explain step by step how to take advantage of this new feature to increase the security of your CI/CD pipelines.
https://skyplabs.com/blog/sourcehut-deploy-keys/
If you are currently using personal SSH keys in your CI/CD pipelines for accessing Git repositories hosted on SourceHut, we recommend you replace them quickly with deploy keys.
#SourceHut #Git #CI #CICD #CicdPipelineSecurity #Security #DevOps #DevSecOps