med-mastodon.com is one of the many independent Mastodon servers you can use to participate in the fediverse.
Medical community on Mastodon

Administered by:

Server stats:

312
active users

#devsecops

1 post1 participant0 posts today
Tanya Janca | SheHacksPurple :verified: :verified:<p>Is there an <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AppSec</span></a> or <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> trend right now that you think is overhyped? Which one and whyyyyyy? Tell me your feels <a href="https://infosec.exchange/tags/talkappsectome" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>talkappsectome</span></a>&nbsp;</p>
James Moceri 🔐<p>Hello <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> community!</p><p>I'm James (JMo), a Institute of Data x Michigan Tech Cybersecurity Bootcamp grad who built an open-source security scanner as part of my capstone project.</p><p>**JMo Security** orchestrates 11 tools (Trivy, Semgrep, TruffleHog, ZAP, Falco) with:<br>✅ Multi-target scanning (repos, containers, IaC, web apps, GitLab, K8s)<br>✅ Auto-compliance mapping (OWASP, CWE, NIST, PCI DSS, CIS, ATT&amp;CK)<br>✅ Unified reporting (dashboard, SARIF, JSON)</p><p>**Quick start:**<br>pip install jmo-security jmotools wizard</p><p>📖 Docs: <a href="https://docs.jmotools.com" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">docs.jmotools.com</span><span class="invisible"></span></a><br>🐙 GitHub: <a href="https://github.com/jimmy058910/jmo-security-repo" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/jimmy058910/jmo-sec</span><span class="invisible">urity-repo</span></a></p><p>**Actively seeking <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> / <a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AppSec</span></a> roles!** DMs open for opportunities or technical feedback.</p><p>What security tools are you using in your workflows?</p><p><a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://infosec.exchange/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://infosec.exchange/tags/Python" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Python</span></a> <a href="https://infosec.exchange/tags/SecurityEngineering" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecurityEngineering</span></a> <a href="https://infosec.exchange/tags/JobSearch" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JobSearch</span></a></p>
Thomas Fricke (he/his)<p><span class="h-card" translate="no"><a href="https://social.tchncs.de/@diabhoil" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>diabhoil</span></a></span> <span class="h-card" translate="no"><a href="https://social.bund.de/@zendis" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>zendis</span></a></span> </p><p><a href="https://23.social/tags/cloudnative" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cloudnative</span></a> heißt </p><p><a href="https://de.wikipedia.org/wiki/Cloud-native_Computing?wprov=sfla1" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">de.wikipedia.org/wiki/Cloud-na</span><span class="invisible">tive_Computing?wprov=sfla1</span></a></p><p>Weitere Prinzipien </p><p><a href="https://23.social/tags/devsecops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devsecops</span></a> (Link geht zum US Militär 😱)</p><p><a href="https://www.cloud.mil/devsecops/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">cloud.mil/devsecops/</span><span class="invisible"></span></a></p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@owasp_de" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>owasp_de</span></a></span> Version </p><p><a href="https://owasp.org/www-project-devsecops-guideline/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">owasp.org/www-project-devsecop</span><span class="invisible">s-guideline/</span></a></p><p><a href="https://23.social/tags/google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>google</span></a> <a href="https://23.social/tags/dora" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dora</span></a> </p><p><a href="https://en.wikipedia.org/wiki/DevOps_Research_and_Assessment?wprov=sfla1" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">en.wikipedia.org/wiki/DevOps_R</span><span class="invisible">esearch_and_Assessment?wprov=sfla1</span></a></p><p><a href="https://23.social/tags/OpenDesk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenDesk</span></a> ist die erste Applikation in der Verwaltung, die diese Prinzipien berücksichtigt.</p><p><span class="h-card" translate="no"><a href="https://social.bund.de/@bsi" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>bsi</span></a></span> Grundschutz </p><p><a href="https://23.social/tags/Container" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Container</span></a> </p><p><a href="https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Grundschutz/IT-GS-Kompendium_Einzel_PDFs_2022/07_SYS_IT_Systeme/SYS_1_6_Containerisierung_Edition_2022.pdf?__blob=publicationFile&amp;v=3" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bsi.bund.de/SharedDocs/Downloa</span><span class="invisible">ds/DE/BSI/Grundschutz/IT-GS-Kompendium_Einzel_PDFs_2022/07_SYS_IT_Systeme/SYS_1_6_Containerisierung_Edition_2022.pdf?__blob=publicationFile&amp;v=3</span></a></p><p>und Kubernetes</p><p><a href="https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Grundschutz/IT-GS-Kompendium_Einzel_PDFs_2022/06_APP_Anwendungen/APP_4_4_Kubernetes_Edition_2022.pdf?__blob=publicationFile&amp;v=3" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bsi.bund.de/SharedDocs/Downloa</span><span class="invisible">ds/DE/BSI/Grundschutz/IT-GS-Kompendium_Einzel_PDFs_2022/06_APP_Anwendungen/APP_4_4_Kubernetes_Edition_2022.pdf?__blob=publicationFile&amp;v=3</span></a></p><p> kamen dann von selbst.</p>
Ardèch'Drôm Dev<p>L'association a besoin de vous, sinon elle va fermer ses portes. Est-ce que ce sera la dernière AG ? Venez participer à l'événement en visio <a href="https://mastodon.social/tags/ardeche" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ardeche</span></a> <a href="https://mastodon.social/tags/drome" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>drome</span></a> <a href="https://mastodon.social/tags/dev" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dev</span></a> <a href="https://mastodon.social/tags/code" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>code</span></a> <a href="https://mastodon.social/tags/devops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devops</span></a> <a href="https://mastodon.social/tags/devsecops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devsecops</span></a> <a href="https://mastodon.social/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a> <a href="https://mastodon.social/tags/logiciellibre" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>logiciellibre</span></a><br><a href="https://mobilizon.fr/events/b958f8b2-cdee-4ed2-bcf0-be765374cee6" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mobilizon.fr/events/b958f8b2-c</span><span class="invisible">dee-4ed2-bcf0-be765374cee6</span></a></p>
jpmellojr<p>Vibe coding is fast—but is it secure? Here are 5 critical lessons for AppSec teams navigating AI-generated code in production. <a href="https://jpmellojr.blogspot.com/2025/10/vibe-coding-in-production-5-security.html" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">jpmellojr.blogspot.com/2025/10</span><span class="invisible">/vibe-coding-in-production-5-security.html</span></a><br><a href="https://noc.social/tags/VibeCoding" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VibeCoding</span></a> <a href="https://noc.social/tags/AppSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AppSec</span></a> <a href="https://noc.social/tags/AIgeneratedCode" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AIgeneratedCode</span></a> <a href="https://noc.social/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://noc.social/tags/LLMcoding" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LLMcoding</span></a> <a href="https://noc.social/tags/CodeReview" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CodeReview</span></a> <a href="https://noc.social/tags/SoftwareSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareSecurity</span></a></p>
The DefendOps Diaries<p>Beware, devs! A new scam group is disguising crypto-stealing malware as trusted VSCode extensions. Is your code safe? Read on and stay one step ahead.</p><p><a href="https://thedefendopsdiaries.com/malicious-vscode-extensions-the-tigerjack-campaign-and-its-impact-on-developers/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">thedefendopsdiaries.com/malici</span><span class="invisible">ous-vscode-extensions-the-tigerjack-campaign-and-its-impact-on-developers/</span></a></p><p><a href="https://infosec.exchange/tags/vscode" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vscode</span></a><br><a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a><br><a href="https://infosec.exchange/tags/cryptotheft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cryptotheft</span></a><br><a href="https://infosec.exchange/tags/tigerjack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tigerjack</span></a><br><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a><br><a href="https://infosec.exchange/tags/devsecops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devsecops</span></a><br><a href="https://infosec.exchange/tags/socialengineering" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>socialengineering</span></a><br><a href="https://infosec.exchange/tags/openvsx" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openvsx</span></a><br><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a></p>
Tanya Janca | SheHacksPurple :verified: :verified:<p>🎥 Missed one of my past conference talks? Let’s fix that.</p><p>I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.</p><p>“Security is Everybody’s Job”<br>📽️ <a href="https://twp.ai/4ipQeU" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">twp.ai/4ipQeU</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://infosec.exchange/tags/SecurityAwareness" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecurityAwareness</span></a> <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/devops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devops</span></a> <a href="https://infosec.exchange/tags/devsecops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devsecops</span></a></p>
Tanya Janca | SheHacksPurple :verified: :verified:<p>🎥 Missed one of my past conference talks? Let’s fix that.</p><p>I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.</p><p>“DevSecOps with OWASP DevSlop”<br>📽️ <a href="https://twp.ai/4ipJpl" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">twp.ai/4ipJpl</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://infosec.exchange/tags/SecurityAwareness" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecurityAwareness</span></a> <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/OWASP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OWASP</span></a> <a href="https://infosec.exchange/tags/DevOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevOps</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a></p>
jpmellojr<p>The ongoing battle between shipping code fast and shipping it securely is a real challenge. Here are some strategies for AppSec teams to manage the risk. <a href="https://www.reversinglabs.com/blog/deadlines-vs-secure-code" rel="nofollow noopener" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">reversinglabs.com/blog/deadlin</span><span class="invisible">es-vs-secure-code</span></a> <a href="https://noc.social/tags/SecureCode" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureCode</span></a> <a href="https://noc.social/tags/AppSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AppSec</span></a> <a href="https://noc.social/tags/SoftwareDevelopment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareDevelopment</span></a> <a href="https://noc.social/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://noc.social/tags/CyberRisk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberRisk</span></a></p>
Colin Cogle :verified:<p>Help, I need a code signing certificate that won't bankrupt me.</p><p>Three years ago, I paid $100 for a three-year code signing certificate. I've signed all my open-source projects' releases with it. Now that it's renewal time, Certera (SignMyCode.com) wants almost $700 for the same three-year certificate (excluding the mandatory HSM purchase, which I am totally on board with).</p><p>I write silly C and PowerShell code, and I timestamp my signatures so that they're perpetually valid. My PowerShell Gallery stuff, as well as binaries of aprs-weather-submit on Windows and macOS, are all signed and hashed (but not notarized by Apple, because that's another $99 a year for something that feels done unless Bob Bruninga's followers are thinking about APRS 2.0).</p><p>If I can't find a solution, anything I write or update in the future will have to be released as unsigned unless I half-ass something (like the Notepad++ developer using self-signed certs -- semi-dangerously clever). $100 every three years, fine. $700 every three years, and I'll do it if my three fans click my Buy Me A Coffee link over and over.</p><p>Is there any CA out there that will offer open-source, not-for-profit developers like me a chance to get globally-trusted code signing certificates? I don't think SigStore ever took off (sadly), and even if it did, I don't think it's part of the Microsoft Authenticode program.</p><p><a href="https://mastodon.colincogle.name/tags/CodeSigning" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CodeSigning</span></a> <a href="https://mastodon.colincogle.name/tags/SSL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSL</span></a> <a href="https://mastodon.colincogle.name/tags/TLS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TLS</span></a> <a href="https://mastodon.colincogle.name/tags/certificates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>certificates</span></a> <a href="https://mastodon.colincogle.name/tags/Certera" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Certera</span></a> <a href="https://mastodon.colincogle.name/tags/SoftwareDevelopment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareDevelopment</span></a> <a href="https://mastodon.colincogle.name/tags/C" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>C</span></a> <a href="https://mastodon.colincogle.name/tags/PowerShell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PowerShell</span></a> <a href="https://mastodon.colincogle.name/tags/PowerShellGallery" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PowerShellGallery</span></a> <a href="https://mastodon.colincogle.name/tags/AmateurRadio" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AmateurRadio</span></a> <a href="https://mastodon.colincogle.name/tags/HamRadio" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HamRadio</span></a> <a href="https://mastodon.colincogle.name/tags/APRS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>APRS</span></a> <a href="https://mastodon.colincogle.name/tags/APRS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>APRS</span></a>-Weather-Submit <a href="https://mastodon.colincogle.name/tags/GitHub" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GitHub</span></a> <a href="https://mastodon.colincogle.name/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.colincogle.name/tags/developer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>developer</span></a> <a href="https://mastodon.colincogle.name/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://mastodon.colincogle.name/tags/macOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>macOS</span></a> <a href="https://mastodon.colincogle.name/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.colincogle.name/tags/Authenticode" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authenticode</span></a> <a href="https://mastodon.colincogle.name/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://mastodon.colincogle.name/tags/DevOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevOps</span></a></p>
Ryan Daws 🤓<p>XZ attack reveals unlearned open-source security lessons <a href="https://www.developer-tech.com/news/xz-attack-reveals-unlearned-open-source-security-lessons/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">developer-tech.com/news/xz-att</span><span class="invisible">ack-reveals-unlearned-open-source-security-lessons/</span></a> <a href="https://techhub.social/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a> <a href="https://techhub.social/tags/devsecops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devsecops</span></a> <a href="https://techhub.social/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://techhub.social/tags/technews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>technews</span></a> <a href="https://techhub.social/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a></p>
Cyb3rk1d<p>☁️ Cloud Security Tools — Essential Toolkit for Modern Teams 🛡️🚀</p><p>Cloud environments introduce new risks and require specialized tooling to secure workloads, configurations, and data. Use a mix of CSP-native and third-party tools to cover posture management, runtime protection, identity, and visibility. Key categories and examples: Cloud Security Posture Management (CSPM) — Prisma Cloud, Dome9, Wiz for misconfig &amp; compliance checks 🔍; Cloud Workload Protection (CWPP) — CrowdStrike, Trend Micro, Aqua for container and VM runtime defense 🐳🛡️; Cloud Access Security Broker (CASB) — Netskope, Microsoft Defender for Cloud Apps for SaaS visibility &amp; data control ☁️🔐; Identity &amp; Access Management — AWS IAM/Azure AD hardening, BeyondTrust, Okta for strong auth &amp; least privilege 🔑; Threat Detection &amp; SIEM — Splunk, Sumo Logic, Datadog + cloud-native logging for alerting and forensics 📊; Vulnerability &amp; Configuration Scanning — Qualys, Tenable, Trivy for images and infra-as-code scanning ⚙️; Secrets Management — HashiCorp Vault, AWS Secrets Manager for safe key handling 🔐; and Supply-chain &amp; CI/CD security — Snyk, Checkov, GitHub Advanced Security to catch insecure deps and pipelines 🧩.</p><p>⚠️ Disclaimer:<br>For educational &amp; defensive use only. Evaluate tools against your cloud provider, compliance needs, and threat model before deploying. Always test changes in staging before production. 🚫🔒</p><p><a href="https://defcon.social/tags/CloudSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudSecurity</span></a> <a href="https://defcon.social/tags/CSPM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CSPM</span></a> <a href="https://defcon.social/tags/CWPP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CWPP</span></a> <a href="https://defcon.social/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://defcon.social/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://defcon.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://defcon.social/tags/Cloud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cloud</span></a> <a href="https://defcon.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://defcon.social/tags/SecurityTools" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecurityTools</span></a> <a href="https://defcon.social/tags/Compliance" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Compliance</span></a> <a href="https://defcon.social/tags/ContainerSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ContainerSecurity</span></a> ☁️🛡️</p>
Habr<p>34 минуты до взлома: почему миру всегда будут нужны ИБ специалисты</p><p>Знаете, сколько времени нужно, чтобы взломать типичную российскую компанию? В среднем — меньше суток, а рекорд составил 34 минуты . Меньше, чем уходит на обед. Это данные недавнего эксперимента белых хакеров (пентестеров): они протестировали 74 компании и в двух из трёх случаях получили полный доступ. В 60% атак последствия были критичными: остановка бизнес-процессов, шифрование данных или кража средств. Рынок кибербезопасности в России сегодня стремительно меняется: уходят западные вендоры, компании латают инфраструктуру, а хакеры используют всё — от дыр в коде до генеративного ИИ. И одно остаётся стабильным: спрос на специалистов ИБ всегда выше предложения. Только на hh.ru в 2024 году — 27,3 тысячи вакансий (+17% к прошлому году). И это не предел: уже появляется новая ниша — безопасность AI, но специалистов там почти нет. Всем привет, меня зовут Никита Мотяжов , и я занимаюсь подбором ИБ-специалистов в SENSE . В статье разбираем, что происходит с ИБ в 2025-м: какие угрозы стали «новой нормой», кого ищут компании и как в профессию заходят джуны и опытные инженеры.</p><p><a href="https://habr.com/ru/companies/it_sense/articles/948182/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">habr.com/ru/companies/it_sense</span><span class="invisible">/articles/948182/</span></a></p><p><a href="https://zhub.link/tags/%D0%B8%D1%81%D0%BA%D1%83%D1%81%D1%81%D1%82%D0%B2%D0%B5%D0%BD%D0%BD%D1%8B%D0%B9_%D0%B8%D0%BD%D1%82%D0%B5%D0%BB%D0%BB%D0%B5%D0%BA%D1%82" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>искусственный_интеллект</span></a> <a href="https://zhub.link/tags/%D0%B2%D0%B7%D0%BB%D0%BE%D0%BC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>взлом</span></a> <a href="https://zhub.link/tags/%D1%85%D0%B0%D0%BA%D0%B5%D1%80%D1%81%D1%82%D0%B2%D0%BE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>хакерство</span></a> <a href="https://zhub.link/tags/%D0%B8%D0%B1" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>иб</span></a> <a href="https://zhub.link/tags/%D0%B8%D0%BD%D1%84%D0%BE%D1%80%D0%BC%D0%B0%D1%86%D0%B8%D0%BE%D0%BD%D0%BD%D0%B0%D1%8F_%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%BE%D1%81%D1%82%D1%8C" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>информационная_безопасность</span></a> <a href="https://zhub.link/tags/SOC%D0%B0%D0%BD%D0%B0%D0%BB%D0%B8%D1%82%D0%B8%D0%BA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOCаналитик</span></a> <a href="https://zhub.link/tags/%D0%BF%D0%B5%D0%BD%D1%82%D0%B5%D1%81%D1%82%D0%B5%D1%80" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>пентестер</span></a> <a href="https://zhub.link/tags/devsecops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>devsecops</span></a> <a href="https://zhub.link/tags/appsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>appsec</span></a> <a href="https://zhub.link/tags/compliance" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>compliance</span></a></p>
anchore<p>Find license landmines before they find you. Grant 0.3.0 flags "no-license" by default + turns policy into plain English. Faster, stricter, simpler.</p><p>🔗 <a href="https://anchore.com/blog/grants-release-0-3-0-smarter-policies-faster-scans-and-simpler-compliance/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">anchore.com/blog/grants-releas</span><span class="invisible">e-0-3-0-smarter-policies-faster-scans-and-simpler-compliance/</span></a></p><p><a href="https://mstdn.business/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mstdn.business/tags/SupplyChainSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SupplyChainSecurity</span></a> <a href="https://mstdn.business/tags/Compliance" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Compliance</span></a> <a href="https://mstdn.business/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a></p>
TechnoTenshi :verified_trans: :Fire_Lesbian:<p>Over 40 NPM packages, including the widely used <span class="h-card" translate="no"><a href="https://infosec.exchange/@ctrl" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ctrl</span></a></span>/tinycolor, were compromised in a supply chain attack that harvests cloud credentials and persists via GitHub Actions backdoors. The malware self-propagates by infecting other packages maintained by compromised authors.</p><p><a href="https://www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">stepsecurity.io/blog/ctrl-tiny</span><span class="invisible">color-and-40-npm-packages-compromised</span></a></p><p><a href="https://infosec.exchange/tags/SupplyChainAttack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SupplyChainAttack</span></a> <a href="https://infosec.exchange/tags/NpmSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NpmSecurity</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://infosec.exchange/tags/InfosecNews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfosecNews</span></a></p>
All Things Open<p>🚀 NEW on We ❤️ Open Source 🚀</p><p>SBOMs are the foundation of a more secure open source ecosystem. Alan Pope shows how Syft &amp; Grype help you inventory &amp; scan your software for vulnerabilities—fast, locally, and openly.</p><p><a href="https://allthingsopen.org/articles/sbom-open-source-security-syft-grype" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">allthingsopen.org/articles/sbo</span><span class="invisible">m-open-source-security-syft-grype</span></a></p><p><a href="https://mastodon.social/tags/WeLoveOpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WeLoveOpenSource</span></a> <a href="https://mastodon.social/tags/SBOM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SBOM</span></a> <a href="https://mastodon.social/tags/OpenSourceSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSourceSecurity</span></a> <a href="https://mastodon.social/tags/Syft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Syft</span></a> <a href="https://mastodon.social/tags/Grype" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Grype</span></a> <a href="https://mastodon.social/tags/FOSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FOSS</span></a> <a href="https://mastodon.social/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://mastodon.social/tags/SecureByDesign" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureByDesign</span></a></p>
Grype<p>Is your team struggling with one these dreaded acronyms: FedRAMP, PCI, HIPAA, NYDFS, or SOC 2? We feel you.<br>That's why we partnered up with Chainguard to make compliance faster, easier and continuously enforceable. Join us on Sept 24 when we share best practices for integrating compliance in the SDLC. We will start with secure container images and automate policy enforcement to streamline ... <a href="https://events.chainguard.dev/02c6031d-d65b-417d-b62d-858f53c144f5/?utm_medium=referral&amp;utm_source=anchore&amp;utm_campaign=FY26-GL-LW-ChainguardxAnchoreWebinar2025" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">events.chainguard.dev/02c6031d</span><span class="invisible">-d65b-417d-b62d-858f53c144f5/?utm_medium=referral&amp;utm_source=anchore&amp;utm_campaign=FY26-GL-LW-ChainguardxAnchoreWebinar2025</span></a></p><p><a href="https://fosstodon.org/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://fosstodon.org/tags/SupplyChainSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SupplyChainSecurity</span></a> <a href="https://fosstodon.org/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersecurity</span></a> <a href="https://fosstodon.org/tags/Compliance" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Compliance</span></a> <a href="https://fosstodon.org/tags/Chainguard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Chainguard</span></a> <a href="https://fosstodon.org/tags/Anchore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Anchore</span></a></p>
anchore<p>The <span class="h-card" translate="no"><a href="https://fosstodon.org/@syft" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>syft</span></a></span> &amp; <span class="h-card" translate="no"><a href="https://fosstodon.org/@grype" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>grype</span></a></span> projects combined have hit 40 million downloads!</p><p>A massive thank you to the open source community for trusting us to secure their software supply chains.</p><p><a href="https://mstdn.business/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SBOM</span></a> <a href="https://mstdn.business/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a><br><a href="https://anchore.com/opensource" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">anchore.com/opensource</span><span class="invisible"></span></a></p>
knoppix<p>CISA warns of active exploits targeting a Git flaw (CVE-2025-48384) enabling arbitrary code execution via malicious submodules 🧠<br>Git mishandles \r in config files—attackers can hijack machines when users clone tainted repos ⚠️<br>Patch deadline for U.S. agencies: Sept 15 ⏳<br>Fixes available in Git 2.43.7+ 🔧</p><p>Also added: Citrix Session Recording RCE &amp; privilege escalation bugs 🖥️</p><p><a href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-git-code-execution-flaw/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/cisa-warns-of-actively-exploited-git-code-execution-flaw/</span></a></p><p><a href="https://mastodon.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mastodon.social/tags/Git" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Git</span></a> <a href="https://mastodon.social/tags/CISA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CISA</span></a> <a href="https://mastodon.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://mastodon.social/tags/ZeroDay" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ZeroDay</span></a> <a href="https://mastodon.social/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://mastodon.social/tags/Code" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Code</span></a> <a href="https://mastodon.social/tags/Citrix" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Citrix</span></a> <a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://mastodon.social/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mastodon.social/tags/CVE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CVE</span></a></p>
:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉<p>🚨 Supply chain attack hits Nx NPM package with 4.6M weekly downloads! Malicious updates exploited AI CLI tools to steal developer secrets like SSH keys &amp; tokens, exposing sensitive data in public GitHub repos. Devs urged to audit accounts &amp; revoke creds ASAP. More info: <a href="https://cyberinsider.com/supply-chain-attack-hits-nx-npm-package-with-4-6m-weekly-downloads/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">cyberinsider.com/supply-chain-</span><span class="invisible">attack-hits-nx-npm-package-with-4-6m-weekly-downloads/</span></a> <a href="https://mas.to/tags/SupplyChainAttack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SupplyChainAttack</span></a> <a href="https://mas.to/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersecurity</span></a> <a href="https://mas.to/tags/NPM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NPM</span></a> <a href="https://mas.to/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a><br><a href="https://mas.to/tags/newz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>newz</span></a></p>