Penguin Alley - Inteligent Solutions
Penguin Alley - Inteligent Solutions @PenguinAlleyAds ·
The security scanner built to protect your code was weaponized against it. Trivy was compromised. A self-spreading worm infected 141+ npm packages using blockchain C2. Pin your tool versions. Verify checksums. Trust nothing blindly. #SupplyChain #DevSecOps
1
JTCrawford
JTCrawford @JtCrawford ·
Security researchers scanned 10M websites and found nearly 2,000 valid API keys exposed in public code—including cloud credentials from a global bank. Basic OpSec isn't optional. Every leaked key is an unlocked door. #CyberSecurity #DevSecOps
2
Leon Godwin ☁️
Leon Godwin ☁️ @CloudyBiz ·
hackerbot-claw stole a write token from a 140k-star GitHub repo using a pull_request_target workflow that nobody had audited. If your CI/CD permissions haven't been reviewed lately, that's the to-do. #GitHubActions #DevSecOps
3
Endura Security
Endura Security @endurasecurity ·
Security scanners in CI/CD run with the same privileges they are supposed to protect. Compromise the scanner and you inherit all of them - secrets, network, build artifacts. The tooling IS the attack surface. #DevSecOps #SupplyChainSecurity
7
Xygeni
Xygeni @xygeni ·
Most tools look for CVEs, signatures, hashes. Modern malware doesn’t. It hides in deps, CI/CD, build scripts… and runs at runtime. 👉 No CVE. No alert Better question: What is this code doing when it runs? Read more →xygeni.io/blog/ai-powere…X #AppSec #DevSecOps #CyberSecurity
AI-Powered Malware Detection in SSCS | Xygeni

AI-powered malware detection stops ai malware through behavioral analysis and protects code, dependencies, and CI/CD pipelines.

From xygeni.io
23
NY-squared AI
NY-squared AI @NYsquaredAI ·
Arcjet ships inline prompt injection defense for production AI. Detecting hostile prompts at the app boundary before inference. 500+ production apps protected. Runtime AI defense is becoming table stakes. #PromptInjection #DevSecOps
3
Vineet
Vineet @dvineet9 ·
Most security issues don’t come from hackers. They come from misconfigurations. • Public S3 buckets • Open ports • Weak IAM policies Security isn’t a tool. It’s discipline. #Devsecops
12
Paweł Kucia
Paweł Kucia @PawelKucia ·
GitHub's Credential Revocation API now supports OAuth & GitHub App credentials! Revoke exposed tokens programmatically to secure your projects faster. Stay ahead in protecting your repos and integrations. #GitHub #Security #DevSecOps 🔐🚀 ⬇Oo
1
5
Knetero
Knetero @azero853 ·
Just when you thought your GitHub repos were safe... a new supply-chain attack is using invisible Unicode characters to hide malicious code in plain sight. 😱 This is why supply-chain security is EVERYONE's problem now. #CyberSecurity #DevSecOps
7